Around 300 people working for Scotland's prosecution service have fallen victim to hackers, the Daily Record can reveal. A probe has been launched into the data breach as security experts warned it could be “dangerous” if information about Scotland’s top prosecutors “fell into the wrong hands”.
Breach details
The affected employees, who work for the Crown Office and Procurator Fiscal Service (COPFS), have been told some personal information may have been accessed after they took part in a Scottish Government survey. The survey was carried out by an outside agency, and the files accessed by hackers contained information such as email addresses, roles in the Crown Office, and place of work. Staff were told about the breach yesterday.
Security expert reaction
Scots security expert and ex-SAS operative Graham Yuill said: “This is absolutely shocking and a severe breach. The hackers may have obtained information that could prove dangerous in the wrong hands. It has to be investigated. We need to find out who did this and who is responsible, especially with the gang warfare that is ongoing in Scotland.”
He added: “This hack could have come from abroad, it could be a rogue nation doing this. If I was working for the Crown Office and there was stuff compromised about me I would be terrified. There is more to this than meets the eye. You are talking about hundreds of people.”
Political and union response
Scottish Labour justice spokesperson Pauline McNeill called it “a concerning incident”, adding: “It is important that the organisation now takes the necessary steps to ensure that the personal details of staff were not accessed, and to guarantee that they are not at any risk. Where incidents such as this happen, lessons must be learned to ensure that similar incidents cannot happen again.”
Scots Tory justice spokesman Stephen Kerr said: “SNP ministers must urgently investigate this situation and come clean on the extent of what information has potentially been compromised. They must also outline what robust measures will be put in place to stop an incident like this from occurring again anywhere in Scotland’s public services. There will be real concern about the potential security risks.”
Allan Sampson, national officer for the FDA union which represents staff, said: “We note the assurances provided by COPFS, but will seek confirmation that affected staff have received clear information about the data involved, any associated risks and the support available.”
Official statements
The Crown Office last night confirmed details of the breach. A spokesperson said: “COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector survey. This is unconnected to casework and did not involve sensitive or confidential case information. There is no impact on the work of the prosecution service. Colleagues have been reminded of guidance on responding to any phishing or scam attempts which may arise from this third-party breach.”
A spokesperson for the Information Commissioners Office (ICO), who are responsible for data protection across the UK, said: “Organisations must always notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms. If an organisation decides that a breach doesn’t need to be reported they should keep their own record of it and be able to explain why it wasn’t reported if necessary.”
A Scottish Government spokesperson said: ”Ministers have been made aware of the data breach and are receiving updates.”



