The 2025 Legal Aid Agency breach exposed two very different kinds of personal data, and only one of them can be repaired. Financial details — national insurance numbers, dates of birth, employment status, debts and contribution amounts — are the transactional inputs for identity fraud, and a person can harden accounts and monitor credit against them.
Criminal history cannot be reissued, cancelled or changed, so its exposure carries reputational and coercive risk that no security step undoes. The Legal Aid Agency (LAA) is an executive agency of the UK Ministry of Justice that funds legal representation for people who cannot afford it in England and Wales. Understanding which half of your exposure is fixable is what turns this breach from alarming news into a set of decisions you can actually make.
Table of Contents
- What happened to the Legal Aid Agency's systems
- The financial half — what you can actually mitigate
- Why criminal history sits in a different category
- Who is in the exposed population — and why it is not only defendants
- What the official advice covers, and what it leaves out
- The institutional context
- Frequently Asked Questions
What happened to the Legal Aid Agency's systems
The LAA became aware of a cyber-attack on its online digital services — the systems where legal aid providers log their work and are paid — on 23 April 2025, and took those systems offline on 16 May, according to the official GOV.UK guidance on the incident. On 19 May the Ministry of Justice confirmed that attackers had accessed and downloaded a significant amount of applicant data covering digital legal aid applications from 2007 onward. The categories named were contact details and addresses, dates of birth, national insurance numbers, criminal history, employment status, and financial data including contribution amounts, debts and payments.
The attackers claimed roughly 2.1 million records. MoJ said it could not verify that figure, and instead advised anyone who has applied for legal aid since 2010 to assume they may be affected, as Computer Weekly reported. That advice is deliberately broad: it is a threshold for acting, not an estimate of harm.
The financial half — what you can actually mitigate
The financial fields are the ones with established criminal uses and established defences. A national insurance number, a date of birth, an address and employment details together form the standard identity package used to open credit accounts, take over existing ones, or pass a call-centre identity check.
Contribution amounts and recorded debts add something more specific: they tell a caller what your finances looked like when you applied. A fraudster who can name your contribution figure sounds like the agency, which is precisely what makes a cold call convincing. Practical steps for this half of the exposure:.
- Treat any unexpected call, text or email about legal aid as unverified, and hang up and call back on a number you found yourself.
- Check your credit file for applications you did not make, and consider a credit freeze or protective registration.
- Change passwords on any account that reused credentials, and turn on two-factor authentication where offered.
- Keep the LAA's customer services line, 0300 200 20 20, as your point of contact rather than responding to inbound messages.
Why criminal history sits in a different category
Criminal history is permanent. You cannot be issued a new one the way a bank issues a new card number, which is the core asymmetry in this breach — a point argued in the Law Society's commentary on the incident rather than one MoJ has published. The misuse profile is different too. Financial data is used transactionally: someone takes money and the fraud eventually surfaces on a statement.
Criminal history is used relationally — as leverage in a dispute, as material for harassment, or as grounds for informal discrimination by an employer, landlord or ex-partner who was never entitled to see it. There is no monitoring product for this. Credit monitoring exists because credit files are queryable and generate alerts; there is no equivalent feed telling you that someone has learned about a conviction from twenty years ago. The realistic posture is preparation: knowing what a disclosure would look like, and having a response ready if it happens.
Who is in the exposed population — and why it is not only defendants
Legal aid is means-tested and merits-tested, and it covers far more than criminal defence. The exposed population therefore includes family-law parties, domestic abuse survivors and asylum seekers, as BankInfoSecurity noted in its coverage. For those groups, the most dangerous field in the dataset is not the criminal history or the national insurance number. It is the address.
A survivor who moved to escape an abuser, or an asylum seeker whose location is sensitive, faces a physical-safety risk that no bank action or password change addresses. That is a different response plan entirely. It runs through the organisations that handle safety rather than fraud: a domestic abuse service, a solicitor, or the police where there is a specific threat. Anyone in that position should also assume the address recorded at the time of the application is the one exposed, and check whether it is still current.
What the official advice covers, and what it leaves out
The GOV.UK guidance tells affected people to be alert to unknown messages and phone calls, verify the identity of anyone who makes contact, and update their passwords. That is sound advice — and it is aimed squarely at fraud and social engineering. Read against the data categories MoJ itself published, the gap is visible.
None of those three steps touches criminal history or address exposure. They are the right response to the financial half of the breach and are simply not designed for the other half. MoJ has never published a confirmed count of affected individuals or a breakdown by data category, so there is no basis for assuming criminal history exposure was rare or limited to a subset. The assume-you-are-affected advice applies to every field in the list.
The institutional context
The incident was reported to the Information Commissioner's Office and worked on with the National Crime Agency, the National Cyber Security Centre and the Government Cyber Co-ordination Centre. In the Commons on 19 May 2025, the Minister told MPs that the LAA's systems were known to be fragile, echoing a warning the Law Society had made in 2023 — recorded in the Hansard report of the statement.
That admission matters for anyone weighing what to do next. A known-fragile system holding eighteen years of application data is an argument for treating the 2010 threshold seriously rather than waiting for a personal notification that may never specify what was taken about you.
Frequently Asked Questions
I applied for legal aid before 2010 — am I excluded?
No. MoJ said the downloaded data covers digital applications from 2007 onward; the 2010 date is the threshold it gave for assuming you may be affected, not the limit of the data.
Will the Legal Aid Agency contact me directly?
Do not rely on it, and do not trust an unsolicited message claiming to be from the agency. Use the customer services line, 0300 200 20 20, to make contact yourself.
Does a spent conviction give me any protection here?
Rehabilitation rules govern what must be disclosed in formal settings such as job applications. They do not restrict what someone who has obtained the leaked data can say or do with it.
You Might Also Like
- Legal Aid Agency Data Breach: Why the Affected Application Period Now Starts in 2007
- Legal Aid Agency Data Breach: What Applicants in England and Wales Should Check
- Legal Aid Agency Data Breach: Could a Partner’s Information Be Included?