Skip to main content
Emerging ThreatsData Breaches

UK Government Investments Exposes Official Contact Data in 40-Hour Breach

UK government office with papers scattered, slightly ajar file cabinet, and blurred computer screen in background.

An internal file containing the names and work email addresses of 51 government officials was left publicly accessible for around 40 hours, UK Government Investments (UKGI) says in its annual report.

UK Government Investments admits 40‑hour exposure

UKGI, the Treasury-owned corporate finance adviser, disclosed the incident in its 2025–26 annual report after The Guardian first reported the exposure. According to that filing, the breach occurred when a member of staff "did not follow established information security policies." The organisation says the document was publicly accessible for around 40 hours and contained contact details for 51 government officials alongside what UKGI describes as "high-level management information."

Contents and scale of the leak

The only specifics UKGI provides in the annual report are the number of affected officials and the types of data in the file: names, work email addresses and "high-level management information." The report does not say when during the 2025–26 year the exposure happened, where the file was hosted, whether anyone accessed or downloaded it, or which departments employed the affected officials.

How UKGI responded: reporting, review and remediation

UKGI says it voluntarily reported the incident to the Information Commissioner's Office even though the organisation judged the matter did not "meet the threshold for mandatory notification." It also informed its Audit and Risk Committee and commissioned an external review of the breach. The annual report states the external review concluded UKGI's response was appropriate and recommended further improvements to security controls and incident preparedness, and that "the overwhelming majority" of those recommendations have either already been implemented or are due to be introduced in the coming months.

Context: UKGI's role in major 2025–26 deals

The mishap comes in a year when UKGI had its fingerprints on some of Whitehall's biggest commercial deals. In 2025–26 UKGI advised on finally offloading the government's remaining NatWest shares, worked on small modular reactor financing, and supported the Eutelsat capital raise and Royal Mail takeover, the annual report notes.

What this means for government officials, the Information Commissioner's Office, and auditors

  • Government officials named in the file — the people whose work email addresses were exposed — will want clarity on which departments were affected and whether any downloads or accesses occurred while the file was public. UKGI has not provided that detail in the annual report.
  • The Information Commissioner's Office received a voluntary notification from UKGI even though UKGI judged the incident to fall short of mandatory-reporting thresholds; the ICO will therefore hold the record of UKGI’s voluntary disclosure.
  • The Audit and Risk Committee and whoever conducted the external review now have responsibility for following up on recommendations and ensuring the promised security control and preparedness upgrades are both implemented and documented. UKGI has not identified the external firm that conducted the review nor published the review's recommendations in the annual report.

The Register has asked UKGI for further details, including what additional information the file contained beyond names and email addresses, where it was publicly accessible, whether there is any evidence it was accessed while exposed, and what additional safeguards have since been introduced.

Whether this was merely embarrassing or exposed officials to a meaningful risk depends on details UKGI has yet to disclose.

Source: The Register — UK government investment arm cops to 40-hour leak of officials' contact details