Info Gov

L&Q, one of the UK’s most significant housing associations, is working to restore online services for residents after a cyber-attack which saw webforms and emails from around 12,000 residents accessed by the perpetrators.

It has notified the Information Commissioner’s Office and the Regulator of Social Housing.

London & Quadrant (L&Q) reassured residents that their wider operating systems, including residents’ personal details, data about homes and tenancies, and information relating to suppliers and partners, remained secure throughout the incident.

Those directly affected by the breach received an email from the housing association and the website remained unavailable for a large part of Monday, with residents advised to email or phone the provider instead of using the online services.

Fiona Fletcher-Smith, chief executive at L&Q, said: “As soon as we detected the issue, our information security team took immediate steps to isolate and secure our website, and we are now carrying out a comprehensive investigation to understand how this happened, and ensure we can restore the site safely and securely as soon as possible.”

“The incident resulted in emails and webforms sent to us by approximately 12,000 residents being accessed without authorisation. Our investigation so far indicates that the incident is limited to the online contact made by these residents.”

An RSH spokesperson confirmed the Regulator had been notified about the data breach: “The Regulator of Social Housing was notified of the issue by L&Q and we continue to engage with them as they respond to the incident and address its implications.”

Also in this section

Sep 25, 2026

NHS England orders immediate suspension for staff suspected of snooping on patient records

NHS England has instructed every trust in England to suspend immediately any member of staff suspected of accessing patient records without a legitimate reason and to remove their access to NHS systems while the facts are established, in a letter from chief executive Sir Jim Mackey announcing a zero-tolerance approach to what he called snooping.
Sep 23, 2026

Prime Minister announces new National Centre for Information Defence

Prime Minister Andy Burnham has tasked the UK's security chiefs with establishing a National Centre for Information Defence to detect, attribute and disrupt hostile state information attacks, telling the UN General Assembly in New York on 22 September that AI would "multiply the threat" from disinformation and deepfakes.
Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.

InfoGov Masthead Newsletter 800