MoJ Legal Aid Portal Breach – Lessons for Law Centres
Earlier this year, the Ministry of Justice (MoJ) took down its legal aid portal following a significant cyber incident. Many law centres across the UK rely on this system daily, and the disruption has been widely felt.
What happened
-
The MoJ confirmed that unauthorised access had been detected.
-
The portal was taken offline while investigations and remediation took place.
-
As of September 2025, access issues and delays are still being reported.
Why this matters for law centres
The breach exposed a weakness that many of you have already flagged in your Cyber Essentials assessments: the lack of multi-factor authentication (MFA).
-
MFA is a core Cyber Essentials requirement.
-
Some law centres were frustrated that their own assessments showed non-compliance, while the government system they rely on didn’t support it at all.
The bigger picture
Even central government systems can fall short. But that doesn’t mean you should lower your own standards.
-
MFA reduces risk – adding it to accounts makes a breach significantly harder.
-
Cyber Essentials sets a baseline – a consistent standard that applies whether you’re a law centre, MSP, or government body.
-
Awareness is power – assessments don’t just generate a certificate, they highlight real risks you can address.
Takeaway
The MoJ incident is a reminder that you can only control what’s within your own organisation. Apply the strongest controls you can, insist on best practice from your MSP, and don’t assume “big systems” are immune.