
London on Lockdown: Coordinated Cyberattack Cripples IT and Phone Systems Across Multiple Councils
London on Lockdown: Coordinated Cyberattack Cripples IT and Phone Systems Across Multiple Councils
A coordinated cyberattack has disrupted critical services across several major London boroughs, forcing emergency shutdowns of IT systems, telephone lines, and online portals. The Royal Borough of Kensington and Chelsea (RBKC), Westminster City Council, and Hammersmith & Fulham Council have all confirmed they were hit beginning Monday, November 24 — triggering an escalating regional cyber crisis.
What started as “system issues” quickly revealed itself to be a serious cybersecurity incident impacting core public infrastructure.
🚨 How the Attack Unfolded
The first public signal came Monday afternoon, when RBKC posted on X warning residents of major system outages.
By Tuesday morning, the council reclassified the situation as a “serious IT issue” — a phrasing councils often use to avoid prematurely labeling an incident as a cyberattack.
Behind the scenes, however, internal memos told a far more urgent story.
🔥 Westminster & Hackney Raise Alarm
Westminster staff received alerts confirming that systems were deliberately shut down as part of the incident response process.
Hackney Council — already a victim of a devastating 2020 ransomware attack — issued an emergency internal communication describing a:
“Significant and immediate threat”
Hackney raised its internal cyber threat level to Critical, citing intelligence that multiple London councils had been targeted within a 24–48 hour window.
🛑 Impact Spreads Across Boroughs
Hammersmith & Fulham confirmed they, too, were affected — though so far there is no evidence their internal systems were breached.
Precautionary shutdowns were enacted across all three councils to prevent lateral movement and contain possible compromise.
Affected services include:
Online public portals
Telephone lines
Digital records systems
Internal staff applications
Public-facing communication tools
Residents across impacted boroughs have been advised to expect delays and intermittent service outages.
🕵️ National Security Agencies Step In
Given the scale and timing of the attack, multiple UK security agencies are now involved:
✔ National Cyber Security Centre (NCSC)
✔ Information Commissioner’s Office (ICO)
✔ Metropolitan Police Cyber Crime Unit
✔ Action Fraud (initial reporting)
The NCSC, part of GCHQ, confirmed active involvement and is working to assess the operational and data security impact.
Meanwhile, the Met Police Cyber Crime Unit has opened an investigation, though officials note the inquiry is still in early stages.
🔐 Councils Mobilize Overnight Response
RBKC stated their cybersecurity teams worked through the night implementing mitigations, isolating affected systems, and hunting for indicators of compromise.
In a statement, an RBKC spokesperson noted:
“It’s too early to determine who carried out this attack or their motives. We are investigating potential data compromise, which is standard practice in incidents of this nature. We remain vigilant should there be any further issues.”
The council apologized to residents for expected delays, confirming they are working with cyber specialists and the NCSC to restore services safely.
⚠️ Elliptic Systems Analysis
This coordinated attack highlights several critical realities for public-sector organizations:
1️⃣ Local government remains a prime target
Public-sector digital infrastructure often runs on legacy systems and limited security budgets — making councils soft targets for organized threat groups.
2️⃣ Attackers understand interdependencies
By striking multiple boroughs simultaneously, attackers increase stress on national response systems and maximize disruption.
3️⃣ Precautionary shutdowns are becoming standard
When threat intel suggests active exploitation, shutting down proactively is the only way to prevent catastrophic spread.
4️⃣ Public-facing systems are priority attack vectors
Web portals, authentication gateways, and telephony integration points frequently serve as the initial entry point.
🧭 What Residents Should Expect
Until forensic investigations conclude and systems are safely rebuilt, councils are warning of:
Slow or unavailable online services
Delayed response times
Unreachable phone lines
Temporary disruption of non-critical operations
Full restoration could take days or weeks depending on the scope of the compromise.
