Escalating Cyber Threats
The past few of years have marked a significant escalation in the frequency and severity of data breaches worldwide. In the UK, no sector has been spared from the relentless onslaught of cyberattacks.
According to official statistics from the Cyber Security Breaches Survey 2024 published by UK Government Department DSI&T, half of UK businesses and around a third of UK charities (32%) reported having experienced some form of cyber security breach or attack in the 12 months preceding winter 2023/2024.
This figure was much higher for medium sized businesses (70%), large sized businesses (74%) and high-income charities with £500,000 or more in annual income (66%).
This article delves into the most impactful cyber security breaches during the last couple of years, and outlines recommendations for organisations to implement.
Key Cyber Incidents in 2023-2024
Phishing and Malware Attacks
Phishing remained the most common type of attack, affecting 84% of UK businesses and 83% of UK charities. Malware attacks also posed a significant threat, with medium and large businesses reporting higher costs per breach.
Healthcare Sector Breaches
The healthcare sector faced notable challenges, with breaches exposing sensitive patient data. This included a ransomware attack on Synnovis, a service provider to NHS England, which resulted in major disruption to critical healthcare services and compromised patient data.
CrowdStrike Software Update Incident
CrowdStrike, a leading U.S cyber security firm faced issues when an update to their software caused worldwide system crashes. Around 8.5 million devices were affected globally, including in the UK, where hospitals, banks, and public services faced operational challenges.
Ministry of Defence Payroll Data Breach
A contractor for the Ministry of Defence, Shared Services Connected Ltd (SSCL), experienced a significant breach. Cyber attackers accessed payroll data exposing personal and financial information of thousands of current and former British military personnel. This incident raised concerns about data privacy and national security.

Emerging Trends
Ransomware-as-a-Service (RaaS)
The rise of RaaS models made ransomware attacks more accessible to cybercriminals, leading to an increase in such incidents.
AI-Powered Phishing
Cybercriminals leveraged artificial intelligence to create more convincing phishing campaigns, targeting UK businesses and individuals.
Recommendations
Organisations should prioritise cybersecurity by:
- Ensuring employees are trained to recognise phishing attempts and follow the organisation’s security policies.
- Restricting admin rights to systems wherever possible.
- Investing in technology, such as advanced threat detection systems, updated malware protection, cloud back-ups and network firewalls.
- Regularly updating and patching software to mitigate vulnerabilities.
For further information, see the National Cyber Security Centre guidance: 10 Steps to Cyber Security.
This article is for general information only. It does not constitute legal advice and should not be relied upon as such. If you require further information regarding its content, please contact us at info@kpdpconsultancy.co.uk. Law as of January 2025.
