Oxford City Council has confirmed that it has suffered a cyberattack resulting in a breach of personally identifiable information (PII). The attackers gained unauthorised access to databases containing information on current and former council employees , spanning from 2001 to 2022.

The breach was accompanied by an interruption of certain ICT services, causing delays in serving citizens. Although most services have been restored, as stated in a relevant announcement, some information systems remain in the process of restoration.
The Council, which manages essential public services for around 155,000 residents in Oxford, plays a crucial role in areas such as housing, town planning, waste management, environmental health and elections. Its importance is further enhanced by the city’s “international appeal” — notably through the University of Oxford, research institutions and tourism.
See also: Hackers breached insurance company Aflac
According to an official statement posted on the Council's website: "Unfortunately, the attackers managed to gain access to some historical data in older systems."
The preliminary investigation reveals that the data includes personal information of employees who participated in electoral processes organized by the Council between 2001 and 2022. This includes members of polling stations and people involved in vote counting, who are now considered to have had their data exposed.
The investigation is ongoing, with authorities being notified and working closely with cybersecurity experts to investigate the incident. Oxford City Council says it has begun the process of notifying people who may have been affected.
Oxford Council: No evidence of further leakage
Following the recent data breach, the local authority assures that, so far, there is no evidence that the exposed data has been leaked further.
See also: The leak of 16 billion credentials is not due to a new breach
Furthermore, the Council's initial statement states that no indications of a breach of citizens' data have been identified. However, the question remains open as to whether the compromised databases contained citizens' personal data .

The Oxford City Council data breach is worrying, but unfortunately not rare. These attacks are common, especially in public organisations that often manage large reserves of sensitive information and use systems that may not be adequately protected or up to date.
What stands out here is that the attackers allegedly gained access to older information systems, i.e. “historical” data that had likely been neglected from a security perspective. This highlights the importance of comprehensive cybersecurity not only in active systems, but also in legacy environments, which are often forgotten or considered “dormant.”
The positive side is that there are, so far, no indications of a massive data leak or abuse.
See also: 161,000 people affected by Krispy Kreme data breach
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
However, it is crucial to see whether citizens (and not just employees) have ultimately been affected and whether the organization takes extra security measures, such as access control, regular review of old databases, and penetration testing.
Overall, it is a serious reminder for all public and private entities that data security is not only about the present, but also the past.
Source: www.bleepingcomputer.com
