header-logo header-logo

19 May 2025
Issue: 8117 / Categories: Legal News , Legal aid focus , Technology , Cybercrime
printer mail-detail

Applicants at risk in ‘significant’ legal aid security breach

An entire cohort of people who applied for legal aid in the past 15 years has been warned to be on guard following a major cyber-attack at the Legal Aid Agency (LAA)

The LAA said it discovered the attack on 23 April, taking immediate action to bolster security and inform legal aid providers. However, on 16 May, it discovered the attack was more extensive than first thought.

The LAA believes the hackers have accessed and downloaded a ‘significant amount’ of personal data from those who applied for legal aid through its digital service since 2010.

This data may include contact details and addresses of applicants, their dates of birth, national ID numbers, criminal history, employment status and financial data such as contribution amounts, debts and payments.

Jane Harbottle, the LAA’s chief executive officer, said: ‘I understand this news will be shocking and upsetting for people and I am extremely sorry this has happened.’

In a statement, the LAA advised all those potentially affected to be ‘alert for any suspicious activity such as unknown messages or phone calls and to be extra vigilant to update any potentially exposed passwords’. It warned against providing information to anyone contacting them unless they had first independently verified their identity.

Colin Witcher, barrister at Church Court Chambers, said: ‘As a result of this recent attack, a review of the LAA's data retention policy will be required as, notably, personal material has been accessed and downloaded dating back to 2010, bringing into question why this data was still retained and accessible.’

Law Society president Richard Atkinson said: ‘The incident once again demonstrates the need for sustained investment to bring the LAA’s antiquated IT system up to date and ensure the public have continued trust in the justice system.

‘The fragility of the IT system has prevented vital reforms, including updates to the means test that could help millions more access legal aid, and interim payments for firms whose cashflow is being decimated by the backlogs in the courts, through no fault of their own. If it is now also proving vulnerable to cyber-attack, further delay is untenable.’
Issue: 8117 / Categories: Legal News , Legal aid focus , Technology , Cybercrime
printer mail-details

MOVERS & SHAKERS

Bellevue Law—Lianne Craig

Bellevue Law—Lianne Craig

Workplace law firm expands commercial disputes team with senior consultant hire

EIP—Rob Barker

EIP—Rob Barker

IP firm promotes patent attorney to partner

Muckle LLP—Ryan Butler

Muckle LLP—Ryan Butler

Banking and restructuring team bolstered by insolvency specialist

NEWS
A High Court ruling involving the Longleat estate has exposed the fault line between modern family building and historic trust drafting. Writing in NLJ this week, Charlotte Coyle, director and family law expert at Freeths, examines Cator v Thynn [2026] EWHC 209 (Ch), where trustees sought approval to modernise trusts that retain pre-1970 definitions of ‘child’, ‘grandchild’ and ‘issue’
Fresh proposals to criminalise ‘nudification’ apps, prioritise cyberflashing and non-consensual intimate images, and even ban under-16s from social media have reignited debate over whether the Online Safety Act 2023 (OSA 2023) is fit for purpose. Writing in NLJ this week, Alexander Brown, head of technology, media and telecommunications, and Alexandra Webster, managing associate, Simmons & Simmons, caution against reactive law-making that could undermine the Act’s ‘risk-based and outcomes-focused’ design
Recent allegations surrounding Peter Mandelson and Andrew Mountbatten-Windsor have reignited scrutiny of the ancient common law offence of misconduct in public office. Writing in NLJ this week, Simon Parsons, teaching fellow at Bath Spa University, asks whether their conduct could clear a notoriously high legal hurdle
A landmark ruling has reshaped child clinical negligence claims. Writing in NLJ this week, Jodi Newton, head of birth and paediatric negligence at Osbornes Law, explains how the Supreme Court in CCC v Sheffield Teaching Hospitals NHS Foundation Trust [2026] UKSC 5 has overturned Croke v Wiseman, ending the long-standing bar on children recovering ‘lost years’ earnings
A Court of Appeal ruling has drawn a firm line under party autonomy in arbitration. Writing in NLJ this week, Masood Ahmed, associate professor at the University of Leicester, analyses Gluck v Endzweig [2026] EWCA Civ 145, where a clause allowing arbitrators to amend an award ‘at any time’ was held incompatible with the Arbitration Act 1996
back-to-top-scroll