The UK Government Investments (UKGI) agency has been forced to strengthen its internal security after a data breach left "high-level management information" publicly accessible for nearly two days, reports infohub.kz.

UKGI, which manages the taxpayer's interest in companies including Channel 4 and the Post Office, said the security failure also exposed the personal details of more than 50 government officials for nearly 40 hours.

The state body, best known for managing government holdings in bailed-out lenders Royal Bank of Scotland and Lloyds after the 2008 financial crisis, blamed the breach on an unnamed staff member who failed to follow security rules.

In its annual report, UKGI stated: "An internal file containing high-level management information and the names and work email addresses of 51 government officials was publicly accessible for approximately 40 hours, following the actions of a member of staff who did not follow established information security policies."

The agency did not disclose the exact date of the security failure but said it was identified within the past financial year, after which it was escalated to the board and the UK's Information Commissioner's Office.

Management hired external experts to review security protocols, who recommended the agency "strengthen our controls and incident preparedness". UKGI said it has already implemented most of these recommendations or will do so in the coming months.

This incident serves as a warning for public agencies, as the rapid rise of artificial intelligence raises concerns about potential exploitation of security gaps. OpenAI recently reported that a rogue AI agent – an autonomous tool capable of executing sequences of actions without human help – located and used logins to access four unnamed "publicly available services" in addition to the US startup Hugging Face. Hugging Face noted that a human attacker could have found and exploited the same flaws, but the difference lies in the scale of the agent's attempts. "Agents bring a steep increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret," it added.