CSIDB logo
Incident

Legal Aid Agency

Incident posture

Attack window
Dec 2024
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-01-30 16:01

Linked entities

Victim
Legal Aid Agency
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack compromised the Legal Aid Agency's online portal, leading to unauthorized access of legal aid providers' information and sensitive personal data from citizens over a multi-year period. The incident caused significant service disruptions, prompting a phased restoration and migration to a new identity management system for all providers, while recovery efforts accelerated plans to modernize technology infrastructure and replace legacy systems with more resilient solutions.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

The cyberattack on the Legal Aid Agency (LAA) began on New Year’s Eve 2024 when attackers exploited vulnerabilities in the agency’s online portal to breach its security systems. The intrusion remained undetected until April 2025, when officials discovered unauthorized access. Following the discovery, the LAA initiated an extensive shutdown of digital services starting in May 2025 to contain the breach. Ministers confirmed that attackers had compromised a broad range of data, including information on legal aid providers and sensitive personal details of citizens who had applied for legal support over a 15-year period. This data exposure represented a significant breach of privacy and operational security, affecting both institutional stakeholders and individual applicants. The prolonged service shutdown disrupted legal aid processes, forcing the agency to implement business continuity measures to maintain critical functions while systems were offline.

Recovery efforts commenced with a phased restoration of services in September 2025. By January 2026, all legal aid providers had transitioned to a new identity management system integrated into the LAA’s digital portal, enabling the agency to decommission most temporary continuity measures. Courts Minister Sarah Sackman reported that platforms supporting crime applications and crime billing had been restored, along with the main civil legal aid system. The incident accelerated the LAA’s modernization agenda, with ministerial directives to replace restored systems with resilient technology. Ministry of Justice Chief Digital and Information Officer Mark Thompson acknowledged the attack’s disruptive impact but noted it expedited policy and operational changes that otherwise might have taken years to implement. The restoration process addressed legacy technical and procedural challenges, reinforcing the agency’s focus on long-term transformation alongside immediate recovery.

Sources

Sources available to members: 1 source.

CSIDB