Join the Legal Aid AgencyData Breach Claim

If you applied for Legal Aid between 2007 and 2025, you could be eligible to seek compensation if your personal data was exposed in the 2025 Legal Aid Agency data breach. If you've been affected, check your eligibility.
Pocket Claim has partnered with KP Law, a specialist law firm for data breach claims. You can check if you could be eligible to claim and seek compensation on a No-Win, No-Fee* basis.
In this matter, if it is successful, you will pay 25% of the amount that is recovered plus the cost of any After the Event Insurance. Termination fees may apply if you fail to co-operate with your lawyer or withdraw from the claim.
The first step in getting compensation
Answer a few short questions to check if you could be eligible to claim and seek compensation for the Legal Aid Agency data breach.
THE FACTS SO FAR
What do we know about the Legal Aid data breach?
The breach was initially believed to be limited, but the extent of the compromise was later described as 'more extensive than originally understood.'
The attack discovered in April 2025 actually began much earlier. Systems were first breached in December 2024, with data exfiltrated from January 2025.
According to media reports, over two million pieces of information dating back to 2007 may have been accessed and downloaded by the attackers.
Legal Aid Agency Chief Executive Jane Harbottle has issued a public apology, acknowledging that the breach may be 'shocking and upsetting' for those affected.
The data breach compromised sensitive data from hundreds of thousands of legal aid applicants and providers.
FREQUENTLYASKED QUESTIONS
The Legal Aid Agency became aware of a cyber attack on the 23rd of April 2025. By May, it became clear that the breach was far more extensive than expected, with the incident potentially affecting everyone who accessed legal aid through digital platforms since 2007. Since the breach, the government has admitted the Legal Aid Agency IT software was not fit for purpose and has been extremely vulnerable to attack for years. An injunction has been put in place to stop anyone publishing the personal information, and there is no evidence that the data has been published anywhere yet.
The group behind the attack is believed to have accessed and downloaded a significant amount of personal data from those who applied for legal aid through the digital service between 2007 and 16 May 2025, when the systems were taken offline. This data may include contact details and addresses, dates of birth, national ID numbers, criminal history, employment status, and financial data such as contribution amounts, debts and payments. In some instances, information about the partners of legal aid applicants may also be included.
The UK Government released the following statement on the data breach:
“On Wednesday 23 April, we became aware of a cyber-attack on the Legal Aid Agency’s online digital services.
These are the services through which legal aid providers log their work and receive payment from the Government.
In the days following the discovery, we took immediate action to bolster the security of the system, and informed all legal aid providers that some of their details, including financial information, may have been compromised.
Since then, we have worked closely with the National Crime Agency and National Cyber Security Centre as well as informing the Information Commissioner.
On Friday 16 May we discovered the attack was more extensive than originally understood and that the group behind it had accessed a large amount of information relating to legal aid applicants.
We believe the group accessed and downloaded a significant amount of personal data from those who applied for legal aid through our digital service between 2007 and 16 May 2025 when the systems were taken offline.
This data may have included contact details and addresses of applicants, their dates of birth, national ID numbers, criminal history, employment status and financial data such as contribution amounts, debts and payments. In some instances, information about the partners of legal aid applicants may be included in the compromised data.
We would urge all members of the public who have applied for legal aid in this time period to take steps to safeguard themselves. We would recommend you are alert for any suspicious activity such as unknown messages or phone calls and to be extra vigilant to update any potentially exposed passwords. If you are in doubt about anyone you are communicating with online or over the phone you should verify their identity independently before providing any information to them.
An injunction has been put in place to prohibit sharing of this data. Anyone who does so could be sent to prison.
Further information on how to protect yourself from the impact of a data breach can be found on the NCSC website.”
The Legal Aid Agency should be in touch to notify affected individuals. In the meantime, anyone who applied for legal aid between 2007 and May 2025 is urged to stay alert for suspicious activity such as unknown messages or phone calls, update any potentially exposed passwords, and independently verify the identity of anyone they are communicating with online or over the phone before providing information.
If you receive notification that you are affected by the Legal Aid Agency data breach, you could be eligible to seek compensation. Use the online form to answer a few short questions to check if you could be eligible to claim and seek compensation.
A group action claim is where a group of people – sometimes even thousands of people – have been affected by the same issue. Group action cases are also known as class actions, multi-claimant, or multi-party actions.
There are no upfront costs to join the claim. The partner solicitors work on a No-Win, No-Fee basis. This means you pay nothing up front and, provided you keep to your contractual obligations, even if your claim is unsuccessful, you won’t pay anything. If the claim is successful, a success fee is deducted from the compensation awarded.

