---
title: "Southport court files breach: the access was au… | Firevault"
description: "The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/southport-court-files-insider-access-breach-2026#webpage",
      "url": "https://fire-vault.com/news/southport-court-files-insider-access-breach-2026",
      "name": "Southport court files breach: the access was au…",
      "description": "The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/southport-court-files-insider-access-breach-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/southport-court-files-insider-access-breach-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Southport court files breach: the access was authorised, the purpose was not",
          "item": "https://fire-vault.com/news/southport-court-files-insider-access-breach-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Southport court files breach: the access was authorised, the purpose was not",
      "description": "The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.",
      "url": "https://fire-vault.com/news/southport-court-files-insider-access-breach-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-16T08:29:03.525924+00:00",
      "dateModified": "2026-09-16T08:29:03.525924+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/southport-court-files-insider-access-breach-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 683,
      "keywords": "Southport, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The Ministry of Justice has confirmed an investigation after courts staff accessed case files relating to victims, survivors and families of the Southport attack without authorisation. The unauthorised access was identified during a review of the department's digital systems. For a limited number of people, the information accessed included sensitive and personal data assessed as likely to result ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened in the Ministry of Justice data breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Courts staff accessed case files relating to victims, survivors and families of the Southport attack without authorisation. The access was identified during a review of the department's digital systems. For a limited number of people, the information accessed included sensitive and personal data assessed as a high risk to their rights and freedoms."
          }
        },
        {
          "@type": "Question",
          "name": "Was the Southport court data shared with anyone outside?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Ministry of Justice has said there is no evidence personal data was shared with third parties. The Information Commissioner's Office has been informed, and those affected are being notified directly."
          }
        },
        {
          "@type": "Question",
          "name": "What is an insider data breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "An insider breach happens when someone with legitimate system access uses it for a purpose they are not authorised for, such as opening records out of curiosity. No hacking is involved, which is why perimeter security alone cannot prevent it."
          }
        },
        {
          "@type": "Question",
          "name": "Have there been other breaches linked to the Southport attack?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. In May, a Liverpool hospital trust admitted nearly 50 staff inappropriately accessed the medical records of some victims treated at Aintree Hospital, and North West Ambulance Service began investigating potential inappropriate access to patient records by its staff."
          }
        },
        {
          "@type": "Question",
          "name": "How can organisations prevent insider misuse of records?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Limit access to the smallest group that needs it, log every access completely, review those logs proactively rather than after an incident, and move records that do not need to be online into offline storage so they cannot be casually opened."
          }
        },
        {
          "@type": "Question",
          "name": "What action is being taken over the court files breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Ministry of Justice is investigating urgently, the prime minister has asked the Lord Chancellor to oversee the matter, and HM Courts and Tribunals Service and HM Prison and Probation Service are conducting their own investigations. The department is also reviewing staff conduct and acceptable use policies."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

A pattern, not an isolated caseWhy this is different from an ex…The records most at risk are the…What organisations should take f…SourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 16 September 2026 · Breaking 

# Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthport-court-files-insider-access-breach-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthport-court-files-insider-access-breach-2026&text=Southport%20court%20files%20breach%3A%20the%20access%20was%20authorised%2C%20the%20purpose%20was%20not%0A%0AThe%20Ministry%20of%20Justice%20has%20confirmed%20that%20courts%20staff%20accessed%20files%20relating%20to%20victims%2C%20survivors%20and%20families%20of%20the%20Southport%20attack%20without%20authorisation.%20It%20is%20the%20third%20insider%20access%20case%20connected%20to%20the%20attack%2C%20and%20it%20shows%20why%20perimeter%20security%20alone%20cannot%20protect%20the%20most%20sensitive%20records.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthport-court-files-insider-access-breach-2026)[](mailto:?subject=Southport%20court%20files%20breach%3A%20the%20access%20was%20authorised%2C%20the%20purpose%20was%20not&body=The%20Ministry%20of%20Justice%20has%20confirmed%20that%20courts%20staff%20accessed%20files%20relating%20to%20victims%2C%20survivors%20and%20families%20of%20the%20Southport%20attack%20without%20authorisation.%20It%20is%20the%20third%20insider%20access%20case%20connected%20to%20the%20attack%2C%20and%20it%20shows%20why%20perimeter%20security%20alone%20cannot%20protect%20the%20most%20sensitive%20records.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthport-court-files-insider-access-breach-2026)

