UK Ministry of Justice apologizes for unauthorized access to 2024 attack victims' court files

3 min readSources: The Register

UK Ministry of Justice admits staff improperly accessed court files of 2024 Southport attack victims.

Why it matters: The breach reveals risks in protecting sensitive victim data within the justice system, urging legal professionals to review data access controls and compliance protocols.

  • Unauthorized access to court files related to the July 2024 Southport knife attack was discovered in September 2026.
  • No evidence shows the compromised data was shared with external parties.
  • The Information Commissioner's Office (ICO) is investigating, with oversight from the Lord Chancellor and separate inquiries by justice agencies.
  • Similar May 2026 breach involved nearly 50 hospital staff accessing victims’ medical records without authorization.

In September 2026, the UK Ministry of Justice (MoJ) confirmed that court staff accessed sensitive files concerning victims, survivors, and families affected by the July 2024 knife attack at a Taylor Swift-themed dance class in Southport without authorization. The attack caused three fatalities and multiple injuries.

This unauthorized access was uncovered during a routine review of MoJ digital systems. Although the Ministry has found no evidence that personal data was disclosed to outside parties, officials have expressed serious concern over the breach.

A MoJ spokesperson said, "We are appalled that this happened and recognize the distress caused to victims, survivors, and their families. We apologize to those affected. Unauthorized access to court files is completely unacceptable. All wrongdoing will face strict disciplinary action."

The breach has been referred to the Information Commissioner's Office (ICO), the UK’s data protection regulator overseeing compliance with privacy laws. The Lord Chancellor has been appointed to supervise the investigation. Additionally, the Prisons and Probation Service and the Courts and Tribunals Service are conducting separate internal inquiries.

This incident follows a related May 2026 breach where nearly 50 staff at a Liverpool hospital improper accessed medical records of victims treated at Aintree Hospital. Together, these breaches highlight vulnerabilities in managing sensitive victim data and the imperative for robust data security practices across the legal and healthcare sectors.

By the numbers:

  • July 2024 — Southport knife attack date
  • September 2026 — date unauthorized court file access was discovered
  • Nearly 50 hospital staff — involved in May 2026 medical records breach

Yes, but: While there is no evidence of data being shared externally, investigations are ongoing and the full scope of the breach remains uncertain.

What's next: The ICO is expected to publish investigative findings later this year; MoJ and justice agencies plan to strengthen data protection policies in response.