Opens in a new tab

Find a Vet Breach: RCVS Apologises

RCVS apologises for month-long Find a Vet data breach

The Find a Vet breach reportedly exposed data through the Royal College of Veterinary Surgeons service for around a month. RCVS has issued a public apology following the incident.

Reported on 21 September 2026, the incident concerns Find a Vet, the RCVS service that enables people to locate veterinary professionals and practices. The available report does not identify the exact dates of exposure, the number of affected records or whether anyone accessed the exposed information.

What happened in the Find a Vet breach?

The Find a Vet breach involved data associated with the RCVS online directory. The exposure is described as having lasted for one month, making this more than a brief website error or momentary service disruption.

RCVS acknowledged the incident and apologised publicly. However, the report available at publication does not explain when the issue began, when it was discovered or precisely when it was contained. It is therefore not possible to establish a day-by-day incident timeline from the information released.

The report also does not specify how the data became exposed. There is no confirmed description of a compromised account, malicious intrusion, software vulnerability, incorrect permission, database error or misconfigured web application. Any attribution to a particular attack method would consequently be premature.

This distinction matters. A data breach can involve information becoming accessible to people who should not be able to see it, but that does not automatically prove that a criminal attacker found, copied or misused the information. The public report confirms a month-long breach, not a specific cyberattack.

Information currently confirmed

  • The incident affected the RCVS Find a Vet service.
  • The data breach reportedly continued for approximately one month.
  • RCVS acknowledged the incident and issued an apology.
  • The incident had become public by 21 September 2026.

Important details not yet established

The available account does not state which data fields were exposed. It does not confirm whether the issue involved names, professional details, contact information, account data or any information that was not already intended to appear in the public directory.

There is also no confirmed number of affected veterinary surgeons, veterinary nurses, practices or other users. Without that figure, the overall scale of the Find a Vet breach cannot yet be measured reliably.

No affected software versions or third-party products have been identified in the report. Organisations should not assume that a particular content management system, database, hosting provider or supplier was responsible unless RCVS provides further technical findings.

Who may be affected by the Find a Vet breach?

The incident is directly relevant to people and organisations whose information was held within or connected to Find a Vet during the reported exposure period. This may include veterinary professionals and practices listed by the service, although the disclosed report does not define the affected groups or confirm that every directory entry was involved.

It is equally unclear whether the breach affected only information displayed to the public or included additional data held behind the service. That difference will be central to assessing risk. Exposure of existing public directory details presents a different level of harm from disclosure of private contact, administrative or account information.

RCVS has not been reported as confirming whether individual notifications were sent. The available information also does not say whether the incident was reported to the Information Commissioner’s Office or another authority. The absence of those details in the report should not be interpreted as evidence that notification did or did not occur.

People connected with Find a Vet should rely on direct communications from RCVS for confirmation of whether their records were involved. Public reporting alone does not provide enough detail to identify specific affected individuals or practices.

How the month-long exposure may have worked

No technical cause has been published in the supplied report. Several types of web service failure can produce prolonged data exposure, but none has been confirmed in this case. Possible causes in general include incorrectly configured access rules, an application programming interface returning excessive data, or a page allowing information to be retrieved without the intended checks.

Those examples explain how online exposure can persist unnoticed, but they should not be treated as findings about the Find a Vet breach. A technical account from RCVS would be needed to determine the affected component, the fault that created the exposure and the controls that failed to detect it sooner.

The one-month duration raises questions about monitoring and discovery. Investigators will need to establish whether logs show unusual searches, automated requests, bulk retrieval or access from unexpected locations. They will also need to determine whether sufficient logs were retained throughout the period.

Current exploitation status

There is no confirmed evidence in the available report that exposed data was downloaded, sold, published elsewhere or used for fraud. There is also no report of ransomware, service extortion or a threat actor claiming responsibility.

However, a lack of public evidence is not the same as proof that no access occurred. The current exploitation status should therefore be treated as unknown until RCVS completes its investigation or releases further findings.

Any later assessment should separate potential exposure from verified access. Useful evidence would include server logs, query volumes, account activity, data export records and indicators of automated collection during the month-long window.

Find a Vet breach timeline and unanswered questions

The confirmed public timeline is limited. The breach lasted for approximately one month, RCVS subsequently apologised, and the incident was reported on 21 September 2026. Exact start, discovery, containment and notification dates have not been provided in the available account.

Further disclosure would help affected parties understand the event. The most important unanswered questions are:

  • Which records and individual data fields were exposed?
  • How many people, practices or directory entries were affected?
  • What technical or procedural failure caused the exposure?
  • Was the information merely accessible, or do logs show that it was viewed or copied?
  • When was the breach discovered and fully contained?
  • Have affected individuals and relevant regulators been notified?

Why this RCVS incident matters

Professional directories combine searchable information with trust in the organisation maintaining it. Even where some details are intended to be public, unintended access can expose additional fields, enable bulk collection or make professional information easier to use in convincing impersonation attempts.

The duration of the Find a Vet breach makes the eventual investigation findings particularly important. Clear information about scope, access and containment will allow veterinary professionals and practices to assess their actual risk without relying on speculation.

What veterinary organisations should do now

Practices and professionals connected to Find a Vet should review any notification received from RCVS and confirm that their current contact details are accurate. They should be cautious about unexpected messages that reference directory information or claim to concern the breach.

Organisations operating comparable directories should use this event to verify that public searches return only intended fields. They should also review access logs for bulk extraction, test unauthenticated application routes and confirm that alerts can detect unusual volumes of record requests.

These checks should remain tied to verified evidence. Password resets or wider technical changes should be based on the data and systems confirmed as affected, rather than assumptions about an attack method that has not been disclosed.

Originally reported by Vet Times.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call