Scottish prosecutors cast eye over leaky supplier after staff data exposed
- ID
- 14118
- Status
- summarized
- Published
- 14 Aug 2026, 4:46 PM
- Fetched
- 14 Aug 2026, 5:17 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/14/scottish-prosecutors-cast-eye-over-leaky-supplier-after-staff-data-exposed/5287479
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 14 Aug 2026, 5:20 PM
- Tags
- Audience
- developersdatabase_learnerssaas_founders
What happened
Scotland's prosecution service warned 300 staff that names, roles, and work emails may have been exposed through a supplier breach detected on August 5, tied to an online data maturity assessment. The supplier is unnamed and the intrusion method is unclear, though The Register notes it may be connected to a recently disclosed Metabase cloud zero-day that allowed admin access to connected databases—Framework was also affected.
Why it matters
If you run Metabase Cloud, check whether you were exposed to the zero-day disclosed this month and review what connected databases an admin-level attacker could have reached. The Scottish incident itself is a reminder that data collected for seemingly low-stakes assessments (surveys, maturity exercises) still becomes a breach surface when stored by third parties.
Discussion angle
How much sensitive data do you hand to SaaS tools for internal assessments or surveys, and do you track which vendors hold what—especially BI tools like Metabase that sit directly on top of production databases?