UK government IT so broken it can’t find hack victims
Key Points
- Attackers accessed Legal Aid Agency systems from December 2024 and stole personal data on applicants dating back to 2007, including national insurance numbers, criminal history and financial records
- More than a year later, no affected individual has been contacted because the agency's 48 fragmented IT systems make victims impossible to identify
- MPs found the government's response of a gov.uk notice inadequate, with complaints now with the ICO and litigation underway
- The LAA knew its systems were vulnerable since at least 2021; the government has pledged £200 million to replace them but offers no completion guarantee and no compensation
Thousands of people whose sensitive data was stolen in the Legal Aid Agency cyber-attack have still not been told, because the agency’s fragmented IT systems make it impossible to work out who they are.
That is a key finding of a Justice Committee report published on Friday (17 July) by the House of Commons Justice Committee, which examined the state of legal aid in England and Wales, including the fallout from the 2025 hack.
The Legal Aid Agency (LAA) first detected the attack on its online digital services in April 2025. A month later, it discovered the intrusion was far more extensive than first thought.
Attackers had accessed and downloaded a large volume of personal data submitted through its digital service, covering applicants from 2007 right up to 16 May 2025. The unauthorised access itself began in December 2024, meaning the attackers sat inside the systems undetected for around four months.
The stolen data may include contact details, dates of birth, national insurance numbers, criminal history, employment status and financial information such as contribution amounts, debts and payments. In some cases, data about applicants’ partners was also compromised.
More than a year on, the LAA has not contacted a single affected individual.
The Minister for Courts and Legal Services told MPs that victims were difficult to identify because of the state of the agency’s legacy systems.
The LAA’s chief executive, Jane Harbottle, told the committee the agency runs 48 different IT systems and 100 different components, and that this fragmentation makes it hard to reconstruct an individual’s personal information from the lost data.
Instead of individual notification, the Ministry of Justice informed legal aid providers and posted a notice on gov.uk, an approach it defended to the committee as effective.
MPs disagreed, concluding that the response to informing and safeguarding victims “has not been good enough” and warning that many people may still have no idea their confidential data was stolen.
Some victims have tried to obtain their own breached data from the agency, including special category information and records relating to domestic violence, and failed. Complaints have now reached the Information Commissioner’s Office, and the LAA faces ongoing litigation.
The committee also heard evidence that the Public Accounts Committee reported in January 2026 that the LAA had known since at least 2021 that weaknesses in its IT systems left it vulnerable to attack. The 2024 to 2025 annual report described the agency’s own systems as old and difficult to maintain.
The government has since committed £61 million in 2026, more than double its 2023 to 2024 spend, plus £200 million in additional funding across the spending review period to move off legacy systems entirely.
The minister told MPs she believed this was sufficient, but could not guarantee the work would finish within the spending review period.
The committee has recommended the MoJ accelerate its upgrade plans and publish a timeline to fully replace the agency’s case management system by the end of this parliament.