Skip to main content
Emerging ThreatsData Breaches

Ministry of Justice Breach Exposes Southport Victims' Files

Ministry of Justice office interior with blurred file storage and a lone, out-of-focus staff member.

"We are appalled that this happened and recognise the distress it will have caused victims, survivors, and their families," an MoJ spokesperson said.

Ministry of Justice apology and the chain of command now overseeing the probe

The Ministry of Justice (MoJ) has apologised after court staff accessed documents relating to victims and survivors of the 2024 Southport murders without authorisation. The MoJ described the access as "completely unacceptable" and said the matter is being investigated urgently. The prime minister has asked the Lord Chancellor to oversee the inquiry, and the MoJ vowed that "all wrongdoing will be met with extremely firm action."

The Register asked the MoJ how many staff accessed the files, whether they remained employed, and what their reasons may have been; the ministry did not answer those questions and did not disclose how many people were involved. The MoJ said those affected include members of victims' and survivors' families, all of whom are being contacted directly.

Scope and sensitivity of the records accessed

For a limited number of people, the material accessed included sensitive personal data that the MoJ assessed as likely to pose a high risk to those individuals' rights and freedoms. The ministry reported there is no evidence that the information was shared with third parties.

Beyond the broad description of sensitivity, the MoJ has provided no publicly disclosed breakdown of which files were accessed, how the access was detected, or the timeline for the unauthorised views. The immediate priority, according to the ministry, is contacting those affected and conducting the investigation.

Related inappropriate-access incidents in health and ambulance services

The MoJ breach follows other incidents tied to records connected to the Southport attack. North West Ambulance Service investigated potentially inappropriate access by some of its staff to records of patients in the Southport attacks. Separately, nearly 50 staff were found to have inappropriately accessed the medical records of some victims treated at Aintree University Hospital, near the place of the attacks.

The attacks were carried out by Axel Rudakubana, who was 17 at the time and has since been admitted to a psychiatric hospital. Rudakubana attacked a Taylor Swift‑themed dance class in Southport, England, on July 29, 2024, killing three children and injuring eight other children and two adults. False claims about the attack online prompted violent, racially charged riots across the UK; police made 1,511 arrests in the weeks that followed and brought 960 charges. Rudakubana was sentenced to life imprisonment with a minimum term of 52 years.

Which agencies are investigating and who has been notified

The MoJ said HM Prison and Probation Service and HM Courts and Tribunals Service are investigating the court‑file access. The Information Commissioner's Office (ICO) has also been informed.

Those named agencies now have formal responsibility for determining whether criminal or disciplinary rules were breached, what corrective steps are required, and whether systemic failures contributed to the unauthorised access. The MoJ's stated intention to take "extremely firm action" signals potential personnel or procedural consequences, but the ministry has not released details about possible sanctions or timelines.

How victims and justice agencies, and ambulance and hospital services are responding

  • Victims and survivors' families: The MoJ has said it is contacting those affected directly. Families will be the first to receive the ministry's outreach and any notifications about what material was accessed and by whom, according to the MoJ statement.
  • HM Prison and Probation Service and HM Courts and Tribunals Service: Both bodies are conducting formal investigations into the court staff access. Their inquiries will determine whether procedural safeguards failed and what disciplinary or remedial steps are required.
  • Emergency and hospital providers (North West Ambulance Service, Aintree University Hospital): Those organisations have already conducted or initiated their own reviews after staff were found to have inappropriately accessed patient records. Their experiences underscore that this MoJ incident is part of a cluster of record‑access problems tied to the Southport attacks.

The immediate facts are straightforward but incomplete: the MoJ has apologised, an investigation is under way with oversight from the Lord Chancellor at the prime minister's request, and regulators including the ICO have been notified. What remains unanswered publicly — and what the ongoing investigations must resolve — is how many court staff accessed files, why they did so, whether disciplinary measures will follow, and whether additional safeguards will be put in place to prevent similar breaches.

Read the original Register report