Scottish Government Prosecutor's Office Data Breach Linked to Third-Party Provider
Compromise at Crown Office and Procurator Fiscal Service potentially affects multiple agencies via shared vendor

Key Takeaways
- A data breach at COPFS was linked to a third-party service provider with broader access.
- The compromise may have extended to other government agencies beyond COPFS.
- The full extent of affected organisations, data types, and the initial attack vector remain unconfirmed.
- No patch is available; response focuses on vendor risk management and access controls.
Quick answers
- What happened?
- The Scottish Government's Crown Office and Procurator Fiscal Service (COPFS) confirmed a data breach originating from a third-party service provider. The compromise may have extended beyond COPFS to other government agencies that relied on the same vendor, though the full scope of affected organisations and data types remains unconfirmed.
- What should defenders do?
- Organisations should conduct immediate third-party vendor risk assessments, revoke unnecessary access, and enhance monitoring of affected systems. Enhanced supply chain security due diligence is recommended.
The Scottish Government has confirmed a data breach at the Crown Office and Procurator Fiscal Service (COPFS), the public prosecution body for Scotland. The incident was traced to a third-party service provider that had access to COPFS systems and, potentially, to other government agencies. The breach was reported on August 14, 2026, though the compromise occurred prior to disclosure. The exact nature of the third-party relationship, the initial attack vector, and the specific categories of data exposed have not been detailed in the source material. Authorities have indicated that the scope of the breach may be widening, with other agencies potentially affected through the same vendor. No software patch is applicable; mitigation efforts are focused on third-party risk assessment, access revocation, and enhanced monitoring across impacted services.
Security Details
Breach traced to a third-party service provider; attack vector not specified. Potential compounding effect on other government agencies sharing the same vendor.
Mitigation
Organisations should conduct immediate third-party vendor risk assessments, revoke unnecessary access, and enhance monitoring of affected systems. Enhanced supply chain security due diligence is recommended.
Sources
Dark reading
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
Aug 14, 2026 · 15:58
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



