UK Government Investments, the public body at the helm of state investments, disclosed that it had suffered a data breach that left private information accessible to the public for almost 40 hours.
The agency is now being pushed to improve its security after “high-level management information” was left accessible in a data breach, exposing the personal details of more than 50 government officials in the breach.
The investment body manages taxpayers interests in a range of companies, and is most known in the UK for bailing out Lloyds Banking Group and the Royal Bank of Scotland following the 2008 market crash.
The group pinned the blame on an internal incident, saying a staff member – who remains unnamed – did not follow security protocols.
“An internal file containing high-level management information and the names and work email addresses of 51 government officials was publicly accessible for [about] 40 hours, following the actions of a member of staff who did not follow established information security policies,” the body said in its annual report.
UK Government Investments has yet to say exactly when the data breach took place, though it said that it took place in the last financial year.
Recommended reading
- Report: Cyber Breaches Are Tanking Share Prices
- Human Error Costing UK Business Billions in Data Breach Losses
- Inside the Aftermath: What Really Happens When You Get Hacked
- Report: 93% of Data Breaches Expose Financial Records
The public body did inform board members and the Information Commissioner’s Office of the incident at the time and hired external specialists to review their internal security policies.
UKGI said that it has “since implemented or will be implementing in the coming months” the “overwhelming majority” of what has been suggested to improve the body’s incident preparedness.





