This is a ranked guide to the 26 largest and most consequential data breaches affecting UK organizations or residents, current as of July 2026. Entries are ordered primarily by the number of records or individuals affected, with several high-notability incidents included regardless of scale because their impact on safety, national security, or public trust was severe. Where figures are disputed, estimated, or claimed only by attackers, we flag them as such.
For each incident you'll find the records affected, key dates, sector, attack vector, data exposed, and the regulatory aftermath, with a source link. One pattern runs through the most damaging recent cases: the biggest UK breaches of the past two years rarely started at the headline organization. They started with a supplier, a contractor, or an outsourced help desk.
Breaches at this scale sit on top of a steady baseline of attacks against UK organizations. The Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses and 28% of charities identified a breach or attack in the prior 12 months, equating to roughly 612,000 businesses and 57,000 charities.
A few figures from that data set frame everything below:
Enforcement is tightening in parallel. The Information Commissioner's Office has shifted toward fewer but heavier penalties, exemplified by the £14 million combined fine against Capita in October 2025, one of the largest UK security-failure fines on record.
The list runs from the largest exposures by records to lower-count incidents that earned their place through the sensitivity of the data or the safety consequences for the people involved. These UK data breach statistics reflect the current public record, including revised numbers where organizations updated their initial estimates.
Records affected: Approximately 40 million registered voters (electoral registers 2014 to 2022, plus around 100,000 people on the overseas and open registers)
Date of breach: Initial access August 2021 (undetected for roughly 14 months)
Date disclosed: August 2023
Sector: Government / electoral administration
Attack vector: Exploitation of unpatched Microsoft Exchange servers, followed by persistent access to email and file servers
Data exposed: Names, home addresses, email addresses, and the contents of the Commission's email system
Hostile actors sat inside the Electoral Commission's systems for more than a year before detection in October 2022, and because the Commission held copies of the full electoral registers, the personal data of essentially every registered voter across an eight-year window was accessible. In March 2024 the UK Government attributed the intrusion to a China state-affiliated actor, framing it as espionage rather than criminal data theft.
Aftermath: The ICO issued a formal reprimand in July 2024 rather than a fine, concluding the Commission had failed to keep servers patched and had not enforced adequate password policies, while noting no evidence the data had been misused.
Source: Computer Weekly: Basic failures led to hack of Electoral Commission data on 40 million people
Records affected: 13.8 million UK consumers (revised upward from an initial estimate of 400,000)
Date of breach: May to July 2017
Date disclosed: September 2017, with the full UK figure confirmed October 2017
Sector: Financial services / credit reference
Attack vector: Exploitation of an unpatched Apache Struts vulnerability in Equifax's US dispute portal, where UK data had been processed
Data exposed: Names, dates of birth, telephone numbers, partial card numbers, and in some cases addresses, usernames, passwords, and security questions and answers
The 2017 Equifax breach is remembered as a US event, but UK data had been routed through the compromised US environment, exposing 13.8 million British consumers. The ICO found that the UK arm had failed to ensure its US parent was adequately protecting UK consumer data, making it one of the clearest precedents among UK financial services data breaches on accountability for data processed offshore.
Aftermath: The ICO fined Equifax Ltd £500,000 in September 2018, the pre-GDPR maximum, and the Financial Conduct Authority separately fined it £11,164,400 in October 2023 for its handling of the incident.
Source: FCA: Equifax Ltd fined for cyber security breach
Records affected: 5.6 million payment cards and approximately 14 million personal data records (revised sharply upward from an initial estimate of 1.2 million)
Date of breach: July 2017 to April 2018
Date disclosed: June 2018, revised upward July 2018
Sector: Retail
Attack vector: Point-of-sale malware installed on 5,390 tills, harvesting card data as it was processed
Data exposed: Payment card data, names, postal and email addresses, and failed credit checks
Attackers ran card-scraping malware across thousands of Dixons Carphone tills for nine months without detection, and the initial disclosure dramatically understated the scope, with the personal-record figure revised from 1.2 million to around 14 million weeks later. The ICO found systemic failures including poor network segregation, absent patching, and a lack of local firewalls.
Aftermath: The ICO fined DSG Retail Ltd £500,000 in January 2020, again the Data Protection Act 1998 maximum because the conduct predated GDPR, following a separate £400,000 fine against Carphone Warehouse in 2018.
