The Legal Aid Agency has confirmed that the recent cyberattack ultimately led to a data breach.

About two weeks ago, the Legal Aid Agency (LAA), which operates under the auspices of the UK Ministry of Justice , notified law firms of a cyberattack.
Around 2,000 organisations – including solicitors, law firms and not-for-profit organisations – provide legal aid services in civil and criminal matters in England and Wales, and are contracted to the LAA. The organisation employs around 1,250 people and is responsible for the operation of the Public Defender Service.
The breach, which was initially detected on April 23, led to the leakage of highly sensitive personal data of thousands of citizens who submitted applications for legal aid through the organization's digital platform.
See also: Nova Scotia Power: Cyberattack led to data breach
The latest estimates show that hackers accessed and possibly downloaded a huge amount of data from 2010 to the present. The information stolen includes contact details, addresses, dates of birth, national identity numbers, criminal records, financial details and employment information of applicants.
The severity of the data breach forced the Legal Aid Agency to temporarily disable its online operations for security reasons. Security analysts warn that the exposed data is particularly valuable to cybercriminals, as it can be exploited in targeted phishing attacks, financial fraud and identity theft.
The investigation into the identity of the perpetrators and the scope of the attack is ongoing.
See also: Coinbase: Revealed a customer data breach
Following the widespread cyberattack on the Legal Aid Agency, authorities are urging those who have submitted applications for legal aid since 2010 to be vigilant for suspicious communications via SMS, telephone or email. Citizens are urged to immediately change their passwords and independently verify the identity of anyone requesting personal information, to reduce the risk of further exploitation.
The agency's chief executive, Jane Harbottle, issued a public apology, describing the breach as "shocking and worrying" for those affected. She said staff were working around the clock with the National Cyber Security Centre to strengthen digital protection and ensure systems are back up and running safely.
“It became clear that in order to protect the service and its users, we needed radical measures. That is why we have taken the decision to close the online service. We have put in place the necessary contingency plans to ensure that those who need legal support and advice can continue to access the help they need during this period.“.
See also: Dior reveals customer data breach

Protective measures to prevent such data breaches:
- Data encryption: All sensitive data must be encrypted (in transit and storage).
- Limited access: Implement a least privilege policy for authorized personnel only.
- Strong password & MFA policies: Mandatory use of complex passwords and multi-factor authentication.
- Regular software updates: Immediate installation of updates and patches to prevent known vulnerabilities.
- Security testing: Frequent penetration tests and vulnerability assessments by external partners.
- Logging and monitoring: Enable full logging and real-time monitoring for early detection of violations.
- Staff training: Awareness programs for phishing, social engineering and proper data management.
- Isolation of critical systems: Separation of critical services from publicly accessible networks.
- Incident response plan: Ready and tested incident response plan for immediate response to a breach.
- Secure cloud infrastructures: Choosing providers with strong security certificates (e.g. ISO 27001, SOC 2).
Source: www.infosecurity-magazine.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
