"COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector data maturity survey."
Crown Office and Procurator Fiscal Service: the official account
The Crown Office and Procurator Fiscal Service (COPFS) disclosed on Thursday that an unnamed third‑party supplier detected "suspicious activity" on August 5 and launched an investigation. COPFS said its own systems were not compromised and that the incident relates to information provided for an online data maturity assessment organized by the Scottish government and managed by the affected supplier.
In a statement to The Register, a COPFS spokesperson stressed the data involved was employment‑related and limited to "staff names, roles, and work email addresses." The spokesperson also said the incident "is unconnected to casework and did not involve sensitive or confidential case information" and that there is "no impact on the work of the prosecution service." COPFS added colleagues have been reminded of guidance on responding to any phishing or scam attempts arising from the breach.
The supplier: steps taken and the ongoing investigation
COPFS said the supplier has taken steps to secure its systems and is still investigating how the intrusion happened and precisely what information may have been accessed. Beyond that confirmation, COPFS said it would provide further updates should "significant new information" emerge. The supplier remains unnamed in COPFS’ statements.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat data was involved: personnel records, not case files
COPFS limited its description of the exposed material to "employment‑related data submitted for the exercise, including staff names, roles, and work email addresses." The prosecution service emphasized that the breach did not involve casework or confidential case information and asserted there was no impact on the service’s operational work.
Metabase zero‑day: a possible, but unconfirmed, connection
The report notes an unresolved question about whether the supplier breach is connected to the recent exploitation of a zero‑day vulnerability in the business intelligence platform Metabase. Metabase disclosed this month that attackers had exploited a previously unknown vulnerability in its cloud service, potentially allowing them to gain administrator access and reach connected databases. The Scottish government did not answer a question about whether the affected supplier used the Metabase software.
Earlier reporting cited in the piece also identified modular laptop maker Framework among those affected by the Metabase incident, illustrating the range of organizations named in connection with that vulnerability. For COPFS and the unnamed supplier, the links to Metabase remain speculative pending the supplier’s investigation and any follow‑up disclosures.
What this means for COPFS staff, the Scottish government, and the supplier
- COPFS staff: COPFS has notified about 300 colleagues who participated in the survey and reminded staff of guidance on responding to phishing or scam attempts that may arise from the breach.
- Scottish government: the government organized the data maturity assessment that used the affected supplier; it did not reply when asked whether the supplier used Metabase, leaving the government’s role in the vendor choice and software stack unclarified in public statements.
- The supplier: according to COPFS, the supplier has secured systems and is conducting an investigation into how the intrusion occurred and what data may have been accessed.
For now, the supplier breach leaves "plenty of questions and few answers about who got in or what they accessed." COPFS has framed the exposure as limited to employment‑related fields and unrelated to casework, while the supplier’s probe and the Scottish government’s responses will determine whether the incident ties back to the Metabase zero‑day or points to a different intrusion method. COPFS says it will issue further updates if it discovers "significant new information."




