The Legal Aid Agency (LAA), which operates under the auspices of the UK, has informed law firms of a cyberattack, indicating that sensitive financial data.

Around 2,000 organisations – including solicitors, law firms and not-for-profit organisations – provide legal aid services in civil and criminal matters in England and Wales, and are contracted to the LAA. The organisation employs around 1,250 people and is responsible for the operation of the Public Defender Service.
See also: Ransomware attacks decrease in April (+ most significant incidents)
In a letter to law firms, the agency said it was unable to confirm whether data had been leaked, but admitted that there was a possibility that information related to payments to legal aid providers had been exposed (as first reported by Sky News).
“The incident is being investigated in accordance with established data security, and mitigation measures have already been adopted,” the letter noted. “The LAA takes the security of the information it holds extremely seriously and recognizes the potential impact a breach could have on its partners.”
The National Crime Agency (NCA) confirmed to BleepingComputer that it is working closely with the Ministry of Justice and the National Cyber Security Centre to investigate the incident and support the Legal Aid Agency's investigations.
See also: What are zero-click attacks – how to avoid them
Cyberattacks on the retail sector in the United Kingdom
The incident comes after a series of attacks targeting major UK chains including Co-op, Harrods and Marks & Spencer (M&S). The attacks are believed to be carried out by the ransomware DragonForce, and according to BleepingComputer, the attackers used the same social engineering method to breach the systems of Co-op and M&S.

A few days ago, M&S was hit by a ransomware attackthat used techniques reminiscent of those used by the Scattered Spider. The cyberattack severely affected online ordering, contactless transactions and the Click & Collect service.
The Co-op has restricted access to its corporate VPN after a similar incident, while confirming that cybercriminals had obtained data relating to a large number of its current and former members.
On May 1, Harrods also announced that it had cut off internet access for some services in response to an attempted network breach. While the breach has not been officially confirmed, the action suggests an ongoing threat.
See also: Ukrainian extradited to the US for Nefilim ransomware attacks
Following these attacks, the UK's National Cyber Security Centre (NCSC) has issued guidance to all organisations in the countryto strengthen their security measures, warning that such cyberattacks should serve as a warning to all businesses, as any of them could become the next target.
These developments confirm the need for systematic staff training on social engineering issues, continuous vulnerability checks and review of incident response plans . Prevention must be placed at the center of every enterprise's cybersecurity strategy.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
