Several London borough councils are understood to be dealing with a potential cybersecurity incident that has prompted precautionary shutdowns of parts of their networks.
As officials assess the scope and source of the suspected cyberattack, industry specialists have begun outlining the possible implications for residents, the risks associated with highly sensitive local authority data, and the challenges councils face when responding to fast-moving digital incidents.
Jon Abbott, Co-founder and CEO of ThreatAware, said: “Local councils manage critical functions and store a plethora of personal data, from tax records to personal identifiers, making them attractive targets for cybercriminals. This is why having the security fundamentals in place is so important.
“These data points are highly sensitive, increasing the potential for significant consequences if breached. Cyberattacks on such entities do not just lead to data loss but can erode public trust.
“Many councils operate under tight budget constraints, limiting their ability to invest in the latest cybersecurity technologies or even maintain adequate staffing for their IT security teams.
“Basic cyberhygiene, enforced multi-factor authentication, and robust user verification are some of the most effective ways of securing networks, without putting extra strain on budgets and resources.”
Raghu Nandakumara, VP of Industry Strategy at Illumio, said: “Local councils store a vast amount of personal data, which can be used in the longer term to conduct further attacks, making them an attractive target for cybercriminals. In this case, if residents’ data is found to have been compromised, it may be used for phishing attacks and scams, such as fraudulent fuel-payment schemes, especially as we head into winter.
“Along with the significant amount of sensitive data held by councils, they are often under tight budget constraints and have limited resources. This is why containing cyberattacks is important. Preventing every attack is an unattainable goal for stretched councils, but limiting the impact isn’t.
“While the decision to shut down networks was a precautionary measure to mitigate the impact, these sorts of actions are possible without cutting off vital services that thousands depend on. We need to reach a point where both public and private sector organisations can contain and survive cyberattacks with minimal disruption to operations.”
Nathan Webb, Principal Consultant at Acumen Cyber, said: “Based on the information available, it sounds like councils across London have been compromised via a piece of shared infrastructure.
“It is essential the organisation behind the infrastructure is identified, so its other customers can take action to protect their systems.
“While details into the incident are still emerging, it sounds like the councils have initiated their emergency plans and are actively working to contain the breach.
“It’s positive the councils have been proactive with this incident response planning, but until we know more about the scale of the incident, and what systems have been impacted, we won’t know how long it will take to mitigate, or which, if any, council services are affected.
“Given they have also informed the ICO, this suggests there is a possibility personal data may have been compromised, so employees and citizens across the affected boroughs should be vigilant online just now. Attackers will frequently use publicity around attacks to further target victims, so any correspondence around the incident should be treated with caution. It’s always safer to monitor official sites for updates.
“When it comes to attacks on councils, the impacts can be severe, with data on residents being compromised, key services being disrupted, and even an attack on Leicester City Council disabling the authority’s ability to switch off street lights in the city. Hopefully things don’t get quite so bad this time round.”
Rob Demain, CEO, e2e-assure, said: “With three London councils affected at the same time, the most plausible explanation is a shared service provider being compromised rather than each council being individually targeted. When outages strike multiple organisations simultaneously it often points to an MSP or other common supplier as the root cause. Criminal groups know commercial providers are more likely to pay a ransom than public sector bodies, so disrupting their key customers is a proven pressure tactic.
“If this does turn out to be a direct attack on the councils themselves, motives could range from data theft to notoriety or even state backed disruption, ‘flexing’ against the west, but that looks less likely at this stage. Incidents like this also highlight why the UK is bringing MSPs into scope for greater cyber-oversight under the CSRB. For now, all eyes will be on restoring core services and understanding exactly how the attackers gained a foothold”
Dray Agha, Senior Director of Security Operations at Huntress, said: “This coordinated incident highlights a critical vulnerability in modern public services: the double-edged sword of shared IT infrastructure. While such systems are efficient, the breach of one council can instantly compromise its partners, crippling essential services for hundreds of thousands of residents. It underscores an urgent need to move beyond simple cost-saving IT models and invest in resilient, segmented networks that can contain such threats and protect vital public services.”
Rebecca Moody, Head of Data Research at Comparitech, said: “This sounds like it could be a ransomware attack as the councils are experiencing both system disruption and potential data theft. Most groups today follow this MO so they can demand not one but two ransoms (one to decrypt systems and one to delete stolen data).
“Governments are a key target for these exact reasons, as hackers can cause widespread disruption (as we’re seeing here) and can access highly sensitive data stored by these entities. So far this year, we’ve noted 174 confirmed attacks on government organisations across the globe. These attacks have resulted in data breaches of over 780,000 records and average ransom demands of nearly US$2.5 million (USD).
“While we await more information on the nature of the attack, residents and employees from these boroughs should be on high alert for any potential phishing messages and suspicious activity on their accounts. If this is a ransomware attack and ransom negotiations fail, it’s likely we’ll see a group coming forward to claim the attack and data theft in the coming days/weeks.”
Ian Nicholson, Head of Incident Response at Pentest People, said: “The report on multiple London councils being affected by cyberattacks this morning goes to prove how fragile shared public-sector infrastructure can be. When environments are completely interconnected, compromise in one area quickly propagates across the whole environment. Think supply chain attacks. Again and again, we see attackers exploiting legacy systems, we see slow patching, and underfunded, understaffed IT teams. The real concern now, from my perspective, is data integrity and operational disruption. Local authorities sit on highly sensitive information, and incidents like this really does impact those much needed front line services.”


