Cybercrime in the United Kingdom 2026
Cybercrime remains one of the most persistent and costly threats facing UK businesses, charities, and individuals in 2026. On April 30, 2026, the Department for Science, Innovation and Technology (DSIT) and the Home Office published the government’s flagship Cyber Security Breaches Survey 2025/2026, confirming that 43% of UK businesses and 28% of charities identified a cyber security breach or attack in the previous 12 months — equating to roughly 612,000 businesses and 57,000 charities nationwide. Just this month, the National Cyber Security Centre (NCSC) confirmed that it continues to handle four nationally significant cyber incidents every week, with the majority now traced back to hostile foreign governments rather than criminal hackers, and the agency issued a fresh technical advisory investigating a wave of incidents affecting the retail sector, with early intelligence pointing to potential involvement of the threat group Scattered Spider.
This report compiles the latest verified UK government data — sourced directly from DSIT, the Home Office, the NCSC, and the Information Commissioner’s Office (ICO) — covering business breach rates, national significant incidents, ransomware, phishing, and the sectors most affected as of this week. As of today, the NCSC’s ongoing retail-sector investigation is a live, unfolding situation, with the agency sharing tactical intelligence through established sector-focused Trust Groups even as formal attribution — whether these incidents represent a single coordinated campaign or a series of unrelated events — remains under active investigation.
Interesting Cybercrime Facts and Latest Statistics in the UK 2026
| Cybercrime Fact Category | Latest Verified Figure |
|---|---|
| UK Businesses Identifying a Breach or Attack (2025/26) | 43% (~612,000 businesses) |
| UK Charities Identifying a Breach or Attack (2025/26) | 28% (~57,000 charities) |
| Total Estimated Cyber Crimes Against UK Businesses (2025/26) | 5.19 million |
| NCSC Nationally Significant Incidents Handled | ~4 per week |
| NCSC Annual Review Incident Count (Through Oct 2026) | 204 nationally significant incidents |
| Mean Cost of a Cyber Crime to a UK Business | £1,970 |
| Phishing — Share of Successful Business Breaches | 93% |
| Government Package to Bolster National Cyber Defences (2026) | £90 million |
Data source: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, April 30, 2026; National Cyber Security Centre, CYBERUK 2026 keynote address
These figures confirm that cybercrime remains a widespread and expensive problem across the UK economy despite years of sustained government attention. The Cyber Security Breaches Survey 2025/2026 — commissioned annually by DSIT and the Home Office and based on a representative sample of 2,112 businesses and 1,085 charities — found that 43% of businesses identified a breach or attack in the past year, a figure that has held remarkably steady even as the specific measure of confirmed cyber crime (as distinct from broader breaches or attacks) has actually declined slightly, from 22% in 2023/24 to 19% in 2025/26. Scaled across the full UK business population, the survey estimates 5.19 million individual cyber crimes were committed against UK businesses over the year, with an estimated 267,000 businesses falling victim to cyber crime specifically.
At the national security level, NCSC chief executive Richard Horne told the CYBERUK 2026 conference that the agency now handles roughly four nationally significant cyber incidents every week, with the majority of these attacks now traced directly or indirectly back to hostile foreign governments — principally Russia, China, and Iran — rather than purely criminal actors, a shift Horne described as part of a genuine “perfect storm” combining state-backed aggression with the accelerating capabilities of artificial intelligence. In response, the government announced a £90 million package to bolster the UK’s digital defences, underscoring how seriously Whitehall now treats the scale of the threat documented throughout this report.
UK Cyber Security Breaches Survey Statistics in 2026
Business Size — Micro (0-9 employees)............... 42% breached
Business Size — Small (10-49 employees)............. 46% breached
Business Size — Medium (50-249 employees)........... 65% breac
Business Size — Large (250+ employees).............. 69% breached
| CSBS 2025/2026 Metric | Figure |
|---|---|
| Overall Business Breach/Attack Rate | 43% |
| Overall Charity Breach/Attack Rate | 28% |
| Micro Businesses (0–9 Employees) Breached | 42% |
| Small Businesses (10–49 Employees) Breached | 46% |
| Medium Businesses (50–249 Employees) Breached | 65% |
| Large Businesses (250+ Employees) Breached | 69% |
| Confirmed Cyber Crime Rate, 2023/24 | 22% |
| Confirmed Cyber Crime Rate, 2024/25 | 20% |
| Confirmed Cyber Crime Rate, 2025/26 | 19% |
Data source: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, published April 30, 2026
The Cyber Security Breaches Survey, an official National Statistic, is the UK government’s single most authoritative annual measurement of how businesses and charities are faring against cyber crime, and its 2025/2026 edition confirms a clear pattern: exposure rises sharply with organisational size. While 42% of micro businesses and 46% of small businesses reported a breach or attack, that figure climbs to 65% of medium-sized businesses and 69% of large businesses — a pattern largely explained by larger organisations’ greater digital footprint, more valuable data holdings, and, notably, their greater capacity to actually detect and identify attacks in the first place, meaning the true gap in underlying exposure between small and large businesses may be somewhat narrower than the raw detection-based figures suggest.
