▼
UK Incident · No Settlement, Nothing to Claim
This article describes a data breach at a UK government agency. There is no settlement, no
compensation fund, no administrator and no claim form, and no court has ordered anyone to pay
compensation. Figures attributed to the attackers have not been verified by the government. This
page is informational and is not legal advice.
The Legal Aid Agency runs the online service through which people apply for legal aid in England and Wales,
and through which legal aid providers log their work and get paid. On April 23, 2025, the Ministry of
Justice became aware of a cyber-attack on that service. In the days that followed it moved to secure the
system and told providers that some of their details, including financial information, may have been
compromised.
The picture changed on May 16, 2025. The agency discovered the attack was, in its own words, more extensive
than originally understood, and that the group behind it had accessed a large amount of information
relating to legal aid applicants — not just providers. The systems were taken offline that day, and the
breach was announced publicly on May 19, 2025, with a statement to the Commons the same afternoon.
Status
Systems Restored · No Settlement
Discovered April 23, 2025 · full extent found May 16 · announced May 19 · online services since restored.
Who Is Affected
Legal aid applicants, 2007 to May 2025
England and Wales only · applicants' partners may be included in some records · providers were notified separately.
How Long Undetected
About four months
Systems breached December 2024 · data taken from January 2025 · not detected until April 23, 2025.
Can I Claim?
No — nothing to file, and no U.S. equivalent
No settlement, fund, administrator or claim form exists; UK group litigation has been announced but nothing is decided.
The most damaging detail did not come out until well after the breach was announced. The Public Accounts
Committee reported in January 2026 that the attackers first got into the Legal Aid Agency's systems in
December 2024 and were taking data out from January 2025. The Ministry of Justice did not spot anything
until April 23, roughly four months later.
The committee also found the department had known the system was fragile. Vulnerabilities in the agency's
systems had sat on the Ministry of Justice risk register since 2021, and officials told MPs the cyber-attack
risk rating had been extremely high. More than £50 million was spent trying to transform and stabilise
those systems, in rounds reported at £8.5 million, £10.5 million and £32 million. The committee's assessment
was that the money bought improvements — the upgraded systems are what let the agency identify the breach
at all — but not enough of them, and not in time.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
The agency's own account is that the group accessed and downloaded a significant amount of personal data
from people who applied through the digital service between 2007 and May 16, 2025. The categories it named
were contact details and addresses, dates of birth, national ID numbers, criminal history, employment
status, and financial data such as contribution amounts, debts and payments. In some instances information
about applicants' partners may be in the compromised data as well.
The reach back to 2007 was itself a revision. Earlier accounts of the breach put the affected period at
2010 onward; the agency later established that records went back three years further.
No official figure has ever been put on how many people are involved. The government has consistently
described it only as a significant amount of personal data. A number in wide circulation — roughly 2.1
million records — traces back to a claim attributed to the attackers and reported in the press, and the
government has not verified it. It is worth being clear about which of those two things is which: one is
the position of the agency that holds the records, the other is an assertion by the people who took them.
What makes this breach unusual is not the volume but the population. Legal aid applications are made by
people in criminal proceedings, in family court, at risk of losing their homes, and by victims of domestic
abuse. A file linking a name and current address to criminal history and financial hardship is a different
kind of exposure from a leaked email list.
The Ministry of Justice worked with the National Crime Agency and the National Cyber Security Centre and
notified the Information Commissioner's Office, which is the UK's data protection regulator. In May and
June 2025 the department obtained an injunction prohibiting the unlawful use, disclosure or publication of
information taken from the systems. As of its most recent guidance the department has said it has no
indication the data has been released and is continuing to monitor.
Service restoration took roughly a year. Crime Apply and the crime forms came back, and the contingency
measures that let providers grant representation under delegated authority ended on September 30, 2025.
The civil system returned through the Client and Cost Management System, and the Average Payment for Civil
Representation scheme that had kept firms solvent in the interim has closed. Submit a Bulk Claim went live
on February 4, 2026. The department's incident guidance now says the online services providing key
functionality are available and that the contingency processes have been archived.
On compensation, nothing has been resolved. Several UK firms have said publicly that they are preparing
group litigation in the High Court on behalf of affected applicants, which in England and Wales would
typically run under a Group Litigation Order rather than the opt-out class mechanism U.S. readers know.
No court has decided anything, no liability has been established, and the Information Commissioner's Office
has not announced an enforcement outcome against the Ministry of Justice.
Nothing to file. The Legal Aid Agency administers legal aid in England and Wales, and every compromised
record came from an application to that service, so the exposed population is British. U.S. legal aid runs
through the Legal Services Corporation and state and local providers, which had no involvement in this
incident.
