GoFirm
Back to Blog
Case Studies·3 min read

They Knew. It Happened Anyway. 2 Million Records Gone.

By GoFirm Team

In April 2025, attackers accessed the UK Legal Aid Agency's systems. By May, the full scale was clear. Personal data belonging to over 2 million legal aid applicants had been exfiltrated - names, addresses, dates of birth, National Insurance numbers, criminal histories, financial records, employment status. Some of it dated back to 2007.

The Law Society had been raising concerns about the LAA's outdated IT infrastructure since at least 2023. The vulnerabilities were not a surprise to anyone paying attention. The Ministry of Justice had been warned. The investment to address the ageing systems never materialised. When attackers arrived, eighteen years of highly sensitive personal data was sitting there, accessible, with nothing at the execution boundary to stop it leaving.

The post-breach analysis followed a familiar pattern: underfunded security teams, legacy infrastructure, governance failures, risk that was known but not acted on. All of that is true and worth examining. But it addresses the wrong layer of the problem.

The central question is not why the systems were vulnerable, or why investment was delayed, or why the warnings were not heeded. Those are important questions. The more fundamental question is why bulk access to 2 million records of some of the most sensitive personal data in the legal system did not require a confirmed authority decision before it executed.

Not a policy. Not a risk register entry. Not a periodic access review. A confirmed, biometric, out-of-band authorisation from a named individual, on a registered device, at the moment the bulk export attempted to execute - creating a permanent record of who approved that access.

GoFirm Deep Guard operates at the infrastructure control plane. Configured on the data access layer, it intercepts bulk data exports before they execute and routes a confirmation request to the named authority assigned to that action type. The authority sees what is being accessed, how much, and by whom. They confirm or the export stops. If they do not respond within the configured timeout, the export stops anyway and the non-response is logged.

An attacker who has successfully navigated every vulnerability in the LAA's legacy infrastructure still cannot produce that confirmation. The data does not move.

The LAA breach will cost the Ministry of Justice significantly in remediation, regulatory exposure, and the long-term consequences for the individuals whose criminal histories and financial records are now in the wrong hands. The underlying infrastructure failure is real. But the exfiltration itself - the moment 2 million records left - was an execution boundary failure. That is what GoFirm prevents.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. Ministry of Justice / Legal Aid Agency, Cyber Attack on Legal Aid Agency, May 2025

2. Law Society of England and Wales, Statement on LAA IT Infrastructure

Share this article