Threats, Incidents and Claims
London Councils Cyber Attack: What SMBs Can Learn
London Councils Cyber Attack: What SMBs Can Learn
The London councils cyber attack that surfaced in late November 2025 is one of the most instructive UK public-sector incidents in years, and the lessons apply far beyond the town hall. Three neighbouring boroughs, the Royal Borough of Kensington and Chelsea, Westminster City Council and Hammersmith and Fulham, were knocked out at once because they ran on shared IT infrastructure. Personal data belonging to hundreds of thousands of residents was copied and taken, phone lines went down, and services from council tax to planning were still being restored months later. If a well-resourced local authority can be brought to a standstill this way, the same failure modes are wide open in the average small business.
This article breaks down what actually happened, why the damage spread so far, and the specific, affordable controls a UK SME should take from it. For the wider picture of what UK firms are up against, see our pillar on the cyber threats UK small businesses face.
What happened in the London councils cyber attack
IT problems first appeared around 24 November 2025 and were confirmed as a cyber attack in the days that followed. The Royal Borough of Kensington and Chelsea operated a shared IT service that also ran systems for Westminster and Hammersmith and Fulham, so when the attacker got into that shared environment, all three councils were affected at once. Hackney also reported disruption during the same window.
The National Cyber Security Centre supported the response, and IT teams worked overnight to contain the intrusion and put mitigations in place. Even so, attackers had copied data before they were stopped: Westminster confirmed that its data was taken by a third party that had infiltrated the RBKC-operated systems, and more than 100,000 households were warned that their personal information may have been stolen. Recovery ran for months. Council tax collection and planning systems were reported back online only in early 2026, well after the initial breach.
Why the damage spread so far
The single most important detail for a business owner is this: the boroughs shared infrastructure, so one breach became three. That is not a public-sector quirk. It is exactly the shape of risk that any firm carries when it concentrates systems and data in one place without segmentation or independent backups.
Three weaknesses turned an intrusion into a crisis:
- A shared environment with no hard internal boundaries. Once inside, the attacker could reach data across multiple organisations. In an SME, the equivalent is a flat network where one compromised laptop can reach the finance system, the file server and the backups.
- Data was exfiltrated, not just encrypted. Modern attackers steal data before doing anything visible, so even a clean restore does not undo the breach. Your incident planning has to assume data has left the building.
- Recovery took months, not days. Restoring trusted systems safely is slow when the blast radius is large and you cannot be sure what the attacker touched.
What UK SMEs should take from it
You do not need a council-sized budget to close these gaps. The controls that would have contained this are the same ones cyber insurers and Cyber Essentials already ask for.
Segment your network and your suppliers. If you rely on a managed IT provider or shared platform, ask them directly how one client’s breach is stopped from reaching yours. Inside your own network, separate the systems that hold sensitive data from everyday desktops so one infected machine cannot reach everything. This is the core idea behind securing remote access and internal boundaries.
Keep immutable, offline backups. The recovery lesson is brutal: if your only backups sit on the same network the attacker owns, they can be encrypted or deleted too. Follow the 3-2-1 backup rule with immutable copies so you always have a restore point the attacker cannot touch.
Assume data theft and plan for notification. Because personal data was stolen here, the councils faced resident notification and regulatory scrutiny, not just an IT clean-up. A UK business that loses personal data has 72 hours to consider reporting to the ICO. Build that step into your plan now, not during the panic, using our guide to data breach reporting and the ICO 72-hour rule.
Write the incident response plan before you need it. The councils recovered because trained teams acted fast with NCSC support. A small business will not have that on speed dial, which is exactly why a written incident response plan and a cyber insurance policy with a breach-response hotline matter so much.
Check whether your insurance would respond. An incident of this kind triggers first-party costs (forensics, restoration, legal, notification) and potential third-party liability. This is what cyber insurance actually covers, and reviewing your policy against a scenario like this is a useful annual exercise.
The bottom line for business owners
The London councils cyber attack is not a story about government incompetence. It is a clear demonstration that shared systems, unsegmented networks and reachable backups turn one intrusion into an organisation-wide disaster, and that attackers steal data before you ever see a ransom note. The defences are well established and within reach of any SME: segment, back up immutably, plan your response, and hold cover that pays for the clean-up. For the official, regularly updated guidance, the NCSC small business guidance is the best free starting point.
Frequently asked questions
Which councils were hit in the London councils cyber attack? The Royal Borough of Kensington and Chelsea, Westminster City Council and Hammersmith and Fulham were all affected because they shared IT infrastructure operated by Kensington and Chelsea. Hackney also reported disruption during the same period in late November 2025. The National Cyber Security Centre supported the response.
Was personal data stolen in the attack? Yes. Attackers copied and took data before being stopped, and more than 100,000 households were warned that their personal information may have been compromised. Westminster confirmed its data was taken by a third party that had infiltrated the shared systems, showing that exfiltration, not just disruption, was part of the incident.
Why did the breach affect several councils at once? Because the boroughs ran on shared IT infrastructure. When the attacker compromised that common environment, every organisation relying on it was exposed simultaneously. It is a textbook example of concentration risk, and the same danger applies to any business relying on a single shared platform or provider without strong separation.
What is the main lesson for a small business? Assume that one compromised system can reach everything unless you actively stop it. Segment your network, keep backups that are offline or immutable so they cannot be encrypted, plan your breach notification in advance, and hold cyber insurance that funds the response. These are the same controls Cyber Essentials and insurers already expect.
Could cyber insurance have helped in a case like this? For a private business facing a comparable incident, yes. Cyber insurance typically funds forensics, system restoration, legal advice and the cost of notifying affected people, and many policies include a 24-hour breach-response line. It cannot prevent an attack, but it turns a potentially business-ending recovery into a managed, funded process.