Full Report
Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected
Analysis Summary
# Incident Report: Third-Party Data Breach Affecting COPFS
## Executive Summary
A third-party supplier managing a Scottish Government data maturity assessment experienced a security breach, potentially exposing the professional details of approximately 300 staff members. While the Crown Office and Procurator Fiscal Service (COPFS) internal systems remained secure, attackers accessed names, roles, and work email addresses. The incident is currently under investigation, with no reported impact on active legal casework or organizational operations.
## Incident Details
- **Discovery Date:** August 5, 2026
- **Incident Date:** Ongoing (Investigation launched August 5)
- **Affected Organization:** Crown Office and Procurator Fiscal Service (COPFS) via an Unnamed Third-Party Supplier
- **Sector:** Public Sector / Legal & Prosecution
- **Geography:** Scotland, UK
## Timeline of Events
### Initial Access
- **Date/Time:** Circa August 5, 2026 (Detection)
- **Vector:** Potential exploitation of third-party software (Under investigation; speculation regarding Metabase zero-day vulnerability).
- **Details:** Suspicious activity was detected on the systems of a Scottish Government partner managing an online data maturity assessment.
### Lateral Movement
- **Details:** Information not currently disclosed; the breach was limited to the supplier’s environment.
### Data Exfiltration/Impact
- **Details:** Information submitted for a 2025 data maturity assessment was compromised. This includes the names, job roles, and work email addresses of roughly 300 COPFS employees.
### Detection & Response
- **How it was discovered:** The unnamed third-party supplier detected "suspicious activity" on their own network.
- **Response actions taken:** The supplier secured their systems and launched a forensic investigation; COPFS issued a notification to affected staff and provided anti-phishing guidance.
## Attack Methodology
- **Initial Access:** [Suspected] Exploitation of a third-party business intelligence platform (Metabase).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Potential administrator access if the Metabase zero-day was the vector.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Potential access to database credentials stored within the assessment platform.
- **Discovery:** Reconnaissance of professional contact lists.
- **Lateral Movement:** N/A (Breach localized to supplier).
- **Collection:** Gathering of survey/assessment participant data.
- **Exfiltration:** Potential download of assessment databases.
- **Impact:** Unauthorized disclosure of PII (Names, roles, emails).
## Impact Assessment
- **Financial:** No direct costs reported; potential future costs related to forensic auditing.
- **Data Breach:** ~300 records containing Name, Role, and Email Address.
- **Operational:** Low; no impact on COPFS casework or prosecution services.
- **Reputational:** Moderate; highlights risks in the Scottish Government’s third-party supply chain.
## Indicators of Compromise
- **Network indicators:** None disclosed in the report.
- **File indicators:** None disclosed.
- **Behavioral indicators:** Unauthorized access to survey databases; "suspicious activity" flagged by supplier monitoring.
## Response Actions
- **Containment measures:** Supplier took steps to "secure its systems" immediately following discovery.
- **Eradication steps:** Ongoing investigation into the intrusion method.
- **Recovery actions:** COPFS staff briefed on increased phishing risks and scam awareness.
## Lessons Learned
- **Key takeaways:** Data provided for "assessments" or "surveys" often remains stored in third-party environments long after the exercise is completed, creating a lingering attack surface.
- **What could have been done better:** Implementation of data retention policies that require suppliers to purge PII once assessment results are aggregated and delivered.
## Recommendations
- **Third-Party Risk Management (TPRM):** Conduct rigorous security audits of vendors, specifically focusing on their use of business intelligence tools like Metabase.
- **Data Minimization:** Ensure future surveys use anonymized identifiers rather than full names and work emails where possible.
- **Phishing Simulation:** Launch targeted phishing simulations for the 300 affected staff members to test their resilience following the leak of their professional details.