If you applied for legal aid in England or Wales through the Legal Aid Agency's online service, assume your personal data was taken and check your exposure now. The Ministry of Justice confirmed on 19 May 2025 that attackers downloaded applicant data going back to 2010, including contact details, home addresses, dates of birth, national ID numbers, criminal records, employment status and financial information.
The Legal Aid Agency (LAA) is the government body that funds legal representation for people who cannot afford it. Its online digital service — the system solicitors and barristers use to log work and claim payment — was the entry point. This page sets out what was taken, who is in the dataset, and the specific checks worth making.
Table of Contents
- What happened, and when
- Which of your details were in the dataset
- Who is affected — it is not only criminal defendants
- What to do this week
- Where to complain, and what is still unquantified
- Why the portal you used has changed
- Frequently Asked Questions
What happened, and when
The LAA became aware of a cyber-attack on its online digital services on 23 April 2025, according to Sarah Sackman MP's statement to the Commons on 19 May. The agency took its systems offline between 7 and 11 May to contain the intrusion. The scope changed sharply on 16 May, when the Ministry of Justice found the breach was far more extensive than first understood.
Rather than a payments-system problem affecting providers, the attackers had accessed and downloaded personal data belonging to people who applied for legal aid through the digital service since 2010. That gap matters for anyone tracking the timeline: the public understanding on 12 May and the public understanding on 19 May described two different incidents. The later one is the accurate picture.
Which of your details were in the dataset
GOV.UK's guidance on the incident lists the fields that may have been compromised. They go well beyond a name and email address: Read that list as a fraud toolkit rather than a filing cabinet.
A caller holding your date of birth, your address and the amount you were assessed to contribute can sound exactly like someone from a court, a solicitor's office or a debt recovery firm. The combination of criminal records with home addresses is the element that distinguishes this breach from a routine customer-database leak. It creates a risk of targeted contact, not just generic scam calls.
- Contact details and home addresses
- Dates of birth
- National ID numbers
- Criminal records
- Employment status
Who is affected — it is not only criminal defendants
The Law Society's breach page makes the point directly: family law parties, victims of domestic abuse and other civil applicants sit in the same dataset as criminal defendants. Anyone who applied for legal aid for a divorce, a care proceeding or a housing matter should treat themselves as potentially affected. Later checks indicated the exposure runs deeper than the original 2010 cut-off, with some records reaching back to 2007.
Information about applicants' partners may also have been taken, which means a person who never applied for legal aid themselves can still appear in the data. For anyone who applied while fleeing an abusive partner, the home address field is the one to focus on. If the address held by the LAA is one you still live at, that is the check to make first, and a reason to contact a domestic abuse support service about safety planning rather than treating this as a purely financial matter.
What to do this week
GOV.UK sets out a short list of practical defences for affected applicants, and each one counters a specific tactic the stolen data enables: The independent-verification step does the heaviest lifting. The usual advice to be suspicious of callers who "don't know your details" fails here, because these callers can know your details.
- Be alert to unexpected calls, texts, emails or letters, especially ones referencing a real case or a real payment amount.
- Verify independently the identity of anyone who contacts you — hang up and call the organisation back on a number you looked up yourself, never one the caller supplies.
- Update passwords that may have been exposed, and avoid reusing them across accounts.
- Contact the LAA Customer Services Team on 0300 200 20 20, 9am to 5pm Monday to Friday, if you have received legal aid and are concerned.
Where to complain, and what is still unquantified
The Ministry of Justice is the data controller for the LAA, and it notified the Information Commissioner's Office, which is investigating. That gives you a route beyond the agency itself: you can raise a complaint with the ICO about how your data was handled, as the Law Society notes, rather than relying only on the LAA's own response.
The scale remains the open question. The criminal group claimed to hold 2.1 million pieces of data, a figure reported by The Record that the government has not confirmed. Pieces of data are not people, so that number cannot be converted into a count of affected individuals, and any headline that does so is guessing.
Why the portal you used has changed
Ministers attributed the breach to the fragility of the agency's ageing IT estate, according to PublicTechnology, which is why the response was a rebuild rather than a patch on the existing system. The digital services were replaced rather than simply restored.
Providers were told a new identity and access system, "Sign into Legal Aid Services", would arrive in September, so applicants and their solicitors may be asked to re-authenticate through a different portal. That creates an obvious opening for phishing. A genuine instruction to log in somewhere new is exactly what an attacker holding your case details would imitate — so if you receive a link asking you to re-authenticate for legal aid, reach the service through GOV.UK or your own solicitor instead of clicking it.
Frequently Asked Questions
I applied for legal aid but was refused. Am I in the breach?
The data taken covers people who applied through the digital service, not only those who were granted funding. Treat an unsuccessful application as exposed.
Will the LAA contact me to tell me if my data was taken?
Rather than waiting, you can call the LAA Customer Services Team on 0300 200 20 20 between 9am and 5pm, Monday to Friday, if you have received legal aid and are concerned.
My partner applied for legal aid, not me. Does this affect me?
Possibly. Checks indicated that information about applicants' partners may also have been taken, so the same alertness to unexpected contact applies.
You Might Also Like
- Legal Aid Agency Data Breach: Why the Affected Application Period Now Starts in 2007
- Legal Aid Agency Data Breach: Could a Partner’s Information Be Included?
- What Is New With Government Data Breach News in September 2026? Latest breach notices and security advisories and Key Takeaways