Security News

UK Ministry of Justice Apologises After Court Staff Improperly Accessed Southport Victims' Files

The Register · 16 Sept 2026
Key Takeaway Businesses handling sensitive customer or client records should enforce strict access controls, log and regularly audit who views sensitive files, and ensure staff understand that curiosity is not a valid reason to access data outside their role.

The UK Ministry of Justice (MoJ) has apologised after court staff accessed documents relating to victims and survivors of the 2024 Southport murders without authorisation. For a limited number of people, the accessed material included sensitive personal data assessed as likely to pose a high risk to their rights and freedoms, though there is no evidence it was shared with third parties.

An MoJ spokesperson called the incident 'completely unacceptable' and confirmed that the Prime Minister has asked the Lord Chancellor to oversee an urgent investigation. Affected families are being contacted directly, though the MoJ has not disclosed how many people were involved or clarified how many staff accessed the files or why. HM Prison and Probation Service, HM Courts and Tribunals Service, and the Information Commissioner's Office are all now involved in reviewing the matter.

This is not an isolated case. Separate investigations have also examined inappropriate access to Southport victims' records by North West Ambulance Service staff and nearly 50 employees at Aintree University Hospital. The pattern highlights a recurring problem: staff with legitimate system access misusing it to view records unrelated to their duties, particularly around high-profile or emotionally charged incidents.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.