The United Kingdom’s state investment agency has been urged to strengthen its internal security measures after a data breach exposed sensitive management information to the public for almost two days.
UK Government Investments, which oversees the government’s stakes in several companies, including Channel 4 and the Post Office, disclosed that the incident also exposed the personal information of more than 50 government officials for nearly 40 hours.
The agency, known for managing the government’s shareholdings in Royal Bank of Scotland and Lloyds following the 2008 global financial crisis, attributed the breach to an employee who failed to comply with established security protocols.
“An internal file containing high-level management information and the names and work email addresses of 51 government officials was publicly accessible for [about] 40 hours, following the actions of a member of staff who did not follow established information security policies,” UKGI said in its annual report.
UKGI did not disclose when the security breach occurred but said it was detected during the last financial year. The incident was subsequently reported to the agency’s board and the UK’s data protection regulator, the Information Commissioner’s Office.
Following the breach, the agency engaged independent cybersecurity experts to assess its security framework. The review recommended that UKGI reinforce its internal controls and enhance its preparedness to respond to future security incidents.
“The overwhelming majority of which UKGI has since implemented or will be implementing in the coming months,” UKGI said.
The incident is expected to serve as a stark reminder for public sector organisations to tighten their cybersecurity defences, particularly as the rapid advancement of artificial intelligence heightens concerns that sophisticated AI tools could exploit existing security vulnerabilities.
