Scottish Government Prosecutor’s Office Hit by Third‑Party Data Breach, Potentially Affecting Multiple Agencies
What Happened — A Scottish government agency disclosed that a data breach originated from a third‑party service provider used by the Prosecutor’s Office. The breach appears to have exposed personal and case‑related information and may be spreading to other public‑sector bodies that share the same vendor.
Why It Matters for Compliance & Audit Readiness
- This incident exemplifies a failure in vendor‑risk management – a core SOC 2 CC 5.2 control that requires continuous monitoring of third‑party security posture.
- Demonstrates the need for auditable evidence that a service provider complies with your organization’s security policies and contractual safeguards.
- Highlights the importance of having a documented incident‑response workflow that includes third‑party notifications and evidence collection for audit purposes.
Who Is Affected – Government and public‑sector entities, particularly those that rely on shared third‑party IT or data‑processing services.
Recommended Actions
- Map the breach to SOC 2 CC 5.2 (Vendor Management) and ensure you have up‑to‑date third‑party risk assessments.
- Collect and preserve logs, contracts, and communications with the vendor as audit evidence of due diligence.
- Validate that your incident‑response plan includes third‑party breach notification and remediation steps.
Technical Notes – The breach was discovered through anomalous access patterns; the exact vector is not publicly disclosed, but investigators attribute it to inadequate security controls at the third‑party provider. No specific CVE or vulnerability has been identified. Source: Dark Reading