Separately from the broader “breach or attack” measure, the survey also tracks a narrower category specifically defined as confirmed cyber crime, and this figure has shown a modest but consistent decline: from 22% of businesses in 2023/24, to 20% in 2024/25, and 19% in the most recent 2025/26 survey. Given the UK’s business population is overwhelmingly composed of micro and small businesses (81% and 16% respectively), which typically carry less mature security profiles, the survey’s authors caution that its findings inherently provide more statistically robust insight into the small-business threat landscape than into sophisticated, large-scale attacks against bigger organisations, which occur less frequently but often cause disproportionately greater damage.
National Cyber Security Centre Incident Statistics in the UK 2026
NCSC Nationally Significant Incidents (Weekly Average).... ~4
NCSC Annual Review Total (Through October 2026)........... 204
Government Cyber Defence Investment Package (2026)........ £90 million
| NCSC Metric | Figure |
|---|---|
| Average Nationally Significant Incidents Handled Weekly | ~4 |
| Total Nationally Significant Incidents (NCSC Annual Review, to Oct 2026) | 204 |
| Majority of “Nationally Significant” Threats Originate From | Nation states |
| Countries Named as Primary State Threats | Russia, China, Iran |
| Government Cyber Defence Package Announced 2026 | £90 million |
| NCSC-GCHQ Joint Advisory on China-Linked Campaign | August 2025 (12 allied agencies) |
| Recent Technical Advisory Subject | Russia’s GRU compromising home/small office routers |
Data source: National Cyber Security Centre, CYBERUK 2026 keynote and technical advisories; The Record from Recorded Future News
The National Cyber Security Centre, the UK’s technical authority on cyber security and part of GCHQ, confirmed at its flagship CYBERUK 2026 conference that the agency is handling an average of four nationally significant cyber incidents every week — activity NCSC chief executive Richard Horne described as remaining “fairly steady” compared to the agency’s most recent annual review, published in October 2026, which recorded 204 such incidents over the preceding twelve months. Crucially, Horne emphasised that the majority of these nationally significant threats now originate directly or indirectly from nation states, rather than from purely criminal groups, naming Russia, China, and Iran as continuing to target both UK organisations and individual citizens with distinct tactics and strategic objectives.
This state-backed threat picture has produced concrete recent action: in August 2025, the NCSC joined twelve allied international agencies in a joint advisory publicly linking three China-based companies to a global campaign targeting critical networks, overlapping with activity tracked elsewhere as Salt Typhoon. More recently, the NCSC published a technical advisory warning that Russia’s GRU military intelligence agency has been compromising home and small office routers to redirect internet traffic through servers under Russian control, enabling credential interception and network mapping for further targeting — precisely the kind of infrastructure-level threat that prompted the government’s newly announced £90 million package to strengthen the UK’s overall digital defences.
UK Ransomware and Major Incident Cost Statistics in 2026
Jaguar Land Rover Ransomware Attack — Estimated UK Cost........ £1.9 billion
Marks & Spencer / Co-op Ransomware — Combined Estimated Cost.... £270m–£440 million
UK Ransomware Victims Who Paid Despite NCSC Guidance............ 58%
Victims Subsequently Targeted for a Second Extortion Payment.... 21%+
| Ransomware/Major Incident Metric | Figure |
|---|---|
| Jaguar Land Rover Cyber Incident — Estimated UK Cost | £1.9 billion |
| Marks & Spencer and Co-op Attacks — Combined Estimated Cost | £270 million–£440 million |
| UK Ransomware Victims Who Paid a Ransom | 58%, despite NCSC guidance not to |
| Victims Subsequently Hit With a Second Extortion Demand | More than 1 in 5 (21%+) |
| UK Ransomware Victims Reporting Data Theft | 66% (two-thirds) |
| Businesses Reporting Ransomware (2025/26 CSBS) | 1%, down from 3% in prior two years |
| Businesses Reporting Revenue/Share Value Loss From Breach | 5%, up from 2% |
| Businesses Reporting Reputational Damage From Breach | 3%, up from 1% |
Data source: UK Cyber Monitoring Centre; Proofpoint 2026 AI-Era Ransomware Report; DSIT/Home Office Cyber Security Breaches Survey 2025/2026
The UK Cyber Monitoring Centre, an independent body established to assess the financial and operational impact of major cyber incidents, estimates that the ransomware attack on Jaguar Land Rover in late 2025 cost the UK economy approximately £1.9 billion, while the linked wave of retail-sector attacks affecting Marks & Spencer and the Co-op carried combined estimated costs of between £270 million and £440 million. These headline-grabbing figures illustrate why ransomware, even though it affects a comparatively small share of businesses in any given year, remains what NCSC officials consistently describe as the most acute cyber threat facing most UK organisations — the low-frequency, high-severity nature of ransomware means a single successful attack against a major employer can inflict damage measured in the billions.
