PARLIAMENTARY DEBATE
Legal Aid Agency: Cyber-security Incident - 19 May 2025 (Commons/Commons Chamber)
Debate Detail
On Wednesday 23 April, the Legal Aid Agency became aware of a cyber-attack on its online digital services. These are the services through which legal aid providers log their work and receive payment from the Government. The Government of course took immediate action to bolster the security of the system, working closely with experts at the National Crime Agency, the Government Cyber Co-ordination Centre and the National Cyber Security Centre. We alerted the Information Commissioner and, importantly, informed all legal aid providers that some of their details had been compromised. We also took some Legal Aid Agency systems offline between 7 and 11 May to carry out work to contain the breach. Officials have been working around the clock to stabilise the system and support a complex investigation.
I can now confirm that the cyber-attack was more extensive than originally thought. On Friday 16 May, we learned from the attackers behind it that they had accessed a large amount of information relating to legal aid applicants, and we assessed that threat to be credible. We believe they have accessed and downloaded a significant amount of personal data from those who applied for legal aid through our digital service some time since 2010. That data may include applicants’ contact details, addresses, date of birth, national ID numbers, criminal history, employment status and financial data, such as contribution amounts, debts and payments. I should stress that this does not mean that every individual involved will be impacted in the same way, but we needed to act to safeguard the service and its users. In line with advice from the National Cyber Security Centre, the Legal Aid Agency took its online services down on Friday. I urge all members of the public who have applied for legal aid since 2010 to be on high alert for any suspicious activity. That includes messages and phone calls from unknown numbers. If anyone is in any doubt at all, please take steps to verify a person’s identity before providing any information.
I understand the gravity of these events. At this stage, we believe that the breach is contained to the Legal Aid Agency’s systems; there are no indications that other parts of the justice system have been impacted. The Government are committed to making every effort to ensure that the vital operational delivery of legal aid continues. We have put in place contingency plans to ensure that those most in need of legal support can continue to access the help that they need.
The House should be in no doubt that the Legal Aid Agency has suffered an unacceptable attack on its systems at the hands of criminals. Sadly, that attack is not altogether surprising; the vulnerabilities in the Legal Aid Agency systems have been known for many years. The risk of such an attack was steadily growing during through the previous Government’s tenure, but they took no meaningful action to fix the systems, leaving them vulnerable to attack. The previous Government were repeatedly warned about the Legal Aid Agency systems being old, inflexible and unstable. In 2023, the Law Society called on the Government to urgently invest in the Legal Aid Agency digital system, saying that the system was “too fragile to cope.” In March 2024, the Law Society pointed to the agency’s “antiquated IT systems” as
“evidence of the long-term neglect of our justice system”.
In short, this data breach was made possible by the long years of neglect and mismanagement of the justice system under the last Conservative Government. They knew about the vulnerabilities of the Legal Aid Agency digital systems, but did not act. By contrast, since taking office, this Government have prioritised work to reverse the damage of over a decade of under-investment. That includes the allocation of over £20 million in extra funding this year to stabilise and transform the Legal Aid Agency digital services. I am extremely grateful to legal aid providers across the country for their patience and co-operation, and to Ministry of Justice officials for their ongoing efforts to secure the system. The investigation is live, and the Government will do everything we can to seek justice.
Recent events have shown that every organisation, no matter how big or small, is at risk from this type of criminal behaviour. Sadly, the Government are not exempt. This incident has none the less demonstrated in stark terms that our legal aid digital systems are critically fragile and not fit for the 21st century. When I took up this ministerial role, I was frankly shocked to see just how fragile they were. This Government inherited a legal aid sector that has been neglected for far too long. We have invested in stabilising the current digital systems and have kick-started an ambitious reform programme to transform them. That means creating a modern, user-friendly and resilient service. The programme will also deliver a more flexible service, so that we can implement changes faster, and better respond to changing demands.