Source: Computer Weekly: Retail group Dixons Carphone fined £500,000 over data breach
Records affected: 9 million customers, including 2,208 with credit card details exposed
Date of breach: January 2020 (with unauthorized access reported from October 2019)
Date disclosed: May 2020
Sector: Aviation
Attack vector: Not publicly confirmed; described by easyJet as a "highly sophisticated" intrusion
Data exposed: Email addresses and travel itinerary details for 9 million customers; full credit card numbers and CVV codes for 2,208 customers
easyJet disclosed the breach roughly four months after discovery, drawing criticism for the delay. Travel itinerary data is unusually sensitive because it reveals movement patterns, and the exposure of full card numbers including CVV for a subset of customers made the incident materially worse than a simple contact-data leak.
Aftermath: A group claim was brought in the High Court on behalf of affected passengers. The ICO investigated but has not published a monetary penalty.
Source: Computer Weekly: Nine million easyJet customer details lost in data breach
Records affected: Approximately 6.9 million users globally, of whom 155,592 were UK residents; around 14,000 accounts were directly compromised
Date of breach: April to September 2023
Date disclosed: October 2023
Sector: Consumer genomics / health
Attack vector: Credential stuffing against accounts with reused passwords and no mandatory multi-factor authentication, then mass scraping via the DNA Relatives feature
Data exposed: Names, dates of birth, profile photos, geographic location, ancestry and ethnicity estimates, health-related genetic reports, and family relationship data
Attackers logged into roughly 14,000 accounts using credentials leaked elsewhere, then exploited the opt-in DNA Relatives feature to pull profile data on millions of linked users. Datasets specifically targeting Ashkenazi Jewish and Chinese users were advertised on criminal forums, giving the incident an explicit ethnic-targeting dimension.
Aftermath: The ICO fined 23andMe £2.31 million in June 2025, citing inadequate authentication and incident response. The company filed for Chapter 11 bankruptcy in March 2025, raising questions about the custody of affected UK users' genetic data.
Source: The Register: 23andMe hit with £2.3M fine after exposing genetic data
Records affected: Approximately 6.6 million individuals, including special category data
Date of breach: March 2023
Date disclosed: March 2023, with scope revised repeatedly through 2023
Sector: Outsourcing / business process services
Attack vector: Malware delivered to an employee device, escalated to domain-level access; a separate unsecured storage bucket also exposed benefits data
Data exposed: Names, contact details, National Insurance numbers, bank details, pension records, and special category data including health and criminal record data
Capita detected suspicious activity but took nearly a week to remove the intruder, during which data on millions of people was exfiltrated. Because Capita administers pension schemes and public-sector contracts, the fallout spread across the Universities Superannuation Scheme, dozens of local authorities, and multiple NHS bodies.
Aftermath: In October 2025 the ICO fined Capita plc and Capita Pension Solutions Ltd a combined £14 million, reduced from a provisional figure reported at around £45 million after remediation and cooperation were taken into account.
Source: CPO Magazine: ICO fines Capita £14 million over data breach affecting 6 million people
Records affected: Personal data of all 6.5 million Co-op members
Date of breach: Late April 2025
Date disclosed: April 2025; full member-data impact admitted May 2025
Sector: Retail / grocery / funeralcare
Attack vector: Social engineering of IT helpdesk staff to reset credentials and bypass multi-factor authentication, attributed to the Scattered Spider ecosystem
Data exposed: Member names, contact details, and dates of birth; Co-op stated no financial, payment, or password data was taken
Co-op initially described the incident as an attempted intrusion, then confirmed within two weeks that attackers had copied the data of every one of its 6.5 million members. The group pre-emptively shut down large parts of its IT estate, which caused significant stock shortages across its convenience-store network for weeks.
Aftermath: Co-op reported a revenue impact of around £206 million for the first half of 2025. The National Crime Agency arrested four people in July 2025 in connection with the Co-op, M&S, and Harrods intrusions, and the ICO opened an investigation.
Source: Computer Weekly: Co-op declares cyber attack damage cost £206m
Records affected: Approximately 339 million guest records globally, of which around 7 million related to UK residents
Date of breach: 2014 (Starwood systems) to September 2018
Date disclosed: November 2018
Sector: Hospitality
Attack vector: Compromise of the Starwood reservation database prior to Marriott's 2016 acquisition, undetected through the integration; widely attributed to a Chinese state-linked actor
Data exposed: Names, addresses, phone numbers, email addresses, passport numbers, arrival and departure dates, and encrypted payment card data
Attackers were inside the Starwood reservation environment for four years, spanning Marriott's acquisition, so Marriott inherited an active compromise it did not identify during due diligence. Around 5.25 million unencrypted passport numbers were among the exposed records, and it sits alongside the biggest data breaches worldwide as the standard reference for cyber due diligence in mergers and acquisitions.
