A cybersecurity incident has disrupted the shared IT systems of the Royal Borough of Kensington and Chelsea, Westminster City Council, and the London Borough of Hammersmith and Fulham. The attack, first identified on a Monday morning, has led to outages affecting council websites, phone lines, and online reporting services, forcing the councils to invoke business continuity and emergency plans. The National Cyber Security Centre (NCSC) is assisting with remediation, and IT teams have implemented mitigations to restore services and protect data, though the full extent of the compromise remains under investigation.
Authorities have stated that it is too early to determine the responsible party or the motive behind the attack, and investigations are ongoing to assess whether any data has been compromised. The councils have notified the Information Commissioner’s Office as a precaution and are prioritizing support for their most vulnerable residents. Residents have been advised of service disruptions and assured that updates will be provided as more information becomes available. Media reports suggesting Hackney Council was affected have been denied by officials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By November 26, multiple outlets reported that RBKC and Westminster were suffering major service outages tied to shared infrastructure, while Hammersmith and Fulham was also affected. The cause and perpetrator had not been confirmed, though experts and reporting suggested a possible ransomware intrusion.
The National Cyber Security Centre, the Metropolitan Police, and specialist cyber incident responders became involved in investigating and remediating the attack. The UK Information Commissioner's Office was also notified as authorities assessed possible data compromise.
The London Borough of Hammersmith and Fulham, which shares elements of the affected IT environment, took precautionary measures that also caused business disruption. This marked the incident's expansion beyond the two primary councils initially hit.
As the incident unfolded, the affected councils invoked emergency and business continuity plans, shut down multiple computerized systems to contain potential damage, and provided alternative contact methods for residents. Websites, phone lines, and other council services were disrupted.
A significant cybersecurity incident began on Monday affecting shared IT services used by the Royal Borough of Kensington and Chelsea and Westminster City Council, with possible impact extending to Hammersmith and Fulham. The disruption knocked some systems offline and affected council operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.