Data leak

UK Legal Aid Agency Breach (2,000 Legal Service Providers)

πŸ“… 2025-04-01
Primary Source β†—

Incident Details

In May 2025, the UK Legal Aid Agency (part of the Ministry of Justice) disclosed a significant data breach affecting information on 2,000 legal service providers and their clients. The exposed data included names, dates of birth, National Insurance numbers, criminal records, and detailed financial information about legal aid applicants. The Legal Aid Agency provides public funding for legal representation in England and Wales; the breach affected sensitive client records spanning many years of applications. The attacker gained access through the agency’s online portal and exfiltrated a substantial volume of personal and financial data. The UK’s National Cyber Security Centre (NCSC) assisted with incident response.

Technical Details

Initial Attack Vector
Attackers exploited an unpatched vulnerability in the Legal Aid Agency's online portal to gain unauthorized access to its database

Timeline

  1. 2025-04-01 Breach occurred
  2. 2025-05-19 Publicly disclosed
  3. 2025-05-19 Customers notified