Aftermath: The ICO fined Marriott £18.4 million in October 2020, sharply reduced from a £99.2 million notice of intent, citing remediation and the economic impact of COVID-19.
Source: Hunton: ICO fines Marriott International £18.4 million for security breach
Records affected: Approximately 5 million registered companies, and by extension the personal data of their directors and officers (the number of individuals actually accessed has not been published)
Date of breach: Vulnerability introduced October 2025; live for roughly five months until March 2026
Date disclosed: March 2026
Sector: Government / corporate registry
Attack vector: A logic and session-handling flaw; a user with any valid Companies House login could select "File for another company", enter any company number, press the browser back button four times, and view the target company's dashboard using only their own ordinary login
Data exposed: Company officers' residential (home) addresses, email addresses, and dates of birth, including data suppressed from the public register
The exploit required no tooling, no technical skill, and no credentials beyond an ordinary free Companies House account. Residential address suppression is a statutory protection used by people at risk of harassment, stalking, or violence, so exposing that field carries direct physical safety consequences rather than only fraud risk.
Aftermath: Companies House suspended the WebFiling service and self-reported to both the ICO and the National Cyber Security Centre. As of late July 2026 no penalty had been published and no figure released for how many records were actually accessed during the five-month window.
Source: Help Net Security: Companies House data exposure
Records affected: 2.7 million UK riders and 82,000 UK drivers (part of 57 million global records)
Date of breach: October to November 2016
Date disclosed: November 2017 (concealed for over a year)
Sector: Transport / gig economy
Attack vector: Credentials found in a private code repository used to access an Uber cloud storage environment
Data exposed: Names, email addresses, mobile phone numbers, and for drivers, journey and earnings data
Uber paid the attackers $100,000 through its bug bounty program and required them to sign non-disclosure agreements, concealing the breach for more than a year rather than notifying regulators or users. The cover-up, not the intrusion, is what makes this case a landmark, and it reshaped how the largest US data breaches involving concealment are prosecuted.
Aftermath: The ICO fined Uber £385,000 in November 2018. The company's former chief security officer was convicted in a US federal court in October 2022, the first criminal conviction of a security executive for breach concealment.
Source: Computer Weekly: ICO fines Uber £385,000 for data protection failings
Records affected: Approximately 900,000 patients identified in the published dataset (estimated; Synnovis and NHS England have not published a final confirmed figure)
Date of breach: June 2024
Date disclosed: June 2024, with patient death confirmed June 2025
Sector: Healthcare / pathology
Attack vector: Qilin ransomware, with initial access reported as via compromised credentials
Data exposed: Patient names, NHS numbers, dates of birth, test descriptions and results, and in some records data relating to sexually transmitted infections and cancer diagnoses
The Qilin attack crippled pathology services across major south-east London hospitals, forcing the postponement of more than 10,000 outpatient appointments and over 1,700 elective procedures, and triggering a national appeal for O-type blood. Around 400GB of data was published to a criminal leak site, ranking it among the most severe healthcare data breaches on record.
Aftermath: In June 2025 a hospital trust confirmed one patient's death was partly attributed to a delayed blood test result caused by the attack, the first publicly confirmed UK death linked to a cyber attack. The ICO opened an investigation into Synnovis.
Source: The Register: Qilin ransomware attack on NHS supplier contributed to patient fatality
Records affected: 900,000 customers and potential customers
Date of breach: Database left unsecured from April 2019; accessed at least once by an unauthorized party
Date disclosed: March 2020
Sector: Telecommunications / media
Attack vector: Misconfiguration; a marketing database was left accessible without password protection for around ten months
Data exposed: Names, home and email addresses, phone numbers, and in a small number of cases requests to block or unblock adult, gore, and gambling websites
This was not a hack but a configuration failure: a marketing database sat on the open internet for ten months and was accessed by at least one unauthorized third party. The inclusion of website-blocking preference data made a subset of records unusually sensitive.
Aftermath: The ICO investigated and no monetary penalty was published. A group claim was filed in the High Court seeking damages for distress on behalf of affected customers.
