Cyberattacks Target UK Local Councils: Westminster, Hammersmith & Fulham Affected
Primary Topic: Cybersecurity incidents impacting UK local government.
Primary Keyword: UK council cyberattack
Secondary Keywords: local government cybersecurity,ransomware attacks UK,Westminster City Council cyberattack,Hammersmith and Fulham Council cyberattack,council IT systems,data breach UK,cyber incident response,local authority data security.
Recent cybersecurity incidents have impacted several UK local councils, including Westminster City Council and Hammersmith & Fulham Council. While the full extent of the attacks is still under investigation, councils have taken steps to contain the issues and minimize disruption to public services. This incident underscores the growing threat landscape faced by local authorities and the critical need for robust cybersecurity measures.
Confirmed Attacks and Council Responses
The incidents began to surface around november 24th, 2025, with Westminster City Council initially identifying a cyber security incident. as of November 28th, 2025, both Westminster and Hammersmith & Fulham councils confirmed they were affected, citing “joint arrangements” as a contributing factor to the widespread impact https://www.localgov.co.uk/Westminster-and-Hammersmith-and-Fulham-councils-hit-by-cyber-attack/59911.
Hammersmith & Fulham Council stated they were able to “successfully isolate and safeguard our network” and currently have “no evidence of H&F systems being compromised.” Though, as a precautionary measure, some public-facing applications were temporarily suspended while investigations continue. Westminster City Council confirmed services are still running, though some disruption remains. They have taken “immediate steps to contain the issue and protect our systems.”
Nature of the Attack – Suspected Ransomware
While official details remain limited, reports strongly suggest the attacks involve ransomware. The local Government Association (LGA) has warned councils to be vigilant against ransomware attacks, which have become increasingly common targets for cybercriminals https://www.lga.gov.uk/news/cyber-attack-warning-councils. Ransomware attacks typically involve malicious software encrypting a council’s data, demanding a ransom payment for its release.
Why Local Councils are Attractive Targets
Local councils are increasingly becoming attractive targets for cyberattacks for several reasons:
* critical infrastructure: Councils provide essential public services, making disruption highly impactful.
* Sensitive Data: They hold vast amounts of personal data, including financial information, addresses, and medical records, making them valuable to cybercriminals.
* Limited Resources: Many councils operate with constrained budgets, possibly leading to underinvestment in cybersecurity.
* Complex IT Systems: Councils frequently enough rely on aging and complex IT infrastructure, creating vulnerabilities.
Mitigation and Response – Best Practices
Following a cyberattack, councils typically employ a range of mitigation and response strategies:
* Isolation: Instantly isolating affected systems to prevent further spread of the malware.
* Incident Response Plan: Activating a pre-defined incident response plan to guide the recovery process.
* Data Backup & Recovery: Restoring data from secure backups to minimize data loss.
* Law Enforcement Notification: Reporting the incident to relevant law enforcement agencies, such as the National Cyber Security Center (NCSC) https://www.ncsc.gov.uk/.
* Forensic Investigation: Conducting a thorough forensic investigation to determine the root cause of the attack and identify vulnerabilities.
* Public Communication: Keeping residents informed about the situation and any potential impact on services.
The Broader Threat Landscape for UK Local Government
This incident is not isolated. In recent years, several UK local authorities have been targeted by cyberattacks, including Redcar & Cleveland Borough Council and Gloucester City Council. These attacks highlight the urgent need for increased investment in cybersecurity across the local government sector. The NCSC provides guidance and support to local authorities to help them improve their cyber resilience.
The LGA is also advocating for increased funding and resources to help councils strengthen their cybersecurity defenses. Proactive measures, such as regular security audits, staff training, and robust data protection policies, are crucial to mitigating the risk of future attacks.
Keep reading