A joint parliamentary committee report warned that the UK government is risking a catastrophic ransomware attack that could cripple the country’s critical infrastructure.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A new proposal from the Home Office would prevent the NHS as well as schools and local councils from making ransomware payments, and certain limitations would also be put on private companies along with the public sector.
Students are responsible for most school data breaches in the U.K., usually involving compromised, leaked, or weak credentials, setting them up for a life of cybercrime.
UK law enforcement has shared over half a million compromised passwords found in cloud storage with Have I Been Pwned. The headline item is that over one-third of these passwords (about 225 million) have not been logged before.
UK's NCSC issued an alert over the growing risk of ransomware attacks as threat actors diversified attack vectors and monetization methods, with some victims hit by repeat attacks shortly after paying a ransom.
The 2025 UK report is composed of 1,727 tips on cyber incidents over the course of the year that developed into a total of 429 cases that involved intervention by the NCSC IM team. The share of incidents ranked as "nationally significant" jumped from 89 in the prior year to 204 in the current one.
UK Police have arrested a 17-year-old suspected Scattered Spider member accused of the MGM hack that disrupted casinos and hotels in Las Vegas on September 12, 2023, costing over $100 million in recovery.
After an apparent refusal to pay a ransom demand, Russian hackers have leaked a sampling of 13 million records of UK police data to the dark web in retaliation. The records were stolen from a police contractor.
Restrictions on ransomware payments have become common for government agencies around the world, but it is still fairly rare to see them extended to the public sector or local levels of government. The new UK rules would additionally require all business types that are not impacted to notify the government.
UK retailer The Co-op has confirmed that over 6.5 million people were impacted by the April 2025 data breach, which was loosely attributed to the elusive Scattered Spider cybercriminal gang.










