Tewkesbury Borough Council shut down its systems after a suspected cyberattack

Organization
Tewkesbury Borough Council
Exploit
Human Error
Industry
Government

Tewkesbury Borough Council in Gloucestershire, England, declared a major incident on 4 September 2024 after its systems detected suspicious activity across a number of machines on its network. The council said it was proceeding on the assumption that its systems had been compromised.

As a precaution the authority shut down its IT and telephone systems and took its online services offline. Residents were told that many services would be unavailable or slower than usual, that phone lines would be busy, and that they should contact the council only when absolutely necessary. The council also warned residents to be alert to phishing attempts and to check that any message claiming to come from it used a .gov.uk address.

The council brought in a cyber incident response specialist and worked with the National Cyber Security Centre. In the days immediately after the shutdown it said the nature of the incident had not been confirmed, that it was still investigating whether any data had been compromised, and that there was no evidence at that point of a personal data breach.

The majority of systems were restored on 24 September 2024 after security specialists advised that they were safe to bring back, and the council said no data had been lost. The council later established that there had been no attack at all: at a meeting on 24 February 2025 it said the incident was an accident rather than an attack, a case of its own systems testing its own security, and put the cost of responding at £289,625.28. The Record noted that UK local authorities reported more than 160 data security incidents to regulators during 2023, around half of them involving ransomware.

Sources