The Crown Office and Procurator Fiscal Service (COPFS) has disclosed a data security incident involving a third-party supplier, in a statement issued on 13 August 2026.
What COPFS says happened
According to the statement:
“This is not a breach of COPFS systems. There is no evidence that the incident has had any impact on confidential casework or the operational work of the Service.
“There is currently no evidence that information relating to cases, victims, witnesses or members of the public has been affected.”
What was affected
COPFS says the affected data comes from a Scottish Government-organised survey run last year:
“Last year, COPFS participated in an online data maturity assessment organised by the Scottish Government and managed by an external supplier. The information affected is limited to employment-related information connected with that survey, such as names, roles and work email addresses.”
Timeline
COPFS reports that the external supplier “became aware of suspicious activity on 5 August and immediately began investigating the incident.”
“Steps were taken to secure systems, establish how the breach occurred and identify what information may have been accessed.”
Investigation ongoing
The statement concludes: “The supplier’s investigation remains ongoing and further work is underway to establish the full circumstances of the incident. We will provide updates should any significant new information emerge.”
COPFS has not named the third-party supplier in its statement.