A breach at UK law firm ACS:Law exposed confidential data on thousands of broadband subscribers accused of illegal file-sharing, including people allegedly linked to adult-film downloads. Reports said the leak followed disruption tied to Operation Payback, after which a backup file was mistakenly left publicly accessible and then widely redistributed online. The exposed material included roughly 1,000 internal emails, names, addresses, IP addresses, compensation demands, case notes, and in some cases payment details and correspondence from accused individuals; affected customers were reported across Sky, PlusNet, and other ISPs, with totals rising from more than 5,000 to well over 8,000 records as additional files surfaced.
The incident triggered scrutiny from the UK Information Commissioner's Office and the Solicitors Regulation Authority, with regulators examining whether ACS:Law had failed to protect sensitive personal data under the Data Protection Act and whether fines of up to £500,000 were warranted. ISPs including Sky said they were deeply concerned and suspended cooperation until adequate safeguards were shown, while critics said the leak underscored longstanding problems with ACS:Law's mass-enforcement tactics and reliance on IP-address evidence. Months later, solicitor Andrew Crossley told the High Court he had stopped pursuing alleged file-sharers, citing criminal attacks, hacked emails, and threats against him and the firm.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
During patent court proceedings in London, ACS:Law solicitor Andrew Crossley said he had stopped pursuing alleged illegal file-sharers in 26 MediaCAT cases. He cited criminal attacks, hacked emails, and death and bomb threats.
Sky said it was very concerned by the leak and suspended cooperation with ACS:Law until the firm could demonstrate adequate security measures. ACS:Law principal Andrew Crossley said the firm had notified police, the ICO, and the Solicitors Regulation Authority.
Additional leaked files exposed data on thousands more alleged file-sharers, including over 8,000 Sky subscribers and about 400 PlusNet users, with some records reportedly containing credit card details and correspondence from accused individuals. The stolen data was reportedly uploaded to The Pirate Bay for wider distribution.
The UK Information Commissioner's Office said it would examine ACS:Law's security controls after the breach, including encryption, firewalling, staff training, and why sensitive information was publicly accessible. Reports said the firm could face a fine of up to £500,000 under the Data Protection Act.
Attackers obtained and distributed ACS:Law data after the exposed backup file was discovered, leaking around 1,000 confidential emails and personal details tied to thousands of alleged file-sharers. The exposed material included names, addresses, IP addresses, allegations involving pornographic downloads, and other sensitive case information.
ACS:Law's website was hit by DDoS activity linked to 4chan participants in Operation Payback. During efforts to restore the site, a backup file containing website data was reportedly exposed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
web.archive.org
Open sourcebbc.co.uk
Open sourceweb.archive.org
Open sourcetheregister.co.uk
Open sourceweb.archive.org
Open sourcetheregister.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.