Ransomware attacks happening every day in UK, intelligence agents say | BBC News

BBC NewsAbout 5 min readJul 22, 2025Watch original
THE SUMMARYAI-generated

Key Concepts:

Ransomware attacks, GCHQ, National Cyber Security Centre (NCSC), cyber security, data breaches, ransom demands, cybercrime, cyber defense, Scattered Spiders, blackging, geopolitical threats.

Main Topics and Key Points:

  • Ransomware Attacks and Their Impact: The segment focuses on the increasing threat of ransomware attacks on UK businesses and infrastructure, highlighting incidents affecting companies like Marks and Spencer (M&S), Co-op, and K&P (Knights of Old). K&P went bust after a ransomware attack due to an employee's compromised password.
  • The Role of GCHQ and NCSC: The National Cyber Security Centre (NCSC), a part of GCHQ, is actively involved in defending against cyber attacks. They receive at least one report of an organization being encrypted every day.
  • Increasing Frequency and Severity: 2025 is projected to be the worst year on record for ransomware attacks. The National Audit Office has described the threat as severe and advancing quickly, with a parliamentary joint committee suggesting the UK is close to a catastrophic incident.
  • Criminal Tactics and Actors: Ransomware gangs often operate from overseas, particularly countries like Russia, North Korea, and Iran. "Scattered Spiders" is a term for a newer type of attacker: English-speaking individuals who came from gaming backgrounds and exploit system vulnerabilities.
  • The Human Element: A significant vulnerability is the human element, with attackers using "blackging" (social engineering) to trick individuals into providing access to systems, such as feigning a forgotten password.
  • Financial Implications: In 2023, the average ransom demand is about £4 million a year. Many companies pay the ransom without reporting the incident. 19,000 ransomware attacks on UK businesses happened last year.

Important Examples, Case Studies, or Real-World Applications Discussed:

  • Marks and Spencer (M&S): Experienced disruption to its operations after a cyber attack over Easter, demonstrating the vulnerability of even large corporations. The M&S attack involved a "blackging" incident.
  • Co-op: Was breached in a cyber attack, further illustrating the widespread nature of the threat.
  • K&P (Knights of Old): A trucking company that went bankrupt after a ransomware attack locked their computers and stole their data because the hackers had worked out an employees password.
  • General Examples: Warehouses protecting goods are compared to digital companies protecting data.

Step-by-Step Processes, Methodologies, or Frameworks Explained:

  • Defense Layers: The NCSC provides a "first layer" of defense to prevent attacks. If prevention fails, the National Crime Agency steps in to assist.
  • Incident Response: When a ransomware attack is detected, the initial focus is on assessing the impact and attempting to contain the breach. The NCSC and other agencies work with affected organizations to investigate and recover.

Key Arguments or Perspectives Presented, with Their Supporting Evidence:

  • Individual Responsibility: Companies are ultimately responsible for protecting themselves against cyber attacks. The NCSC can provide guidance, but the onus is on businesses to implement adequate security measures.
  • The Threat is Grave: The UK is potentially nearing a "national incident" due to the increasing frequency and severity of cyber attacks.
  • Under Reporting: Many companies pay ransom demands but don't disclose the incidents, making it difficult to fully assess the scale of the problem.

Notable Quotes or Significant Statements with Proper Attribution:

  • NCSC Spokesperson: "We get in at least one report a day of an organization being encrypted."
  • Richard Bilton: "Talk to people who know about this world and they'll tell you a lot of companies pay and we never get to hear about it. They just pay and make it go away."
  • Richard Bilton: "We are quite near a national incident".
  • Richard Bilton quoting the National Audit Office: "the threat was severe and advancing quickly."

Technical Terms, Concepts, or Specialized Vocabulary with Brief Explanations:

  • Ransomware: A type of malware that encrypts a victim's files or systems, demanding a ransom for their release.
  • GCHQ: Government Communications Headquarters, a UK intelligence and security organization.
  • NCSC: National Cyber Security Centre, part of GCHQ, responsible for providing cyber security advice and support.
  • Encryption: The process of converting data into an unreadable format, requiring a key to decrypt.
  • Data Breach: An incident in which sensitive, protected, or confidential data is copied, transmitted, viewed, stolen, or used by an individual unauthorized to do so.
  • Blackging (Social Engineering): Manipulating people into divulging confidential information.
  • Scattered Spiders: A media name given to a brand of attacker, English-speaking individuals who came through gaming and exploit system vulnerabilities.

Logical Connections Between Different Sections and Ideas:

The segment begins by establishing the prevalence of ransomware attacks and then moves to discuss the governmental response, highlighting the roles of the NCSC and the National Crime Agency. It then delves into specific examples of companies affected, illustrating the real-world impact of these attacks. The discussion broadens to address the actors involved, the methods they use, and the overall state of cyber defense in the UK. The financial implications and the issue of underreporting are also explored, emphasizing the multifaceted nature of the problem.

Data, Research Findings, or Statistics Mentioned:

  • At least one report a day of an organization being encrypted to the NCSC.
  • In 2023, the average ransom demand is about £4 million a year.
  • 19,000 ransomware attacks on UK businesses last year.
  • The National Audit Office has described the threat as severe and advancing quickly.

Brief Synthesis/Conclusion of the Main Takeaways:

The threat of ransomware attacks is a significant and growing problem for organizations in the UK, with the potential to cause major disruption and financial losses. While government agencies like the NCSC are actively working to defend against these attacks, companies must take proactive steps to protect their systems and data. Human error and social engineering remain key vulnerabilities. The segment emphasizes the collective responsibility in bolstering cyber defenses to mitigate the escalating risk.

AI summaries can miss context or contain errors. Check important details against the original video.

MAKE IT YOURS

Read. Remember. Reuse.

Free tools

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.