The Legal Aid Agency data breach now covers applications going back to 2007 because the Ministry of Justice widened the affected period on 31 July 2025, after further forensic work showed data from that year may have been accessed. The MoJ's updated notice, reported by the Law Society Gazette, states plainly: "Previously we stated the data went back to 2010." The Legal Aid Agency (LAA) is the Ministry of Justice body that decides who gets government-funded legal help in England and Wales. The revision means anyone who applied for legal aid between 2007 and 16 May 2025 — an 18-year window — may have had personal data stolen, and information about applicants' partners was pulled into scope at the same time.
Official resources:
- Explore the official data from Gov — Use this primary source to review the underlying data.
- Apply through Co’s official page — Use this page to review requirements and apply directly.
Table of Contents
- What changed in July 2025
- How the breach unfolded
- What data was taken, and how many people it touches
- What to do if you applied for legal aid since 2007
- Frequently Asked Questions
What changed in July 2025
When the breach was first confirmed in May 2025, the LAA said the stolen data covered applications from 2010 onwards. On 31 July 2025 the MoJ revised that, stating that "further investigations have shown that some data going back to 2007 may have been accessed as well as information linked to the partners of applicants," per the Law Society Gazette. The Law Society confirmed the LAA told it the compromised data now covers client information from 2007 to 16 May 2025.
Two groups were added at a stroke: applicants from 2007–2009 who had previously been outside the stated window, and partners of applicants whose details sat on application files. The MoJ's wording matters. It says data going back to 2007 "may have been accessed" — the agency has not confirmed that every record in the period was taken, and as of the July update the Law Society reported no evidence the stolen data had been published.
How the breach unfolded
The LAA first became aware of an attack on its online digital services on 23 April 2025. By 16 May 2025 it had confirmed the attackers downloaded a "significant amount" of personal data on legal aid applicants, according to GOV.UK's incident guidance. The agency took its digital services offline and brought in the National Crime Agency and the National Cyber Security Centre.
A later disclosure reported by the Law Society Gazette found the hackers had first breached LAA systems around four months before the attack was detected. That long dwell time is why the picture kept changing: the 2007 start date, like the partner data, emerged only through progressive forensic investigation rather than being known on day one. LAA chief executive Jane Harbottle apologized publicly: "I understand this news will be shocking and upsetting… I am extremely sorry this has happened.".
What data was taken, and how many people it touches
The compromised data may include names, contact details and addresses, dates of birth, national ID and National Insurance numbers, criminal history, employment status, and financial data such as contribution amounts, debts and payments. Since the July revision, information about applicants' partners is in scope in some cases. The scale is large.
The attackers claimed to have accessed about 2.1 million pieces of data, and with roughly 360,000 legal aid applications processed in 2023–24 alone, Computer Weekly reported the breach potentially reaches millions of people across the full period. This population is unusually exposed. Legal aid applicants include people in criminal proceedings, family disputes and domestic abuse cases, so criminal history and address data carry more risk here than in a typical retail breach.
What to do if you applied for legal aid since 2007
The government's advice now applies to anyone who applied at any point since 2007 — including people who had previously ruled themselves out because they applied before 2010, and partners named on applications. Per GOV.UK's guidance: Because National Insurance numbers and financial details are in scope, treat unexpected credit applications or account activity as a red flag worth checking promptly.
- Be alert to phishing emails, scam calls and messages from unknown contacts, especially any that reference legal aid or a legal case.
- Verify anyone claiming to be from the LAA, a law firm or another official body through a known channel before sharing information.
- Update any passwords that may have been exposed, and don't reuse them elsewhere.
- Call the LAA's dedicated breach line on 0300 200 2020 with questions about your own data.
Frequently Asked Questions
Has the stolen Legal Aid Agency data been published?
As of the July 2025 update, the Law Society reported no evidence the stolen data had been published or leaked online.
Am I affected if I was only the partner of a legal aid applicant?
Possibly. The July 2025 revision confirmed information linked to applicants' partners may have been accessed in some cases, so partners should follow the same precautions.
Does the 2007 date mean every application since then was stolen?
No. The MoJ says data going back to 2007 "may have been accessed" — it has not confirmed every record in the period was taken.
You Might Also Like
- Social Blade Data Breach: What Was Exposed and What to Do Now
- What Is New With Government Data Breach News in September 2026? Latest breach notices and security advisories and Key Takeaways
- Government Data Breach News August 2026 Update: What Changed, Why It Matters, and What to Watch Next