Supply chain
β Supply Chain
2,000 providers, including barristers, solicitor firms, and non-profit organizations Third-Party Breach (May 2025)
Primary Source βIncident Details
UK Legal Aid Agency investigates cybersecurity incident. The Legal Aid Agency (LAA), an executive agency of the UK’s Ministry of Justice that oversees billions in legal funding, warned law firms of a security incident and said the attackers might have accessed financial information. Approximately 2,000 providers, including barristers, solicitor firms, and non-profit organizations, deliver civil and criminal legal aid services in England and Wales under contracts with the LAA. The agency employs around 1,250 staff and runs the country’s Public Defender Service. In a letter sent to law firms, the agency said it cannot confirm if any data was accessed. Still, it acknowledged the risk that legal aid providers’ payment information might have been compromised, as Sky News first reported. Third-party company: Legal Aid Agency (LAA).
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Legal Aid Agency (LAA)
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-05-01 Breach occurred
- 2025-05-06 Publicly disclosed