cybersecurity

London on Lockdown: Coordinated Cyberattack Cripples IT and Phone Systems Across Multiple Councils

December 03, 20253 min read

London on Lockdown: Coordinated Cyberattack Cripples IT and Phone Systems Across Multiple Councils

A coordinated cyberattack has disrupted critical services across several major London boroughs, forcing emergency shutdowns of IT systems, telephone lines, and online portals. The Royal Borough of Kensington and Chelsea (RBKC), Westminster City Council, and Hammersmith & Fulham Council have all confirmed they were hit beginning Monday, November 24 — triggering an escalating regional cyber crisis.

What started as “system issues” quickly revealed itself to be a serious cybersecurity incident impacting core public infrastructure.


🚨 How the Attack Unfolded

The first public signal came Monday afternoon, when RBKC posted on X warning residents of major system outages.

By Tuesday morning, the council reclassified the situation as a “serious IT issue” — a phrasing councils often use to avoid prematurely labeling an incident as a cyberattack.

Behind the scenes, however, internal memos told a far more urgent story.

🔥 Westminster & Hackney Raise Alarm

Westminster staff received alerts confirming that systems were deliberately shut down as part of the incident response process.

Hackney Council — already a victim of a devastating 2020 ransomware attack — issued an emergency internal communication describing a:

“Significant and immediate threat”

Hackney raised its internal cyber threat level to Critical, citing intelligence that multiple London councils had been targeted within a 24–48 hour window.


🛑 Impact Spreads Across Boroughs

Hammersmith & Fulham confirmed they, too, were affected — though so far there is no evidence their internal systems were breached.

Precautionary shutdowns were enacted across all three councils to prevent lateral movement and contain possible compromise.

Affected services include:

  • Online public portals

  • Telephone lines

  • Digital records systems

  • Internal staff applications

  • Public-facing communication tools

Residents across impacted boroughs have been advised to expect delays and intermittent service outages.


🕵️ National Security Agencies Step In

Given the scale and timing of the attack, multiple UK security agencies are now involved:

National Cyber Security Centre (NCSC)

Information Commissioner’s Office (ICO)
Metropolitan Police Cyber Crime Unit
Action Fraud (initial reporting)

The NCSC, part of GCHQ, confirmed active involvement and is working to assess the operational and data security impact.

Meanwhile, the Met Police Cyber Crime Unit has opened an investigation, though officials note the inquiry is still in early stages.


🔐 Councils Mobilize Overnight Response

RBKC stated their cybersecurity teams worked through the night implementing mitigations, isolating affected systems, and hunting for indicators of compromise.

In a statement, an RBKC spokesperson noted:

“It’s too early to determine who carried out this attack or their motives. We are investigating potential data compromise, which is standard practice in incidents of this nature. We remain vigilant should there be any further issues.”

The council apologized to residents for expected delays, confirming they are working with cyber specialists and the NCSC to restore services safely.


⚠️ Elliptic Systems Analysis

This coordinated attack highlights several critical realities for public-sector organizations:

1️ Local government remains a prime target

Public-sector digital infrastructure often runs on legacy systems and limited security budgets — making councils soft targets for organized threat groups.

2️ Attackers understand interdependencies

By striking multiple boroughs simultaneously, attackers increase stress on national response systems and maximize disruption.

3️ Precautionary shutdowns are becoming standard

When threat intel suggests active exploitation, shutting down proactively is the only way to prevent catastrophic spread.

4️ Public-facing systems are priority attack vectors

Web portals, authentication gateways, and telephony integration points frequently serve as the initial entry point.


🧭 What Residents Should Expect

Until forensic investigations conclude and systems are safely rebuilt, councils are warning of:

  • Slow or unavailable online services

  • Delayed response times

  • Unreachable phone lines

  • Temporary disruption of non-critical operations

Full restoration could take days or weeks depending on the scope of the compromise.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog