Yes. The Ministry of Justice has confirmed that a partner's personal information may be among the data stolen in the Legal Aid Agency (LAA) cyber-attack, stating in its official breach announcement that "in some instances, information about the partners of legal aid applicants may be included in the compromised data." Partners are therefore inside the stated scope of the breach, even though they never applied for legal aid themselves. The Legal Aid Agency is the government body that funds legal representation for people who cannot afford it. Its online application service holds the financial and personal records of everyone assessed for that funding — and, because of how the assessment works, the people they live with.
Table of Contents
- Why a partner's details were on file at all
- What kind of information was exposed
- The window: who falls inside it
- No individual notifications — and what that means for you
- Practical steps for a partner
- How long the attackers were inside
- Frequently Asked Questions
Why a partner's details were on file at all
Legal aid is means-tested, and the means test does not stop at the applicant. LAA guidance on civil legal aid means testing tells caseworkers to "check if your client has a partner whose income should be included," and a partner's income and capital are normally assessed alongside the applicant's. That aggregation is the entire reason partner data exists in these systems. To decide whether a household falls below the eligibility threshold, the agency needed the partner's earnings, savings and outgoings.
Those figures were recorded in the application, and the application is what was taken. There are defined exceptions. The LAA's Means Assessment Guidance for April 2025 excludes a partner's means where that partner has a contrary interest in the dispute — an opponent in a matrimonial case, for example — or where the couple are permanently separated. Applicants in those categories are less likely to have partner information sitting in their file.
What kind of information was exposed
The Ministry of Justice's guidance on the incident states that the data accessed and downloaded may have included: Not every field applies to a partner in the same way. The means test drives the financial and employment entries, so those are the categories most likely to describe a partner directly.
Contact details and dates of birth commonly appear too, because an application identifies the person whose income is being counted. The combination matters more than any single field. Address, date of birth and financial position together are exactly what someone needs to open an account in another person's name or to build a convincing impersonation call.
- Contact details and addresses
- Dates of birth
- National ID numbers
- Criminal history
- Employment status
The window: who falls inside it
The exposure covers people who applied through the LAA's digital service between 2007 and 16 May 2025, when systems were taken offline. That range is wider than the MoJ first announced: the department extended it from an original "since 2010" after further investigation, in the same update that added partners' data to the scope. So the relevant question for a partner is not whether they remember a breach notice.
It is whether the person they were with applied for legal aid online at any point in that eighteen-year period. A relationship that ended a decade ago can still have left a record. The attackers claimed to hold 2.1 million pieces of data. According to the Law Society Gazette, the MoJ has not verified that figure and describes the loss only as a "significant amount" of personal data.
No individual notifications — and what that means for you
The MoJ has said it cannot confirm precisely whose data was compromised, and it has not issued person-by-person notifications. Its advice is addressed to everyone who applied in the window rather than to a confirmed list of victims. For partners, that has a practical consequence.
Nobody is going to write to you to say your income details were in the stolen set, and the absence of a letter is not evidence that they were not. The sensible posture is to treat your data as potentially exposed if your partner applied during the covered period, and act accordingly. This also shapes what a phone call or email from "the LAA" is worth. An organisation that cannot identify individual affected records is not going to ring you about your specific file — which makes any such contact a strong signal of a scam.
Practical steps for a partner
The MoJ directs affected people to the National Cyber Security Centre's data breach guidance. The core actions: Queries go to the LAA Customer Services Team on 0300 200 20 20, 9am to 5pm Monday to Friday, or by email to [email protected]. The incident is also under investigation by the Information Commissioner's Office.
- Change any password that was exposed, and any password reused elsewhere.
- Be alert to unexpected calls, texts and emails, particularly ones that reference your finances or a legal matter.
- Verify anyone claiming to be from the LAA before giving them information — call back on a number you looked up yourself.
- Watch for account-opening activity and unfamiliar credit applications, since dates of birth and addresses were in scope.
How long the attackers were inside
The timeline explains why the stolen set is so broad. The Law Society Gazette reports that the intrusion began in December 2024, with data exfiltration running from January 2025, and was not detected until 23 April 2025 — roughly four months of undetected access. That length of dwell time is the difference between a snatched file and a systematic harvest.
It gave the attackers room to work through historic records rather than only current ones, which is consistent with a window reaching back to 2007. The disruption ran long after detection. LAA civil systems — the Client and Cost Management System, or CCMS, which solicitors use to apply for and bill civil legal aid — were only fully restored on 1 December 2025.
Frequently Asked Questions
My partner applied for legal aid but we have since separated. Is my data still at risk?
Possibly. Records from applications made between 2007 and 16 May 2025 are in scope regardless of whether the relationship continued. The exception is where you were permanently separated at the time of the application, or had a contrary interest in the dispute, since the LAA would not then have assessed your means.
Can I find out whether my specific details were taken?
No. The Ministry of Justice has stated it cannot confirm precisely whose data was compromised, and it has not issued individual notifications. Its guidance is aimed at everyone who applied in the covered period.
Someone claiming to be from the Legal Aid Agency has contacted me. What should I do?
Do not give them any information. Verify the contact independently by calling the LAA Customer Services Team on 0300 200 20 20 during office hours, using that number rather than any number the caller provides.
You Might Also Like
- Legal Aid Agency Data Breach: Why the Affected Application Period Now Starts in 2007
- What Is New With Government Data Breach News in September 2026? Latest breach notices and security advisories and Key Takeaways
- Social Blade Data Breach: What Was Exposed and What to Do Now