Scottish prosecutors cast eye over leaky supplier after staff data exposed
What happened
A third‑party supplier that handled a Scottish government data‑maturity survey detected suspicious activity affecting around 300 prosecution service staff. The exposed information was employment data (names, roles, work emails) and did not touch casework systems. Watch whether suppliers provide full forensic artifacts and timetables for notification and remediation
Why the category manager should care
Treat this as an operational supplier incident: the supplier discovered the activity and buyer systems were unaffected, but procurement must force evidence and remediation commitments from suppliers
Key facts
- Affected cohort: around 300 COPFS staff who participated in a public‑sector survey
- Data types: staff names, roles, and work email addresses