The public body in charge of the UK’s state investments has been pushed to improve its internal security after a data breach left “high-level management information” publicly accessible for nearly two days.
UK Government Investments (UKGI), the agency that manages the taxpayers’ interest in a swathe of companies including Channel 4 and the Post Office, said the security failure also left more than 50 government officials’ personal details exposed for nearly 40 hours.
The state body, best known for managing government holdings in bailed-out lenders Royal Bank of Scotland and Lloyds after the 2008 financial crisis, blamed the breach on an unnamed staff member who it said failed to follow security rules.
“An internal file containing high-level management information and the names and work email addresses of 51 government officials was publicly accessible for [about] 40 hours, following the actions of a member of staff who did not follow established information security policies,” UKGI said in its annual report.
It stopped short of divulging the date of the security failure but said it had been identified within the past financial year, after which it was escalated to board members and also to the UK’s information watchdog, the Information Commissioner’s Office.
Bosses also hired external experts to review security protocols, who suggested the body “strengthen our controls and incident preparedness”.
“The overwhelming majority of which UKGI has since implemented or will be implementing in the coming months,” UKGI said.
The incident will be a wake-up call for public agencies, at a time when the rapid rise of AI has prompted fresh fears over how the frontier technology could exploit security gaps.
Open AI recently said that a rogue AI agent – an autonomous tool able to carry out sequences of commands without human help – had located and used logins to access four unnamed “publicly available services” in addition to the US startup Hugging Face, a company that hosts a database of AI models.
after newsletter promotion
Hugging Face said a human attacker could have found and exploited the same flaws, but the difference was the sheer scale of the agent’s attempts to find a way through. “Agents bring a steep increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret,” it added.

6 hours ago
12

















































