Scotland's public prosecution service, the Crown Office and Procurator Fiscal Service (COPFS), has alerted approximately 300 staff members that their employment-related data may have been compromised in a cyberattack targeting one of its third-party suppliers. The incident, which COPFS disclosed on Thursday, August 13, 2026, involved an online data maturity assessment completed by the prosecution service in 2025.
The affected supplier, which managed the assessment organized by the Scottish government, detected suspicious activity on its systems on August 5, 2026, and initiated an investigation. COPFS has confirmed that its own internal systems were not compromised in the incident.
The potentially exposed information is limited to data submitted for the assessment, specifically staff names, roles, and work email addresses. COPFS emphasized that the breach is unconnected to casework and did not involve sensitive or confidential case information, assuring that there is no impact on the work of the prosecution service. Staff have been reminded of guidance on responding to potential phishing or scam attempts that might arise from this third-party breach.
According to COPFS, the supplier has implemented measures to secure its systems and is continuing its investigation into the nature of the intrusion and the precise scope of information accessed. COPFS stated it would issue further updates should significant new information become available.
The Scottish government has not confirmed whether the affected supplier utilized Metabase, a business intelligence platform that recently disclosed exploitation of a zero-day vulnerability in its cloud service. This vulnerability could allow attackers to gain administrator access and reach connected databases. Modular laptop maker Framework was among the organizations reportedly affected by the Metabase vulnerability.






