Posted

Data breach at the UK’s state investments agency

The UK Government Investments agency (UKGI) has reported a data breach incident that left confidential information publicly accessible for nearly two days.

According to UKGI’s annual report, an internal file containing high-level management information, as well as the names and work email addresses of 51 government officials, was publicly accessible for approximately 40 hours. The incident was caused by the actions of a staff member who failed to follow established information security policies.

UKGI manages the taxpayers’ interest in a range of companies, including Channel 4 and the Post Office, and previously oversaw the government’s stakes in banks that were bailed out after the 2008 financial crisis (including the Royal Bank of Scotland and Lloyds).

The agency did not disclose the exact date of the incident but stated that it was identified within the past financial year. After the breach was discovered, the information was immediately escalated to board level and reported to the UK’s Information Commissioner’s Office (ICO). UKGI’s leadership engaged external experts to audit its security systems. The specialists recommended strengthening controls and improving incident preparedness. The overwhelming majority of these recommendations have already been implemented or are in the process of being implemented.