A Survey Company May Have Leaked Scottish Government Workers' Personal Details

A contractor hired to run a government training exercise lost staff data from Scotland's public prosecution service. The real worry: dozens of other agencies probably handed over the same information.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Government office building in Edinburgh with survey equipment cases and hard drives stacked near an unsecured loading area, clipboard with employee rosters visi
Share

Key points

  • Scotland's Crown Office and Procurator Fiscal Service (COPFS), the country's public prosecution and death-investigation authority, disclosed a data breach on 13 August.
  • Around 300 government employees had names, job titles and work email addresses exposed.
  • The breach traces to an unnamed third-party contractor that ran a compulsory government training survey.
  • Multiple Scottish government departments took part in the same survey programme, meaning the total number of people affected could be far higher.
  • No case files or witness information were exposed.

A contractor hired to run a routine government training exercise lost personal details belonging to staff at Scotland's most important legal agency, and the damage may stretch well beyond the 300 employees confirmed so far.

Scotland's Crown Office and Procurator Fiscal Service, known as COPFS, is the agency that decides who gets prosecuted in Scotland and investigates sudden or suspicious deaths. On 13 August it admitted that an outside supplier had suffered a data breach. The supplier had been running a "Data Maturity Assessment," a survey-based exercise where organisations score how well they handle data. COPFS said the unnamed supplier spotted "suspicious activity" on its systems on 5 August.

What information was taken?

Employee names, job roles and work email addresses were exposed. Case records and witness information were not affected.

Three hundred people sounds small. Boris Cipot, principal security engineer at software-security firm Black Duck, told Dark Reading it shouldn't be treated that way. Even a name and a work email address is enough for a convincing phishing attack, where a fake email is crafted to look like it comes from a trusted government colleague or supplier. "It often takes only one compromised employee account to provide an attacker with a foothold into the broader environment," Cipot said.

Could more agencies be affected?

Almost certainly yes. The Data Maturity Assessment is part of a wider Scottish government programme running since 2021. Multiple departments take part each year, not just COPFS, so the unnamed contractor likely held employee data from several agencies that could all be sitting in the same breached system.

Dark Reading, which broke the story, identified the contractor it believes to be involved as Data Orchard, a UK-based research company whose published reports describe running exactly this kind of programme for Scottish public bodies. Data Orchard has not been publicly named by the Scottish government, and hadn't responded to press enquiries at publication time.

Why does a survey company have government employee data at all?

This is the failure mode that keeps appearing in breach post-mortems. Vendor risk doesn't pause once a contract is signed, but the monitoring often does. We covered exactly this pattern on 3 August in "Your Company's Vendor Problem Starts Before Anyone Calls Security", and the COPFS incident is a textbook illustration of it.

Cory Kennedy, a threat researcher at SecurityScorecard, put it plainly to Dark Reading: "The exposure sat with a survey vendor hired for a one-off assessment, exactly the kind of peripheral supplier that never makes it onto anybody's continuous monitoring list." His prescription isn't more paperwork. It's continuous outside-in monitoring of a supplier's live attack surface, extending past direct vendors into their dependencies. He pointed to NIS2 and DORA as the regulatory pressure already pulling European organisations that direction.

Detail Confirmed fact
Organisation affected COPFS, Scotland
Disclosure date 13 August
Breach detected 5 August
Employees affected Approx. 300
Data exposed Names, roles, work email addresses
Data NOT exposed Case files, witness details

If you're a Scottish government employee, treat your work inbox with extra suspicion, particularly emails that invoke real names or internal roles. Phishing built on accurate personal details is harder to catch than a generic scam.

The real story here isn't the 300 names. It's that every other agency that handed data to this same contractor is probably still waiting to find out whether theirs was in the same breached system.

© 2026 Threat Vectr