Natural Resources Wales has disclosed a personal data breach involving a spreadsheet containing sensitive diversity information belonging to former and current employees.
The incident affected people employed by Natural Resources Wales (NRW) between April 2013 and March 2018. The organization said the spreadsheet was inadvertently published online, making the information accessible before it was removed.
The exposed data may have included equality-monitoring and diversity details collected from employees. Depending on the individual, the information could include ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities, and other equality-related information.
NRW said not every category of personal data applied to every affected employee. However, the information involved is considered highly sensitive because it could reveal personal characteristics that employees may not expect to be publicly accessible.
The breach was discovered following an internal investigation into the disclosure of the spreadsheet. NRW said it acted immediately after identifying the issue to contain the exposure and determine how the data became available.
Natural Resources Wales Exposes
The organization removed the spreadsheet from the website where it had been published. It also obtained confirmation that the data had been permanently deleted and reviewed other published information to identify similar risks.
NRW reported the incident to the UK Information Commissioner’s Office, the country’s data-protection regulator. The notification was made in accordance with its legal obligations regarding personal data incidents.
Although the organization did not provide technical details about the website, publication process, or spreadsheet access controls involved, the case highlights a common data-exposure risk.
Files uploaded to public websites can contain hidden tabs, metadata, historical records, or sensitive columns that are not intended for public release.
Spreadsheet-related leaks can also occur when organizations fail to apply data classification, review procedures, access restrictions, and content-scanning controls before publishing files online.
Sensitive employee records should be kept separate from public documents and reviewed through a formal approval process before release.
NRW said it has completed a full investigation and continues to review its internal processes and controls to prevent a similar incident from happening again. The agency apologized to affected workers and acknowledged that the breach could cause concern and uncertainty.
At this stage, NRW said it has found no evidence that the exposed information has been misused. However, former and current employees who may have been affected are advised to remain alert for unexpected emails, phone calls, messages, or requests for personal information.
Threat actors can use diversity and employment information to make phishing attempts appear more convincing. For example, an attacker could impersonate a human resources department, benefits provider, or government agency and reference personal details to build trust.
Employees who believe they may have been affected but have not received direct communication from NRW can contact the organization at [email protected].
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Natural Resources Wales Exposes Sensitive Employee Data in Spreadsheet Breach appeared first on Cyber Security News.
