The Legal Aid Agency (LAA) was subject to a data attack in April 2025. All systems were taken offline and contingency measures were put in place to make sure legal aid providers could be paid. At the time, no one thought systems would be down for nine months. Our head of justice, Richard Miller, explains how the crisis developed.
The LAA told me about the breach on 30 April 2025. At that point, they were notifying legal aid providers to be alert of any unusual activity on their bank accounts.
On Friday 9 May they informed me that the breach was still being investigated and they had taken their systems offline until the following Monday.
For the next week they continued to take the system offline periodically.
On Monday 19 May, they confirmed that the breach was far more extensive than they thought and they would be keeping their systems offline.
At that stage, we still didn’t know how long systems would be out for, but the LAA started to put contingency arrangements in place.
I had a degree of sympathy for the LAA. They had repeatedly flagged historic problems with their IT.
But I was frustrated at the way information trickled out and the lack of a robust contingency plan to deal with this situation.
When the LAA’s systems were taken offline, there was no way to apply for legal aid, in either civil or criminal cases, or for anyone to be paid for legal aid work.
For clients this was a serious problem, because cases never stop. People were still being charged with criminal offences, or served with eviction notices, or fleeing domestic abuse, and solicitors could not get legal aid to be able to start helping them.
For firms this was a serious problem – because after years of government cuts to legal aid – many legal aid businesses operate on tiny margins with little to no financial headroom.
We were faced with the prospect of firms becoming insolvent in a matter of weeks, if not sooner.
It has been known for years that the LAA’s IT system is not fit for purpose.
We joined their repeated lobbying to the MoJ to provide the investment needed to fix it, but our pleas have fallen on deaf ears.
We don’t know if this contributed to the breach, but it has undoubtedly made it more difficult to establish contingency arrangements and recover from the breach.
The LAA’s obligations
The LAA had numerous responsibilities in this situation.
First, they have duties to both clients and firms under data protection legislation. We understand that this question is in the hands of the Information Commissioner’s Office.
Secondly, the LAA is the body responsible for implementing the lord chancellor’s responsibilities under LASPO to operate an effective legal aid system.
Thirdly, the LAA has obligations to firms under the Legal Aid Contract, although it is quite remarkable just how few and limited those obligations are, compared with what would be expected in a normal commercial contract for the supply of services.
Finally, I would argue that the risk of a cyber-attack causing loss of systems is an obvious and common risk to every organisation.
The LAA should have had a robust and comprehensive contingency plan in place to restore services to clients and lawyers very promptly. They didn’t, and almost a year on, we are still some way from a return to normal functionality.
What we’ve been doing for our members
While I found it frustrating that we had to build contingency arrangements from scratch, I have to give credit to the LAA staff we were working with at that time.
We worked with the LAA intensively, alongside other practitioner groups to develop systems and processes that would work as well as possible for firms and clients.
Given the extreme limitations of what the LAA was able to do, they did everything they could in difficult circumstances.
We started by establishing processes for emergency applications and for bulk claim payments. We then moved on to deal with other types of application and with payments of individual bills in crime.
For civil work, the LAA was unable to create a contingency process to pay individual bills, so we developed the average fee scheme to ensure firms could at least receive something.
From an early stage, we urged firms so far as possible to keep records of the additional time and cost they were incurring as a result of the breach, with a view to claiming compensation in due course.
What we’re asking for
We have continued to actively engage with the MoJ as they have gradually returned to something closer to normal operations.
We lobbied hard to ensure the transitional arrangements were fair to firms and would not require them to account for money they had received during the outage before they had had a reasonable opportunity to bill their work.
We have also been engaging with HMRC to seek guidance on the VAT treatment of the contingency payments firms have received.
We are continuing to explore options for firms to seek compensation, whether under the contract, under data protection legislation or through the LAA’s complaints process, and have published guidance to help firms understand what they can do.
Our preference would be for the MoJ to establish a bespoke compensation scheme to deal with the substantial cost they have put firms to, but unfortunately, they have so far refused to do so.





Contact us using the details below for a confidential conversation with one of our experienced consultants
1 St Peter’s Square, Manchester M2 3DE
10 York Rd, London SE1 7ND