That transformation will take time. In the light of this incredibly serious incident, my right hon. Friend the Lord Chancellor and I are exploring options to expedite the programme and put our systems on a more secure footing. The Government will not hesitate to act to protect our vital public services, because without legal aid, our justice system would grind to a halt. This is an ongoing and sensitive issue, and our investigation and mitigating action continue. To ensure that Members are informed and updated, I will provide a written update in due course. I commend this statement to the House.
I will say what the Minister should have said to all those worried by what has happened, including those who may be victims of fraud as a result, and taxpayers who will pick up the bill: we should never lose sight of the fact that whatever the role of any Government, past or present, in unsuccessfully defending against such attacks, the primary responsibility for this lies with the despicable criminals who carried it out. This was not just an attack on a digital system; it was an attack on some of the most vulnerable in our society. Their data is deeply personal in some cases, given that sensitive medical records have been exposed. It is utterly appalling. We welcome the fact that the National Crime Agency and the National Cyber Security Centre are involved, and I hope that the Minister will agree that those behind this breach must be brought to justice. Nothing should stand in the way of full accountability for this crime.
Addressing the actions of those behind the attack is paramount. The Minister may seek to focus blame on a previous Government, but I have questions about this Government’s response. First, why was the decision taken not to inform the House and the public about the breach when it was first discovered on 23 April? We now learn that the impact may extend to those who made applications as far back as 2010, and that more than 2 million pieces of information have been accessed. The delay of nearly a month in notifying the public and/or understanding the nature of the attack could have hindered individuals from taking necessary steps to protect themselves from potential harm, such as fraud or harassment.
Secondly, the Minister mentioned taking systems offline that are crucial for legal professional payments. Can she provide a clear update on the operational status of those systems? If they are not yet fully functional, what is the estimated timeline for their restoration? She mentioned contingency plans; could she tell us more about their nature? Thirdly, can she share any information about the origin of this attack? Is it believed to be a state-linked criminal enterprise? Fourthly, has the Ministry of Justice initiated a thorough risk assessment of its other digital systems, and digital systems across Government more widely? She says that the Government believe that the attack is contained, but on what basis has she reached that conclusion?
Fifthly, the Minister talked about the £20 million set aside for delivering improved systems. She will know the challenges that previous Governments faced in attempting to upgrade those systems. What specific improvements will be achieved by this funding, and when? Finally, will the Minister give a commitment to full transparency for the House, through regular updates as the investigations progress? She mentioned seeking to make the public more aware of the issue, so that people know if they might be affected. Will she ensure that those affected by this breach are directly contacted and offered appropriate support? Will she reiterate the Government’s commitment to ensuring that those responsible are brought to justice? The security of our justice system, public confidence and the wellbeing of vulnerable individuals depend on a robust and transparent response to this serious incident.
It is important that we are honest and frank about the vulnerability of the legacy IT systems that support our legal aid system. The vulnerability of that system exposed both legal aid providers and end users—as the hon. Member says, some of the most vulnerable people in our society—to unacceptable risk. I am focused on the short term and eliminating the threat, but also on the long term, on investing in resilience, and on the rescue and transformation of the platforms, so that we who are responsible for the legal aid system and our wider justice system do not expose people to that risk again.
The hon. Member asks why the House was not informed when Ministers were informed, in late April. The reason for that is simple: when Ministers were first informed about the exposure of the Legal Aid Agency’s digital platforms to this risk, the full extent of the risk, and the nature and extent of the data put at risk, were not fully understood. As a Minister, I have competing responsibilities. I have a responsibility to keep the legal aid system going—to ensure that those who need to access legal support can do so, and that those providing legal aid to vulnerable clients are paid. At that point, given the understood risk, the responsibility to keep the system going outweighed any need to inform the House of the exposure of the system. However, the most important people in the system—the legal aid providers and, by extension, their clients—were informed, as was the Information Commissioner, whom we are legally obliged to inform. When the greater extent of the risk became known, we promptly and transparently informed the House of the position. That was a transparent and proportionate response to our understanding of the evolving criminal theat.
