Policy

UK's State Investments Agency Hit by Data Breach Affecting 51 Government Officials

Security lapse leaves sensitive information and contact details of 51 government officials exposed for 40 hours, the Guardian reports.

R
By Ravi Menon Security Correspondent
August 3, 2026 / 5 min read

The public body in charge of the UK's state investments has been pushed to improve its internal security after a data breach left "high-level management information" publicly accessible for 40 hours, the Guardian reported on August 2. The breach affected 51 government officials.

What Happened

The British Business Bank, which manages the UK's state investments, accidentally made a portion of its internal SharePoint accessible without authentication. The exposure included names, contact details, and certain internal documents related to senior government officials. The bank closed the access gap within 40 hours after being notified.

"The public body in charge of the UK's state investments has been pushed to improve its internal security after a data breach left 'high-level management information' publicly accessible for 40 hours," the Guardian wrote.

Why It Matters

The breach is one of several recent incidents that have raised questions about the UK government's data-handling practices. The Information Commissioner's Office is investigating. The bank has committed to an internal review and additional staff training. Opposition MPs have called for a wider review of how UK public bodies handle sensitive data.

What's Next

The ICO investigation will determine whether the bank breached UK GDPR. If so, the bank could face a fine - the ICO has issued several significant fines for similar incidents in recent years. The bank has also engaged an external cybersecurity firm to review its systems. The breach is the latest reminder that even basic misconfigurations can expose sensitive government data.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.