Info Gov

A coordinated cyber attack has forced three London boroughs - Westminster City Council, the Royal Borough of Kensington & Chelsea (RBKC), and Hammersmith & Fulham - to shut down parts of their IT infrastructure after detecting suspicious activity earlier this week.

Officials have confirmed that data was accessed and copied from council systems, though early indications suggest the breach relates to historical records. RBKC has warned that while the information remains available to the councils, there is a risk it could be published online. Investigations are ongoing to determine whether personal or financial details of residents and service users are affected.

The incident has left residents struggling to contact their councils, with phone lines and online portals intermittently unavailable. All three councils have “activated emergency plans” to maintain critical services, including housing, social care, and waste collection.

The Information Commissioner’s Office (ICO) has been notified due to the potential compromise of personal data. The National Cyber Security Centre (NCSC) is working with the boroughs to isolate affected systems, restore functionality, and prevent further spread across shared IT networks.

Investigations by the National Crime Agency (NCA) and NCSC remain ongoing, with councils urging residents to remain vigilant for potential phishing attempts or misuse of personal data. Updates are expected as forensic analysis clarifies the scope of the breach and the measures required to restore full service continuity.

Also in this section

Jul 30, 2026

Section 166 application succeeds as tribunal finds ICO left complaints unresolved

The First-tier Tribunal (General Regulatory Chamber) has ordered the Information Commissioner to take further steps and issue a written outcome on a data protection complaint after finding that the regulator invited the complainant to return if dissatisfied with the department's response, received her further material but then did not demonstrate that it had concluded the complaints.
Jul 29, 2026

Regulators clarify medical device status and governance expectations for NHS AI scribes

The Medicines and Healthcare products Regulatory Agency (MHRA) has published new guidance to clarify how existing medical device law applies to ambient voice technology (AVT) products used in health and care settings in Great Britain, setting a regulatory line between tools that merely transcribe and summarise clinical conversations and those that go further into diagnosis or automated action.

InfoGov Masthead Newsletter 800