![Court case files on wet stone steps outside a government justice building at dusk](/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg)

Court case files on wet stone steps outside a government justice building at dusk

Why it matters

## What this means for organisations holding critical data

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

In this analysis

1.  01 [A pattern, not an isolated case](#section-0)
2.  02 [Why this is different from an ex…](#section-1)
3.  03 [The records most at risk are the…](#section-2)
4.  04 [What organisations should take f…](#section-3)

**On this page**[A pattern, not an isolated case](#section-0)[Why this is different from an ex…](#section-1)[The records most at risk are the…](#section-2)[What organisations should take f…](#section-3)

The Ministry of Justice has confirmed an investigation after courts staff accessed case files relating to victims, survivors and families of the Southport attack without authorisation.

The unauthorised access was identified during a review of the department's digital systems. For a limited number of people, the information accessed included sensitive and personal data assessed as likely to result in a high risk to their rights and freedoms. Those affected are being notified directly, the Information Commissioner's Office has been informed, and the prime minister has asked the Lord Chancellor to oversee the matter. The MoJ has said there is no evidence personal data was shared with third parties, and that all wrongdoing will be met with extremely firm action. HM Courts and Tribunals Service and HM Prison and Probation Service are also investigating.

An MoJ spokesperson said the department was appalled, apologised to those affected, and described unauthorised access to court files as completely unacceptable.

## A pattern, not an isolated case

This is the third inappropriate access case connected to the Southport attack. In May, a Liverpool hospital trust admitted that nearly 50 staff had inappropriately accessed the medical records of some victims treated at Aintree Hospital. North West Ambulance Service later began investigating potential inappropriate access to patient records by its own staff.

Three separate organisations. Three separate systems. The same failure mode: people with legitimate credentials opening records they had no legitimate reason to open.

## Why this is different from an external attack

No firewall was bypassed. No password was stolen. No vulnerability was exploited. Every person involved almost certainly had valid access to the system in front of them, because their job required it.

This is the hardest class of breach to prevent, because the access path is legitimate. The only thing that was not legitimate was the purpose. Traditional security, built to keep outsiders out, has very little to say about an insider who is already in.

What limits insider misuse is control inside the perimeter: genuine least-privilege access scoped to role and case, complete audit logging of who opened what and when, proactive review of that logging rather than discovery by chance, and consequences that are known in advance. It is notable that this access was found during a review of digital systems, which suggests the logging existed. The question every organisation should ask is whether anyone is looking at theirs.

## The records most at risk are the ones that matter most

Court files, medical records and ambulance logs sit at the extreme end of sensitivity. When they relate to victims of a violent attack, the harm caused by inappropriate access is not abstract. It compounds the trauma of people who have already suffered the worst imaginable loss.

That is why the principle of Disconnect to Protect applies with particular force to records of this kind. Data that does not need to be online should not be online. Where records must remain accessible for live proceedings or care, access should be narrowed to the smallest possible group, monitored continuously, and reviewed as a matter of routine rather than after a breach.

[Offline Secure Storage](/offline-secure-storage) is built for the data an organisation must keep but does not need connected: archives, evidence copies, historical records. For the systems that must stay live, the answer is control. Both begin with the same admission: you cannot protect what everyone can reach.

## What organisations should take from this

First, assume insider misuse will be attempted wherever records are sensitive or newsworthy. Curiosity alone is a threat actor.

Second, audit access logs proactively. If your review process is what finds misuse, fund it. If you have no review process, that is the finding.

Third, separate what must be live from what must be kept. Every record moved out of a connected system is a record an insider cannot casually open.

## Sources

-   [BBC News: Southport attack victims, survivors and families hit by data breach](https://www.bbc.co.uk/news/articles/cr74kwn1eeyjo)
-   [BBC News: NHS staff accessed Southport victims' records inappropriately, hospital trust admits](https://www.bbc.co.uk/news/articles/cgmpz1mxzd9o)
-   [BBC News: Southport victim's dad accuses ambulance staff of breaching trust](https://www.bbc.co.uk/news/articles/c5yzy71p9zeo)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)