CSIDB logo
Incident

Milton Keynes Council

Incident posture

Attack window
Jul 2019
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
Milton Keynes Council
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyber attack targeted the planning portal of Milton Keynes Council, prompting officials to take affected systems offline for investigation and implement additional security measures. The council assured no data was compromised but advised residents to submit planning applications or comments via email or phone due to service disruption. The incident was addressed swiftly, with restoration efforts ongoing to resume normal operations.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

5 techniques

Description

On or around July 22, 2019, Milton Keynes Council in Buckinghamshire, England, experienced a cyberattack targeting its planning portal. Council officials detected the breach and took immediate action by taking the affected systems offline to contain the incident and conduct an investigation. A council spokesperson confirmed awareness of the attack and emphasized their rapid response, which included implementing additional security measures. While the council asserted no data was compromised, the disruption necessitated alternative methods for public engagement with planning services. Residents were instructed to submit planning applications or comments via email to [email protected] instead of the offline portal. A telephone contact (01908 252358) was also provided for application-related queries. The council’s public access system displayed a maintenance notification on July 22, masking the ongoing security incident from general users.

The attack’s timeline indicates initial detection occurred shortly before July 18, as the Development Control Panel discussed the breach during a meeting that day. Panel chairman Cllr John Bint explicitly referenced a cyberattack within the preceding 24 hours of the July 18 session. This suggests the intrusion attempt or its effects were identified no later than July 17. Service disruptions persisted through at least July 22, when the maintenance notice remained active. The council’s primary operational impact was the prolonged unavailability of its digital planning portal, forcing reliance on manual processes for application handling. No technical specifics regarding the attack vector, perpetrator identity, or data access attempts were disclosed publicly. Restoration timelines and forensic findings were not detailed in available reporting.

Sources

Sources available to members: 1 source.

CSIDB