The mechanics differ as much as the geography. A UK group claim of this type is opt-in — affected people
individually instruct a solicitor and are added to a managed group — where a U.S. data breach class action
sweeps in everyone who fits the class definition unless they opt out, and typically ends in a fund with a
claim form and a deadline.
For breaches that do work that way, OCA tracks
open data breach settlements
with cash tiers and credit monitoring attached.
The one thing that travels is the advice the agency itself gave: be alert for unexpected messages or calls,
update passwords that may have been exposed, and independently verify the identity of anyone who contacts
you asking for information. Breach notifications are a reliable trigger for impersonation attempts, and
this one was announced publicly rather than by individual letter — which means anyone claiming to write to
you personally about it deserves a second look.
Who was affected by the Legal Aid Agency data breach?
People who applied for legal aid through the Legal Aid Agency's online digital service in England
and Wales between 2007 and May 16, 2025, when the systems were taken offline. The agency has said that
in some instances information about the partners of applicants may also be in the compromised data.
Legal aid providers were affected separately: they were told within days of the April 2025 discovery
that some of their details, including financial information, may have been compromised.
What data was taken in the Legal Aid Agency hack?
The Legal Aid Agency has said the data may have included applicants' contact details and addresses,
dates of birth, national ID numbers, criminal history, employment status, and financial data such as
contribution amounts, debts and payments. That combination is unusually sensitive because legal aid
applications come from people in criminal proceedings, family cases and domestic abuse matters.
How long were the attackers inside the Legal Aid Agency systems?
About four months before anyone noticed. The Ministry of Justice detected unusual activity on
April 23, 2025, but the systems had been breached in December 2024, with data taken from January 2025.
The Public Accounts Committee reported that finding in January 2026.
How many people had data stolen in the Legal Aid Agency breach?
The government has never confirmed a figure, describing it only as a significant amount of personal
data. Media reporting has cited a claim of about 2.1 million records attributed to the attackers
themselves, which the government has not verified. Treat that number as an unverified claim by the
people who carried out the attack rather than an official count.
Can I claim compensation for the Legal Aid Agency data breach?
Not in the United States, and not through any settlement — none exists. There is no fund, no
administrator, no claim form and no deadline. UK solicitors have said they are preparing group
litigation in the High Court, but nothing has been decided and no court has ordered anyone to pay
compensation. Anyone who applied for legal aid in England or Wales and wants official information
should use the Legal Aid Agency's own guidance on GOV.UK.
Will the Legal Aid Agency contact people whose data was taken?
The agency made a public announcement on May 19, 2025 rather than writing to applicants
individually, and urged anyone who had applied for legal aid in the affected period to be alert for
suspicious messages or calls, to update potentially exposed passwords, and to verify independently the
identity of anyone asking for information. Its guidance page on GOV.UK carries the current
position.
Does the Legal Aid Agency breach affect anyone in the United States?
No. The Legal Aid Agency administers legal aid in England and Wales only, and the compromised
records come from applications made to that service. U.S. legal aid is administered separately by the
Legal Services Corporation and state and local providers, which were not involved.
- Legal Aid Agency and Ministry of Justice — news story, "Legal Aid Agency data breach," published May 19, 2025 (GOV.UK).
- Legal Aid Agency and Ministry of Justice — guidance, "Legal Aid Agency cyber security incident," including the data exfiltration injunction and the system restoration updates (GOV.UK).
- Legal Aid Agency — "Legal Aid Agency cyber security incident: frequently asked questions" (GOV.UK).
- Hansard — oral statement by Sarah Sackman MP, Legal Aid Agency cyber-security incident, House of Commons, May 19, 2025.
- Committee of Public Accounts — "Ministry of Justice follow-up: Autumn 2025," reported January 2026, on the December 2024 intrusion, the risk register entry dating to 2021 and the £50m-plus spend.
- National Cyber Security Centre — guidance on protecting yourself after a data breach.
For more class actions keep scrolling below.
Status
Systems Restored · No Settlement or Compensation Scheme
Incident
Cyber-attack on the Legal Aid Agency online digital services
Systems Breached
December 2024 · data taken from January 2025
Detected
April 23, 2025
Full Extent Found
May 16, 2025 · systems taken offline the same day
Publicly Announced
May 19, 2025
Data Controller
Ministry of Justice (Legal Aid Agency)
Affected Period
Legal aid applications made 2007 to May 16, 2025
Jurisdiction
England and Wales
Regulator Notified
Information Commissioner's Office · no enforcement outcome announced