Desk live·
ForensicPost
Nation-state/Accountability/File 24-0808

Sellafield Pleaded Guilty to Nuclear Site IT Security Failings

Britain’s nuclear regulator prosecuted the operator of the Sellafield site over information technology security offences between 2019 and early 2023. Sellafield Ltd entered a guilty plea in August 2024.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomSeascale, Cumbriathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSellafield Ltd
ActorUnattributed
D. Kennedy9 min readConfidence: high2 sources reviewed

The Office for Nuclear Regulation prosecuted Sellafield Ltd, which runs the nuclear site in Cumbria, under the Nuclear Industries Security Regulations 2003. The charges concerned information technology security offences over a period running from 2019 to early 2023. In August 2024 the company was found to have failed to comply with an approved security plan.

Prosecuted For The State Of The Defences

Almost everything in this database is a record of an incident. This is a record of a condition: the regulator did not need an intrusion to bring a case, only a failure to meet the plan the operator was working to.

That is unusual and worth marking. Where enforcement appears in this file set it is nearly always after a breach and directed at the response — how late the notification was, how the disclosure was worded. Here the offence is the posture itself.

A Four-Year Period, Not A Date

The charges span 2019 to early 2023. Nothing about that is a moment; it describes years in which required controls were not where they were supposed to be.

For a site holding one of the world’s largest stores of untreated nuclear waste, the absence of a named breach is not reassurance. It is the same problem recorded at the Polish heat plant, where an intrusion sat unrecognised for months: nobody can point to what did not get detected.

How we reported this

Compiled from regulator statements and public reporting, listed below. The case concerns compliance with a security plan; no breach of the site’s systems has been established publicly and we are not asserting one. Corrections: corrections@forensicpost.com.

Sources
  1. Sellafield to be prosecuted over alleged cyber compliance failureComputer Weekly
  2. Sellafield enters guilty plea following cybersecurity failingsNew Civil Engineer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary