Skip to main content

Written question asked by Iqbal Mohamed (Independent (affiliation)) on Wednesday, 10 June 2026, in the House of Commons. It was due for an answer on Monday, 15 June 2026. It was answered by Sarah Sackman (Labour) on Friday, 19 June 2026 on behalf of the Ministry of Justice.


Legal Aid Agency: Cybersecurity

Question

To ask the Secretary of State for Justice, what categories of personal data were accessed or exfiltrated during the April 2025 Legal Aid cyber security breach; and was data relating to domestic abuse survivors, asylum seekers or criminal defendants affected.

Answer

We take the security of people’s personal data extremely seriously.

We are working hard to identify those whose data may have been stolen by the criminal attackers. Given the scale of the services the LAA delivers, the timespan of the data involved, and the fragmented, unstructured, and incomplete way that data is stored on our systems, this is a complicated and challenging task. In many cases the identification of specific individuals may not be possible.

The MoJ and the LAA have been working urgently to assess who may have had their data breached. We anticipate being in a better position to outline how many people were potentially impacted by the cyber-attack later this month.

We identified a breach on 23 April 2025 and took immediate action to tell legal aid providers as the evidence available at the time suggested they were the impacted cohort. At this time there was no clear evidence that data relating to legal aid recipients had been accessed.

On Friday 16 May, we discovered the attack was more extensive than originally understood and that the criminal group behind it had accessed a large amount of information relating to legal aid applicants.

To ensure transparency about the cyber-attack and that we reached as many potentially impacted individuals as possible, the MoJ published a notice at 08:15 on 19 May on GOV.UK. A public statement was considered a necessary and effective means of notifying any potentially impacted individuals given the scale of the attack, and the inherent risks associated with historic data.

The notice provided information about the cyber-attack and directed concerned members of the public to the National Cyber Security Centre’s (NCSC) webpage, which contained information on how to protect against the impact of a data breach.

The LAA also set up dedicated Customer Services support via a telephone line and email for providers and clients who had concerns regarding the data breach, in line with NCSC guidance. Throughout this timeframe, we were in regular contact with providers to give them updates as soon as we could.

The published statement referred to above clarifies that the compromised data may have included contact details and addresses of applicants, their dates of birth, national ID numbers, criminal history, employment status and financial data such as contribution amounts, debts and payments. In some instances, information about the partners of legal aid applicants may be included in the compromised data. As far as we are aware, no data has been shared or put out in the public domain.

Relevant law enforcement agencies continue to monitor for this, including the “dark web”. An injunction has been put in place to prohibit the unlawful use, disclosure, publication or communication of this data. Anyone who does so could be sent to prison. If it is identified that a specific individual is at risk, such as a domestic abuse survivor, action will be taken to try to contact them, working closely with the relevant authorities. The Information Commissioner’s Office (ICO) is aware of our current approach to notifying individuals and that we continue to assess the situation as further information becomes available.


Secondary information

Type
Written question
Reference
8849
Session
2026-27
Grouped for answer
Yes
Subjects
ICT Data protection Crime Asylum Domestic abuse Legal Aid Agency Cybersecurity
Link
View this Written question on www.parliament.uk