Scottish Government Prosecutor’s Office Data Breach

Scottish prosecutor’s office hit by widening data breach

The Scottish Government’s prosecuting authority is at the centre of a widening data breach, raising concerns about exposure of highly sensitive legal and personal information. This breach, which affects the Crown Office and Procurator Fiscal Service (COPFS), highlights significant risks for public sector data security and the potential for downstream exploitation.

Details of the Scottish Government Prosecutor’s Office Breach

The breach was first discovered at the Crown Office and Procurator Fiscal Service, Scotland’s main prosecuting authority. Early reports surfaced in late June 2024, suggesting that unauthorised access had occurred within the organisation’s IT systems. The incident was quickly classified as a data breach, but emerging evidence now indicates the scope may be broadening.

While specific technical details remain closely held during the ongoing investigation, sources have confirmed that the breach involves exposure of both legal documents and personal information. This includes case data, correspondence, and potentially records containing names, addresses and other identifiers of individuals involved in legal proceedings. The full extent of compromised data is under active review, with authorities warning that more affected categories may be identified as forensic analysis continues.

  • What happened: Unauthorised access to COPFS systems, exposing legal and personal data
  • When: Discovered late June 2024, with signs breach may have occurred earlier
  • Who is affected: COPFS staff, legal professionals, witnesses, and potentially members of the public named in case files
  • Data at risk: Sensitive legal documents, personal identifiers, internal correspondence
  • Current status: Investigation ongoing, with the affected data set potentially expanding

Authorities have not yet named a specific attacker group or detailed the technical vector used, but the Scottish Government is coordinating with the National Cyber Security Centre and Police Scotland to contain the breach and assess its impact. The possibility that external suppliers or third-party access may have been implicated is also being investigated, reflecting the increasingly complex supply chain risks seen in recent public sector breaches.

How the Breach Works: Attack Vectors and Data Exposure

Although the Scottish Government has not released a full technical breakdown, several plausible attack vectors are under review. Recent UK public sector breaches have often exploited vulnerabilities in remote access solutions, misconfigured cloud storage, or compromised supplier credentials. Attackers may have leveraged phishing, credential stuffing, or exploited software weaknesses to gain a foothold in COPFS networks.

Once inside, the attackers appear to have accessed files and communications relating to ongoing and historic prosecutions. The exposure of this information is particularly serious, as legal documents frequently contain confidential details about criminal cases, witnesses, and sensitive evidence. The breach’s potential to compromise the integrity of ongoing prosecutions and witness protection is a key concern for authorities.

Forensic teams are now working to map the full timeline of the breach. Initial analysis suggests the unauthorised access could have persisted for several weeks before detection. There are concerns that additional datasets, beyond those already identified, may be involved as the investigation proceeds. The incident response is ongoing, with new notifications to affected individuals expected as more information comes to light.

Timeline of Events

  • Early June 2024: Suspicious activity detected on COPFS networks
  • Late June 2024: Breach confirmed, incident response initiated
  • Early July 2024: Investigation expands as new categories of affected data are identified
  • Ongoing: Government, law enforcement and cybersecurity experts working to contain and remediate the breach

So far, there is no public evidence that the stolen data has been published or sold on dark web forums. However, officials have warned that affected parties should remain alert for targeted phishing, scams, or attempts to exploit leaked legal information for fraud or intimidation.

Why the Scottish Government Data Breach Matters

This breach strikes at the heart of public trust in the legal system. The exposure of sensitive case data and personal identifiers not only risks privacy violations but could also undermine criminal proceedings, threaten witness safety, and facilitate wider fraud. For the Scottish Government, the incident underscores the challenges of securing complex, interconnected public sector IT environments.

Beyond the immediate impact, there is a risk that details from the breach could be weaponised for targeted phishing or social engineering campaigns, aimed at legal professionals, witnesses, or victims whose details were exposed. The situation remains fluid, with the potential for further revelations as the investigation continues.

Action Steps for UK Organisations

Although this breach specifically affects the Scottish Government’s prosecuting authority, it serves as a stark reminder for all UK organisations handling sensitive information. Steps to consider in light of this event include:

  • Review access controls for sensitive data, especially for suppliers and external partners
  • Enhance incident response plans for rapid detection and containment
  • Educate staff about targeted phishing risks following publicised breaches

Organisations should remain alert for any signs of data misuse linked to this breach and be prepared to update risk assessments as more facts emerge.

Originally reported by Unknown.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call