Sunday, September 13, 2026

Oxford City Council Hit by Cyberattack Exposing Employee Personal Data

Oxford City Council has confirmed it was the target of a sophisticated cyberattack that resulted in the exposure of personal data belonging to employees, including those involved in council-administered elections over the past two decades.

The council detected an unauthorised presence within its network last week, prompting immediate action from its automated security systems.

These systems swiftly removed the intruder and minimised the extent of access the attackers had to council systems and databases.

In the aftermath, external cybersecurity specialists were deployed to assist with the incident response, and the council proactively took down its main systems to conduct comprehensive security checks and a thorough investigation.

These precautionary measures led to disruptions in some council services throughout the week.

Staff have been working diligently to reduce the impact on residents, and the council has apologised for any inconvenience caused to those attempting to access services during the outage.

Most systems are now safely operational, with the remaining few expected to come back online within days, as per a report by Oxford.

“As a result of these precautionary checks, we can confirm that the Council’s email systems and wider digital services remain secure and safe to use,” a council spokesperson stated.

However, the investigation revealed that attackers managed to access historic data stored on legacy systems.

Specifically, individuals who worked on Oxford City Council-administered elections between 2001 and 2022—including polling station workers and ballot counters—may have had some personal details accessed.

The majority of those affected are current or former council officers. Importantly, there is no evidence to suggest that the information accessed has been shared with third parties or that there was a mass download or extraction of data.

The council has initiated direct communication with all potentially affected individuals, explaining the situation, outlining available support, and detailing the steps being taken to prevent similar incidents in the future.

The council emphasised its commitment to data security and expressed deep regret over the breach.

“We know how important it is to protect the information we hold. We take that responsibility extremely seriously, and this unlawful breach of Council systems is deeply regrettable for all impacted,” the spokesperson added.

The incident has been reported to relevant government authorities and law enforcement agencies. A full investigation is ongoing to determine exactly what data was accessed and whether any information was removed from council systems.

Residents and employees are urged to remain vigilant and report any suspicious activity related to their personal data.

The council has reiterated its dedication to transparency and security as it works to restore full functionality and trust.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News