
Oxford City Council has disclosed a data breach following unauthorized access to legacy systems containing personal information of individuals affiliated with the council between 2001 and 2022. The incident, which also triggered a temporary disruption to the council’s ICT services, is under active investigation.
In a public statement posted on its website, the council confirmed that attackers accessed historic data stored in older systems, specifically affecting records of former and current council officers, as well as individuals involved in election duties such as polling station staff and ballot counters. There is currently no evidence that citizen data was compromised, nor that any of the accessed information has been disseminated.
“Unfortunately, the attackers were able to access some historic data on legacy systems,” the statement read. “We have now identified that people who worked on Oxford City Council-administered elections between 2001 and 2022… may have had some personal details accessed.”
The breach has led to delays in some council operations, although most impacted systems have since been restored. Residual backlogs, however, may continue to affect service delivery in the short term.
Oxford City Council, which manages essential public services for a population of approximately 155,000 residents, has notified relevant government bodies and law enforcement. It has also begun contacting affected individuals directly, providing them with incident details, guidance, and information about available support.
While the full extent of the breach is still being determined, officials say there is currently no indication of large-scale data exfiltration. The council has pledged to bolster cybersecurity defenses and implement lessons learned from the incident to help prevent future breaches.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543