header-logo header-logo

Applicants at risk in ‘significant’ legal aid security breach

19 May 2025
Issue: 8117 / Categories: Legal News , Legal aid focus , Technology , Cybercrime
printer mail-detail
An entire cohort of people who applied for legal aid in the past 15 years has been warned to be on guard following a major cyber-attack at the Legal Aid Agency (LAA)

The LAA said it discovered the attack on 23 April, taking immediate action to bolster security and inform legal aid providers. However, on 16 May, it discovered the attack was more extensive than first thought.

The LAA believes the hackers have accessed and downloaded a ‘significant amount’ of personal data from those who applied for legal aid through its digital service since 2010.

This data may include contact details and addresses of applicants, their dates of birth, national ID numbers, criminal history, employment status and financial data such as contribution amounts, debts and payments.

Jane Harbottle, the LAA’s chief executive officer, said: ‘I understand this news will be shocking and upsetting for people and I am extremely sorry this has happened.’

In a statement, the LAA advised all those potentially affected to be ‘alert for any suspicious activity such as unknown messages or phone calls and to be extra vigilant to update any potentially exposed passwords’. It warned against providing information to anyone contacting them unless they had first independently verified their identity.

Colin Witcher, barrister at Church Court Chambers, said: ‘As a result of this recent attack, a review of the LAA's data retention policy will be required as, notably, personal material has been accessed and downloaded dating back to 2010, bringing into question why this data was still retained and accessible.’

Law Society president Richard Atkinson said: ‘The incident once again demonstrates the need for sustained investment to bring the LAA’s antiquated IT system up to date and ensure the public have continued trust in the justice system.

‘The fragility of the IT system has prevented vital reforms, including updates to the means test that could help millions more access legal aid, and interim payments for firms whose cashflow is being decimated by the backlogs in the courts, through no fault of their own. If it is now also proving vulnerable to cyber-attack, further delay is untenable.’
Issue: 8117 / Categories: Legal News , Legal aid focus , Technology , Cybercrime
printer mail-details

MOVERS & SHAKERS

Muckle LLP—Stacey Brown

Muckle LLP—Stacey Brown

Corporate governance and company law specialist joins the team

Excello Law—Heather Horsewood & Darren Barwick

Excello Law—Heather Horsewood & Darren Barwick

North west team expands with senior private client and property hires

Ward Hadaway—Paul Wigham

Ward Hadaway—Paul Wigham

Firm boosts corporate team in Newcastle to support high-growth technology businesses

NEWS

NOTICE UNDER THE TRUSTEE ACT 1925

HERBERT SMITH STAFF PENSION SCHEME (THE “SCHEME”)

NOTICE TO CREDITORS AND BENEFICIARIES UNDER SECTION 27 OF THE TRUSTEE ACT 1925
Law firm HFW is offering clients lawyers on call for dawn raids, sanctions issues and other regulatory emergencies
From gender-critical speech to notice periods and incapability dismissals, employment law continues to turn on fine distinctions. In his latest employment law brief for NLJ, Ian Smith of Norwich Law School reviews a cluster of recent decisions, led by Bailey v Stonewall, where the Court of Appeal clarified the limits of third-party liability under the Equality Act
Non-molestation orders are meant to be the frontline defence against domestic abuse, yet their enforcement often falls short. Writing in NLJ this week, Jeni Kavanagh, Jessica Mortimer and Oliver Kavanagh analyse why the criminalisation of breach has failed to deliver consistent protection
Assisted dying remains one of the most fraught fault lines in English law, where compassion and criminal liability sit uncomfortably close. Writing in NLJ this week, Julie Gowland and Barny Croft of Birketts examine how acts motivated by care—booking travel, completing paperwork, or offering emotional support—can still fall within the wide reach of the Suicide Act 1961
back-to-top-scroll