The shadow Minister asked about the restoration of the system. The system has been closed down to negate the threat and prevent further exposure of legal aid providers and users. We will not reopen the system until we are satisfied that it is safe to do so. As he will understand, I cannot comment further on this live and sensitive situation. However, I can assure him that we have put in place contingency plans to ensure that those who need to apply for legal support in the coming days and weeks, and those who are currently accessing legal aid, can provide information to the legal aid agencies through alternative means, so that we can keep the show on the road.
The shadow Minister asks about wider Government exposure to any risks. As I have mentioned, regrettably, Government Departments, local authorities, universities and our best-known businesses are exposed to the sort of criminal activity that the Legal Aid Agency has experienced, but from what we know, this attack is confined to the Legal Aid Agency, and goes no wider than that. He asks about our long-term plans. As I have said, our long-term plans involve a significant investment of £20 million to stabilise and transform the service. Indeed, we know about today’s threat partly because of the investment that we have made since we came into government. We discovered the threat and became alive to the fact that hackers were infiltrating the system partly because of the work that we were doing to stabilise and transform the system. That work has to continue. The Lord Chancellor and I will look at whether we can expedite some of that work to bake resilience into the system.
The shadow Minister asked about full transparency and keeping the House up to date. As I said, I will provide a written update in due course, and today I can undertake to provide full transparency. Legal aid providers have been kept fully informed along the way, as have our professional bodies, such as the Law Society and the Bar Council, many of which are legal aid providers. That is because we need all of them, working in a robust system, to deliver the justice and legal aid that people so sorely need.
The malign criminals who are responsible for the hack have given a figure for the amounts of data that they have, which has been trailed in some of the newspapers. Those who have read the papers will know that it is in the region of 2 million items of data, so one can see that the scale of the problem is very serious indeed. I should say that that figure cannot be verified, and I will not comment in further detail.
With respect to my hon. Friend’s request that the JSC and Opposition parties are kept up to date as the investigation develops and as we take steps to eliminate this risk from our systems, I am very happy to give that update.
This Government must urgently restore trust, and I have a few questions in pursuit of that. First, how will the Minister proactively communicate with all those affected about this breach to provide guidance and support? Secondly, will she consider launching a dedicated advice line, for example, for anyone who is worried about what it means for them? Thirdly, the Legal Aid Agency’s services were taken offline last Friday, as the Minister confirmed, so how will she ensure that that does not compromise people’s access to legal aid in the meantime? Finally, will the Government conduct a cyber-security review of all the systems they use across their remit to identify and address further vulnerabilities before they are exploited at the expense of our constituents?
We are taking a proactive approach to communicating with people and with the sector. As soon as the risk and the exposure of the system to these hackers was identified, legal aid providers were updated on their exposure and told to take proactive security steps. That communication has been updated, and, as well as today’s public statement, we are in constant communication with those legal aid providers. They are really the most important point of contact, because they have a relationship of trust with their clients, and they will be invited to pass on the warnings and messages coming from the Government. Where we know of particular individuals whose data may have been exposed and who may be particularly vulnerable, we are communicating directly with them. I will take away the hon. Gentleman’s suggestion of an advice line, but for now what I have described will be the most important and effective way of disseminating the warnings and keeping people up to date as the situation evolves.
Turning to the wider security threat to Government and other vulnerabilities, before this attack we had indicated in any event that we would have a new national cyber strategy across Government by the end of the year. Obviously, we also intend to introduce the cyber-security and resilience Bill, which aims to improve and strengthen Government cyber-defences and Government responses to attacks just like this one. All of that is going to be important to improving the resilience not just of the Legal Aid Agency but of cyber-systems right across Government.
I can assure the hon. Gentleman that we will be in contact with all the devolved nations and regions to ensure that legal aid providers throughout the United Kingdom are kept informed. He is right: some of the most vulnerable people in society who are in receipt of legal aid will be feeling that much more vulnerable today. I deeply regret that, and it is what makes me so furious about what has happened. I urge them to be super-vigilant and to be in touch with their providers, and I urge those providers to contact the Legal Aid Agency, and contact us, about any particular vulnerabilities and about cases in which they need to continue to provide those clients with legal aid.
Contains Parliamentary information licensed under the Open Parliament Licence v3.0.