{"id":161783,"date":"2025-09-26T15:17:09","date_gmt":"2025-09-26T15:17:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/161783\/"},"modified":"2025-09-26T15:17:09","modified_gmt":"2025-09-26T15:17:09","slug":"uk-has-suffered-at-least-26-major-cyberattacks-in-last-five-years-guido-fawkes","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/161783\/","title":{"rendered":"UK Has Suffered at Least 26 Major Cyberattacks in Last Five Years \u2013 Guido Fawkes"},"content":{"rendered":"<p>Below is a list of 26 major cyberattacks on UK companies and public bodies since just 2020. There will of course be more which have gone unreported, or on a smaller scale. At the time of going to pixel, Jaguar Land Rover has still only launched a \u201cphased restart\u201d of its IT systems following a massive breach. Bear this in mind when Cabinet ministers <a href=\"https:\/\/order-order.com\/2025\/09\/26\/watch-nandy-claims-digital-id-will-be-more-secure-if-we-get-it-right\/\" rel=\"nofollow noopener\" target=\"_blank\">regurgitate<\/a>\u00a0talking points about how they take cybersecurity seriously, and it will be very, very different when it comes to mandatory digital ID. Do you believe them?<\/p>\n<p>Read the full, long list below\u2026<\/p>\n<p>2020<\/p>\n<p>EasyJet \u2013 data breach<br \/>Hackers accessed the airline\u2019s booking system using stolen credentials.<br \/>Approximately 9 million customer records affected (names, emails, travel plans).<br \/>Around 2,200 had payment card details accessed.<\/p>\n<p>Virgin Media \u2013 data exposure<br \/>A misconfigured database left customer information publicly accessible for months.<br \/>Approximately 900,000 customer records exposed (names, addresses, contact details, subscription info).<\/p>\n<p>Interserve \u2013 data breach<br \/>A phishing attack on the outsourcing firm led to employee data being compromised.<br \/>Approximately 113,000 staff affected (contact details, bank info, national insurance numbers).<\/p>\n<p>2022<\/p>\n<p>NHS (via Advanced Software Group) \u2013 ransomware<br \/>Conti group encrypted systems of an NHS software supplier, disrupting services.<br \/>Millions of patients potentially affected.<br \/>Patient data accessed and leaked.<br \/>\u00a33 million ICO fine issued in 2025.<\/p>\n<p>British Army \u2013 account takeover<br \/>Official social media accounts were hijacked and used for unauthorised posts.<\/p>\n<p>South Staffordshire Water \u2013 data breach<br \/>Russian hackers accessed internal systems and leaked data in an extortion attempt.<br \/>Volume of exposed data not disclosed.<\/p>\n<p>MI5 \u2013 DDoS attack<br \/>Russian group launched a denial-of-service attack, briefly disabling the agency\u2019s website.<br \/>Temporary public-facing outage.<\/p>\n<p>2023<\/p>\n<p>Royal Mail \u2013 ransomware<br \/>LockBit group encrypted systems, halting international mail tracking.<br \/>Service disruption lasted several days.<br \/>Recovery costs estimated over \u00a310 million.<\/p>\n<p>Ministry of Defence \u2013 data theft<br \/>Russian hackers compromised a fencing contractor to access sensitive documents.<br \/>Thousands of MoD files leaked, including information on nuclear and prison sites.<\/p>\n<p>Electoral Commission \u2013 data breach (disclosed August)<br \/>Russian state actors accessed electoral registers through compromised email and file-sharing platforms.<br \/>Breach began in 2021.<br \/>Around 40 million voter records affected (names, addresses, voting history).<\/p>\n<p>2024<\/p>\n<p>Southern Water \u2013 unauthorised access<br \/>Hackers breached servers and extracted customer data.<br \/>Estimated 100,000 to 200,000 customers affected (names, billing info, addresses).<\/p>\n<p>NHS Dumfries and Galloway \u2013 ransomware<br \/>Inc Ransom group stole and leaked staff and patient data.<br \/>Around 150,000 households affected.<br \/>3 terabytes of data published, including x-rays, test results, and personal information.<\/p>\n<p>Leicester City Council \u2013 ransomware<br \/>Attack caused IT outages and led to the publication of sensitive files.