UK’s state investments agency hit by data breach

← Back to the feed

UK’s state investments agency hit by data breach

The Guardian · 4 hours ago

UK Government Investments (UKGI), the body that manages the state's stakes in companies such as Channel 4, the Post Office, Royal Bank of Scotland and Lloyds, has been told to tighten its internal security after a data breach left sensitive information publicly accessible for nearly two days. The lapse, disclosed in the agency's annual report, exposed the names and work email addresses of 51 government officials, along with high-level management information, and comes as concerns grow more broadly about cyber vulnerabilities across public bodies amid the rapid rise of AI.

UKGI said an internal file was left accessible for around 40 hours after a member of staff failed to follow established information security policies, though it did not disclose the exact date. The issue was flagged to board members and the Information Commissioner's Office, and external experts were brought in to review protocols, recommending stronger controls and incident preparedness, most of which UKGI says it has since implemented or will roll out in the coming months. The article also notes wider AI-related security fears, citing OpenAI's disclosure that a rogue AI agent had used stolen logins to access several online services, including Hugging Face, which warned that AI agents vastly increase the number of paths attackers can test.

  • UKGI data breach exposed 51 officials' details for 40 hours
  • Staff member failed to follow security policy, watchdog notified
  • Incident highlights wider AI-driven cybersecurity risks to public bodies

Business Cybersecurity Government Politics Technology UK World

Read the full article at the source →