UK government investment arm cops to 40-hour leak of officials’ contact details

← Back to the feed

UK government investment arm cops to 40-hour leak of officials’ contact details

The Register · 4 hours ago

UK Government Investments (UKGI), the Treasury-owned body that advises ministers on major financial deals, has admitted that an employee's failure to follow security policy left an internal file containing officials' names and work email addresses publicly accessible for around 40 hours. The incident, disclosed in UKGI's annual report and first reported by The Guardian, is notable because UKGI handles sensitive, high-value government transactions, and the organisation has offered few details about the scale of any risk posed to affected staff.

The exposed document contained "high-level management information" plus the names and work email addresses of 51 officials, though UKGI has not said when the leak occurred, where the file was hosted, or whether it was accessed while exposed. The breach did not meet the threshold for mandatory reporting, but UKGI voluntarily notified the Information Commissioner's Office, informed its Audit and Risk Committee, and commissioned an external review, which found its response appropriate and recommended further security improvements, most of which have been implemented or are due soon. The lapse comes despite UKGI's involvement in major deals this year, including the sale of the government's remaining NatWest shares and advising on the Royal Mail takeover.

  • UKGI left 51 officials' names and emails publicly exposed for ~40 hours
  • Breach blamed on staff not following security policy, voluntarily reported to ICO
  • Key details, like where the file was hosted, remain undisclosed

New here? Start with this

UKGI, formerly known as the Shareholder Executive, is the UK government's specialist unit for managing and advising on complex financial dealings involving public money, from privatisations to bank sell-offs. It sits within the Treasury and works on some of the most commercially sensitive transactions the state undertakes, meaning the officials it employs routinely handle confidential material.

The episode being reported concerns a data protection lapse rather than a hack: an internal document containing staff names and email addresses was left accessible online for roughly two days because a member of staff did not follow the organisation's own security rules. Such incidents are usually assessed against thresholds set by the Information Commissioner's Office, the UK's data protection regulator, which decides whether breaches are serious enough to require formal reporting.

The story matters because it raises questions about internal safeguards at a body entrusted with highly sensitive government business, even though the information exposed in this case was limited to contact details rather than financial data. It also sits alongside UKGI's ongoing role in major current transactions, which is part of why scrutiny of its internal practices carries wider significance.

Government Politics UK World

Read the full article at the source →