2026 UKGI — staff misconfig; 51 officials’ details public ~40 hours
Data compromised
High-level management information plus names and work email addresses of 51 government officials (UKGI disclosure)
Technical writeup
Verified — UK Government Investments (UKGI) disclosed in its 2025–26 annual report (Guardian coverage Aug 2, 2026) that an internal file containing high-level management information and the names and work email addresses of 51 government officials was publicly accessible for about 40 hours after a staff member did not follow established information-security policies. Exact incident date within the financial year was not published. Escalated to the board and the ICO; external review of controls followed. Confirmed public-sector exposure with attested headcount 51.
Root cause
Staff member failed to follow information-security policies; internal file left publicly accessible (~40 hours) — UKGI annual report / Guardian