Despite consistent NCSC guidance advising against paying ransoms, independent research from security vendor Proofpoint’s 2026 AI-Era Ransomware Report found that 58% of UK ransomware victims paid up anyway, and more than one in five of those who paid were subsequently targeted for a second extortion attempt — evidence that paying rarely resolves the underlying exposure and often signals to attackers that a given victim is a soft, repeat target. The same report found that two-thirds of UK ransomware victims (66%) experienced data theft during the incident, reflecting how ransomware has evolved from simple file-encryption extortion into a broader data-theft-and-leak business model, a shift Proofpoint attributes partly to generative AI “making existing human-centric methods harder to detect and more effective at scale.” Notably, the official CSBS 2025/2026 data shows the share of businesses reporting ransomware specifically fell to just 1%, down from 3% in each of the two previous years — though the survey’s authors caution this reflects the rarity of ransomware relative to more common attack types like phishing, not a decline in its severity when it does occur, a distinction reinforced by rising shares of businesses reporting revenue loss (up to 5%) and reputational damage (up to 3%) from breaches overall.
Phishing and Attack Vector Statistics in the UK 2026
Phishing — Share of Successful Business Breaches.......... 93%
Businesses Experiencing Phishing (CSBS 2025/26)............ 38%
Phishing Named Most Disruptive Attack Type (Among Affected). 69%
Impersonation Attacks (2025/26, Down From 17%).............. 12%
| Attack Vector Metric | Figure |
|---|---|
| Phishing — Share of Successful Breaches Against Businesses | 93% |
| Businesses Experiencing Phishing (CSBS 2025/26) | 38% |
| Phishing Named the Most Disruptive Attack Type | 69% of affected businesses |
| Impersonation Attacks, 2025/26 | 12%, down from 17% prior year |
| Sector With Highest Breach Rate — Information/Communications | 43% |
| Sector With Most Raw Incidents — Retail & Manufacturing | ~3,500 incidents |
| Individuals Aged 75+ — Most Likely to Report Financial Losses | Highest-risk age group |
Data source: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026; ICO data security incident trends; Heimdal Security analysis of UK CSBS data
Consistent with global trends, phishing remains overwhelmingly the dominant attack vector in the UK, cited as the initial cause behind 93% of successful breaches against businesses. The 2025/2026 survey found 38% of businesses experienced a phishing attack over the year, and among those affected, 69% named phishing as the most disruptive attack type they encountered — a finding that underscores why UK cyber security guidance continues to emphasise staff awareness training and email filtering as foundational defences, even as more sophisticated technical threats draw greater headline attention. Interestingly, impersonation attacks specifically fell to 12% of businesses in 2025/2026, down from 17% the previous year, a decline researchers attribute to attackers consolidating around more scalable, automated phishing campaigns rather than labour-intensive, bespoke impersonation schemes targeting specific individuals.
At the sector level, the CSBS data and ICO incident records tell subtly different stories depending on methodology: while the ICO’s raw breach counts show retail and manufacturing businesses experiencing the highest overall number of incidents (roughly 3,500), the CSBS’s rate-based analysis finds that information and communications companies are proportionally the most affected, with 43% of firms in that sector reporting a breach — a discrepancy explained by the far larger number of retail and manufacturing businesses overall diluting their proportional breach rate despite generating more absolute incidents. On the individual and consumer side, ICO and Action Fraud data consistently show that UK residents aged 75 and older remain the demographic most likely to report significant financial losses to cyber crime, a pattern that has held across multiple years of reporting and continues to inform targeted public-awareness campaigns from both the NCSC and the ICO, particularly as AI-generated scam content becomes increasingly convincing — a broader technology trend detailed further in the AI usage statistics, which documents how rapidly generative AI tools have been adopted across the UK population, including, unfortunately, by the criminals seeking to exploit them.