<br \/>Over 1.3 terabytes of data leaked, including rent statements, passport scans and child protection records.<\/p>\n<p>Ministry of Defence \u2013 data breach<br \/>Chinese hackers targeted a payroll contractor and accessed personnel data.<br \/>Approximately 272,000 current and former staff affected (names, bank details, home addresses).<\/p>\n<p>NHS (via Synnovis pathology supplier) \u2013 ransomware<br \/>Qilin group disrupted pathology services in London and leaked patient data.<br \/>1,693 procedures and 10,054 appointments delayed.<br \/>Around 400 gigabytes of patient information leaked.<\/p>\n<p>Billericay School \u2013 ransomware<br \/>Attack disabled all IT systems and forced temporary school closure.<br \/>Student records compromised, including names, addresses, medical notes and parent contact information.<\/p>\n<p>NHS (via CrowdStrike outage) \u2013 software failure<br \/>A faulty update from CrowdStrike caused widespread IT failures across NHS systems.<br \/>Millions of patients indirectly affected through delayed or cancelled appointments and record access.<\/p>\n<p>Locata (housing platform) \u2013 phishing attack<br \/>A breach enabled phishing campaigns targeting tenants in Manchester, Salford and Bolton.<br \/>Thousands of residents targeted.<\/p>\n<p>Transport for London (TfL) \u2013 data breach<br \/>Suspicious activity exposed customer data through internal systems.<br \/>Around 5,000 customers potentially affected (contact details and possible payment information).<\/p>\n<p>2025<\/p>\n<p>Unknown UK business \u2013 data theft.<br \/>Hackers stole and leaked records from an unidentified company.<br \/>Approximately 18.8 million personal records exposed.<\/p>\n<p>Royal Mail (via Spectos supplier) \u2013 data breach<br \/>German contractor was compromised, impacting Royal Mail\u2019s UK operations.<br \/>Around 144 gigabytes of internal and customer data leaked (names, addresses, tracking information).<\/p>\n<p>Legal Aid Agency \u2013 data breach<br \/>Sensitive records from more than a decade of legal aid cases were compromised.<br \/>Included personal, legal and financial data.<\/p>\n<p>Marks &amp; Spencer (M&amp;S) \u2013 ransomware<br \/>DragonForce group encrypted systems, causing a prolonged disruption.<br \/>Customer data stolen.<br \/>Online operations were offline for 46 days.<br \/>Estimated \u00a3300 million financial impact.<\/p>\n<p>Co-op \u2013 ransomware and system crash<br \/>Attack forced 2,300 stores into manual operations.<br \/>Widespread disruption to point-of-sale and supply chain systems.<br \/>Possible customer data exposure.<\/p>\n<p>Heathrow Airport (via Collins Aerospace) \u2013 cyber-attack<br \/>Cyber-attack on a shared check-in and baggage system affected multiple European airports including Heathrow.<br \/>Hundreds of flights delayed across Heathrow, Brussels and Berlin.<br \/>Disruption suspected to be linked to a cyber-criminal group.<\/p>\n<p>Jaguar Land Rover \u2013 cyber-attack<br \/>Attack in August forced a full IT shutdown across global operations.<br \/>Production halted across three UK factories.<br \/>Staff sent home and suppliers impacted, with some at risk of collapse.<br \/>Back-end systems and invoicing have only partially resumed as of late September.<\/p>\n","protected":false},"excerpt":{"rendered":"Below is a list of 26 major cyberattacks on UK companies and public bodies since just 2020. There&hellip;\n","protected":false},"author":2,"featured_media":161784,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[84,73466,59,56,54,55],"class_list":["post-161783","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-digital-id","tag-gb","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/161783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=161783"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/161783\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/161784"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=161783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=161783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=161783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}