Breaking NewsUpdated as information becomes available
News·Breach Analysis·16 September 2026·Breaking

Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Court case files on wet stone steps outside a government justice building at dusk
Court case files on wet stone steps outside a government justice building at dusk

Why it matters

What this means for organisations holding critical data

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

The Ministry of Justice has confirmed an investigation after courts staff accessed case files relating to victims, survivors and families of the Southport attack without authorisation.

The unauthorised access was identified during a review of the department's digital systems. For a limited number of people, the information accessed included sensitive and personal data assessed as likely to result in a high risk to their rights and freedoms. Those affected are being notified directly, the Information Commissioner's Office has been informed, and the prime minister has asked the Lord Chancellor to oversee the matter. The MoJ has said there is no evidence personal data was shared with third parties, and that all wrongdoing will be met with extremely firm action. HM Courts and Tribunals Service and HM Prison and Probation Service are also investigating.

An MoJ spokesperson said the department was appalled, apologised to those affected, and described unauthorised access to court files as completely unacceptable.

A pattern, not an isolated case

This is the third inappropriate access case connected to the Southport attack. In May, a Liverpool hospital trust admitted that nearly 50 staff had inappropriately accessed the medical records of some victims treated at Aintree Hospital. North West Ambulance Service later began investigating potential inappropriate access to patient records by its own staff.

Three separate organisations. Three separate systems. The same failure mode: people with legitimate credentials opening records they had no legitimate reason to open.

Why this is different from an external attack

No firewall was bypassed. No password was stolen. No vulnerability was exploited. Every person involved almost certainly had valid access to the system in front of them, because their job required it.

This is the hardest class of breach to prevent, because the access path is legitimate. The only thing that was not legitimate was the purpose. Traditional security, built to keep outsiders out, has very little to say about an insider who is already in.

What limits insider misuse is control inside the perimeter: genuine least-privilege access scoped to role and case, complete audit logging of who opened what and when, proactive review of that logging rather than discovery by chance, and consequences that are known in advance. It is notable that this access was found during a review of digital systems, which suggests the logging existed. The question every organisation should ask is whether anyone is looking at theirs.

The records most at risk are the ones that matter most

Court files, medical records and ambulance logs sit at the extreme end of sensitivity. When they relate to victims of a violent attack, the harm caused by inappropriate access is not abstract. It compounds the trauma of people who have already suffered the worst imaginable loss.

That is why the principle of Disconnect to Protect applies with particular force to records of this kind. Data that does not need to be online should not be online. Where records must remain accessible for live proceedings or care, access should be narrowed to the smallest possible group, monitored continuously, and reviewed as a matter of routine rather than after a breach.

Offline Secure Storage is built for the data an organisation must keep but does not need connected: archives, evidence copies, historical records. For the systems that must stay live, the answer is control. Both begin with the same admission: you cannot protect what everyone can reach.

What organisations should take from this

First, assume insider misuse will be attempted wherever records are sensitive or newsworthy. Curiosity alone is a threat actor.

Second, audit access logs proactively. If your review process is what finds misuse, fund it. If you have no review process, that is the finding.

Third, separate what must be live from what must be kept. Every record moved out of a connected system is a record an insider cannot casually open.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

CustodyNamed, access-controlled hardware in a Firevault Bunker
EvidenceAccess windows and retrieval events are recorded
SeparationPhysical isolation that satisfies offline copy requirements
JurisdictionStored where your regulatory position requires