ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

INC ransomware group claims major ransomware attack on Leicester City Council

Linked InXFacebook
bookmark_borderSave to Library

The infamous INC ransomware group has claimed responsibility for a significant cyber attack on Leicester City Council, stating that it stole up to 3 terabytes of data from the council’s systems.

 

On March 7, Leicester City Council announced in a press release that it identified a cyber security incident that affected IT systems and phone lines. The Council said it launched an internal investigation with assistance from cyber security experts to identify the nature and scope of the incident.

 

The Council said it notified relevant law enforcement authorities about the incident and its officials contacted other city councils who suffered similar cyber security incidents in the past to learn more about how they responded to those incidents.

 

The cyber attack had affected most of the Council departments’ phone numbers. The Council said it acted quickly to commission alternative numbers for the affected departments, including adult social care, child protection, homelessness, community support grant crisis, housing repairs, registrars, school transport, environment and noise nuisance and property related issues.

 

While the council did not initially disclose the identity of the hacker group responsible for the security incident, the INC ransom group claimed responsibility for the cyber attack on April 3, listing the Council on its dark web site. 

 

 

The group also claimed that it had in its possession up to 3 terabytes of data stolen from the Council’s systems and published samples of the stolen data to prove the authenticity of its claims.

 

Acknowledging the group’s claims, the Council admitted that the group had indeed stolen and published data stolen from its systems. “We have today been made aware that a small number of documents held on our servers have been published by a known ransomware group,” it said. 

 

“This relates to the cyber incident identified by the council on 7 March, which led to us closing down our IT systems. At the moment we are aware of around 25 or so confidential documents that have been published online. They include rent statements, applications to purchase council housing and identification documents such as passport information,” said Richard Sword, Leicester City Council’s strategic director of city developments and neighbourhoods.

 

“The breach of confidential information is a very serious matter and its publication is a criminal act. We are in the process of trying to contact all of those affected by this breach, and have also notified the Information Commissioner. We realise this will cause anxiety for those affected, and want to apologise for any distress caused.

 

“At this stage we are not able to say with certainty whether other documents have been extracted from our systems, however we believe it is very possible that they have. We are continuing to work with the cyber crime team at Leicestershire Police and the National Cyber Security Centre as part of this ongoing criminal investigation.

 

“As this is a live investigation, we are not able to comment in further detail, but will continue to give updates when we have news to share,” he added.

 

Oliver Spence, CEO of Cybaverse, said the ransomware attack on Leicester City Council is consistent with the INC ransomware group’s recent targeting of multiple public bodies in the UK.

 

“INC has been busy in the last few weeks, being responsible for two very damaging cyberattacks on UK public bodies. Last week it was revealed that the gang had claimed responsibility for the cyber attack on NHS Dumfries and Galloway, and now they are also claiming the hack on Leicester City Council.

 

“Given the UK government has very publicly voiced its commitment to never do business with ransomware actors, it’s hard to imagine INC would be expecting a payout from these attacks. This could suggest the gang is motivated by damage, rather than money, which means more public bodies could be on its target list,” he added.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543