Important information about the membership renewal portal security incident

On 30 September, our membership renewal portal was subject to a cyber-attack. We became aware of the incident on 1 October and blocked the unauthorised access. 

This notice explains what happened, what information may have been involved, what we are doing in response, and the steps you can take to protect yourself.

Some members’ and ex-members’ personal information, covering records from 2013 to now, may have been available to the hackers. This does not include credit or debit card information.

The incident did not involve the main member database. It mainly affects people who were going through the renewal or application process for this year, although there may also have been some access to historical records.

We have reported the breach to the ICO (in the UK) and the Data Protection Commission (in Ireland).

What Happened

  • On 1 October, we discovered that our membership renewal and application portal (and a data base attached to the old (pre 2021) ARA website) had experienced a security incident involving the renewal form.

  • An investigation was immediately launched, and steps were taken to secure the platform.

  • After reviewing the logs, it was identified that the hackers had begun the attack on 30 September.

  • Our IT team stopped the attack at approximately 7pm on 1 October.

What Information Was Involved

Based on our investigation, the data accessed or compromised includes the following categories of your personal information:

  • Name

  • ARA Membership number

  • Email address

  • Address

  • Details changed?

  • Sections Selected

  • Membership Region

  • Date renewed

  • Payment Reference

  • Amount Received

  • Contact confirmation

  • Contact by phone

  • Contact by email

  • Contact by post

To the best of our knowledge, your financial details were not involved or accessed.

Where people accessed the old ARA Website (pre 2021) using a password, that password may be compromised.

What We Are Doing

We deeply regret that this incident happened. As soon as we discovered the issue, we blocked access to the hackers and took down the member renewal site (which is separate from the main Archives.org.uk website). We have also formally notified the relevant supervisory authorities, the, Information Commissioner’s Office (ICO) in the UK and the Data Protection Commission in Ireland in line with our legal obligations.   

We will also be undertaking a comprehensive review and risk assessment of all our websites and any web hosted data bases.

Recommended Steps You Can Take

While we currently have no evidence that your information has been misused, we recommend that you remain vigilant:

  • Monitor the email and bank accounts that relate to your membership and look out for any unusual activity.

  • Be cautious of any unexpected phishing emails or communications referencing this incident.

  • If you use your old ARA Website password (in use up to November 2021) as a password for other applications you should change it.

For More Information

If you have any questions, concerns, or require further assistance, please contact Deborah Mason on Deborah.mason@archives.org.uk. You can also call her on 01823 327077 Option 03.

You also have the right to lodge a complaint with your local data protection regulator, such as the Information Commissioner's Office if you are based in the UK and the Data Protection Commission if you are based in Ireland.

With many apologies for any inconvenience caused by this breach.

For renewals please contact membership@archives.org.uk or call 01823 327 077.

Next
Next

Survey of Onsite Visitors to Archives live from 5 October 2026