
Child and family agency Tusla, a state agency responsible for improving children’s well-being and outcomes, will soon contact around 20,000 people whose sensitive data was compromised during the 2021 cyber attack on the HSE, which provided IT services.
The affected individual will start receiving letters this week, and this extensive process, involving gardaí and the Data Protection Commissioner, will take around ten months.
Tusla CEO Kate Duggan said that during the attack on the HSE’s systems, information belonging to individuals and staff members, who engaged with Tusla, was copied. The leak data is primarily related to HR data, such as applications for annual leave.
However, no evidence has been presented by national or international experts that any information has been published on the dark web or involved in any fraudulent activity, according to Duggan. Duggan also stated that a High Court order was obtained to prevent stolen data sharing, processing, or publication.
According to Duggan, people who receive the notification will be given two options for how to proceed. People will be given the option of accessing an online portal and working through an online system to learn about the data that is relevant to them. Those who do not wish to use the online portal will be assigned a caseworker who can be reached at a toll-free number.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543