Live Incident Update: UK Retail Sector Cyberattacks 2026
NCSC Retail Sector Investigation — Ongoing.......... Confirmed August 2026
Suspected Threat Actor.............................. Scattered Spider (unconfirmed)
Primary Social Engineering Vector................... IT helpdesk password/MFA reset requests
| Live Incident Metric | Detail |
|---|---|
| NCSC Confirmation of Active Retail Sector Investigation | August 11, 2026 |
| Suspected Threat Group | Scattered Spider (unconfirmed, per industry intelligence) |
| Primary Attack Technique Suspected | Social engineering targeting IT helpdesks |
| Specific Exploited Process | Unauthorized password and MFA resets |
| NCSC Response Mechanism | Sector-focused Trust Groups |
| Formal Attribution Status | Under investigation — single campaign vs. unrelated incidents undetermined |
Data source: NCSC statements as reported by GBHackers, August 11, 2026
The most current development in UK cybercrime as of this report is the NCSC’s active investigation into a wave of cyber incidents affecting the retail sector, confirmed publicly on August 11, 2026. The agency is working directly with affected organisations to analyse attack patterns and minimise operational impact, though it has been careful to note that definitive attribution remains under investigation — specifically, whether these incidents represent a coordinated campaign by a single threat actor or a series of unrelated events affecting multiple retailers independently. Industry intelligence circulating around the investigation has suggested potential involvement of the threat group Scattered Spider, a collective previously linked to earlier UK retail-sector incidents and known for sophisticated social engineering techniques that specifically target IT helpdesks to trigger unauthorised password and multi-factor authentication resets, effectively bypassing technical security controls by manipulating human support staff instead.
In response, the NCSC is sharing tactical intelligence with affected companies through established sector-focused Trust Groups, a mechanism that facilitates cross-organisational knowledge sharing of emerging threats and effective countermeasures without requiring public disclosure of sensitive operational details before an investigation concludes. This retail-sector pattern echoes the earlier wave of 2025 attacks that struck Harrods, Marks & Spencer, and the Co-op, whose combined estimated costs — detailed earlier in this report — already run into the hundreds of millions of pounds, underscoring why the NCSC continues to treat any emerging retail-sector cluster with heightened urgency regardless of whether formal attribution to a single group is ultimately confirmed.
UK Public Cyber Risk and Digital Exposure Statistics in 2026
UK Internet Penetration Rate..................... 97.8%
UK Social Media User Identities.................. 55.5 million (79.0% of population)
UK Adults Expressing Excitement About AI......... Under 30% — lowest measured among major economies
| Digital Exposure Metric | Figure |
|---|---|
| UK Internet Users | 68.1 million (97.8% penetration) |
| UK Social Media User Identities | 55.5 million (79.0% of population) |
| UK Adults Reporting Excitement About AI | Under 30% — lowest among peer nations |
| UK Households Managed Through Digital/Online Services | Vast majority |
| Online Cancellation Button Mandate (EU, Referenced as Comparator) | June 2026 |
Data source: UK Social Media Statistics 2026; Metricool 2026 UK Social Media Report
The scale of the UK’s exposure to cybercrime is inseparable from the country’s near-total digital penetration: with 68.1 million internet users representing a 97.8% penetration rate, and 55.5 million social media user identities covering 79.0% of the total population, according to the UK social media statistics, virtually the entire UK population now maintains an active digital footprint that criminals can potentially target through phishing, impersonation, or credential-stuffing attacks. This ubiquitous connectivity is precisely why the NCSC and DSIT increasingly frame cyber security not as a narrow IT department concern but as a matter touching nearly every UK household and business simultaneously.
Notably, UK public sentiment toward the newest wave of digital technology remains comparatively cautious: separate research finds that fewer than 30% of UK adults express excitement about artificial intelligence, among the lowest enthusiasm levels measured across major global economies, even as AI-powered tools increasingly power both the UK’s cyber defences and the sophisticated phishing and deepfake-driven scams NCSC officials warn are accelerating. This tension — widespread digital dependency paired with public wariness about the very technology reshaping both attack and defence — sits alongside the UK’s broader public finance picture, detailed in the government debt statistics in the UK, since the £90 million cyber defence package announced this year represents just one of many competing demands on a national budget already managing a £2.91 trillion debt position.
Disclaimer: The data research report we present here is based on information found from various sources. We are not liable for any financial loss, errors, or damages of any kind that may result from the use of the information herein. We acknowledge that though we try to report accurately, we cannot verify the absolute facts of everything that has been represented.