Records affected: Approximately 430,000 customer records
Date of breach: Attempted intrusion detected May 2025; a separate third-party compromise disclosed September 2025
Date disclosed: May 2025 (initial), September 2025 (customer data confirmed)
Sector: Luxury retail
Attack vector: Initial attempt via the Scattered Spider-linked social engineering wave that struck M&S and Co-op; the September disclosure involved a compromise at a third-party service provider
Data exposed: Names and basic contact details for around 430,000 customers; Harrods stated no payment or account password data was taken
Harrods was the third major UK retailer hit in the spring 2025 Scattered Spider campaign, initially reporting that it had contained the attempt. In September 2025 it disclosed a separate incident at a third-party provider, and because the customer base skews high net worth, even name-and-contact data carries elevated targeted fraud and physical-security risk.
Aftermath: Harrods declined to engage with the extortion attempt. Four arrests were made by the NCA in July 2025 across the M&S, Co-op, and Harrods investigations, and the ICO was notified.
Source: The Register: Harrods blames supplier after crims steal 430k customers' data
Records affected: 429,612 customers and staff, including 244,000 with card details and around 77,000 with CVV numbers
Date of breach: June to September 2018
Date disclosed: September 2018
Sector: Aviation
Attack vector: Magecart-style skimming; malicious code injected into the BA website and app payment flow after the attacker gained access via compromised credentials for a supplier employee, with no multi-factor authentication in place
Data exposed: Names, addresses, email addresses, payment card numbers, expiry dates, and CVV codes
Attackers redirected customer payment data to a lookalike domain in real time for over two months, harvesting complete card details including CVV, the most directly monetizable form of payment data. The ICO found BA had no adequate justification for the absence of multi-factor authentication or file integrity monitoring, making it the reference case for supply-chain-enabled web skimming in the UK.
Aftermath: The ICO fined BA £20 million in October 2020, down from a record £183.39 million notice of intent. A group action on behalf of more than 16,000 claimants was settled in July 2021 on confidential terms.
Source: Pinsent Masons: British Airways fined £20m over GDPR breach
Records affected: Approximately 272,000 serving armed forces personnel and veterans
Date of breach: Detected early May 2024
Date disclosed: May 2024
Sector: Defence / government outsourcing
Attack vector: Compromise of a third-party payroll system operated by contractor SSCL; the Government did not formally attribute the attack, though ministers pointed to a state actor and reporting linked it to China
Data exposed: Names, bank account details, and in a small number of cases personal addresses of current and former military personnel
An external payroll contractor holding the banking details of the majority of the UK's serving military was compromised, exposing data with obvious value for both financial fraud and foreign intelligence targeting. The then Defence Secretary told Parliament that a malign actor was suspected and that the system had been taken offline.
Aftermath: The Ministry of Defence stood up an eight-point response plan including personal data monitoring for affected personnel. The ICO was notified, and no monetary penalty against SSCL had been published as of July 2026.
Source: AP via Global News: UK payroll data breach exposed details of 272,000 military personnel
Records affected: Approximately 2.1 million individual pieces of data relating to legal aid applicants, covering applications from 2010 onward
Date of breach: April 2025
Date disclosed: May 2025
Sector: Government / justice
Attack vector: Not fully disclosed; the Ministry of Justice confirmed a cyber attack on the Legal Aid Agency's digital services with data downloaded by the attackers
Data exposed: Names, addresses, dates of birth, National Insurance numbers, criminal history, employment status, and financial data including debts, contributions, and payments
This is arguably the most sensitive UK government breach by content rather than volume. Legal aid records combine criminal history with financial hardship data and information about people involved in domestic abuse, family court, and immigration proceedings, so exposure can directly endanger people fleeing violence.
Aftermath: The Ministry of Justice took the digital application service offline and told applicants to assume their data had been taken, causing significant disruption to the justice system. As of July 2026 no ICO penalty had been published.
Source: Computer Weekly: Legal Aid Agency breach may encompass millions of people
Records affected: Approximately 1.5 million UK customers (around 9.4 million across Europe); approximately 60,000 Barclaycard payment cards subject to known fraud
Date of breach: February to June 2018
Date disclosed: June 2018
Sector: Ticketing / entertainment
Attack vector: Magecart compromise of a third-party JavaScript chatbot supplied by Inbenta, which Ticketmaster had deployed on its payment pages contrary to the supplier's intended use
Data exposed: Names, addresses, email addresses, telephone numbers, payment card numbers, and CVV numbers
Ticketmaster embedded a supplier's customer-support chatbot script directly into its payment pages, and when the supplier was compromised the script began skimming live card data. Barclaycard flagged a fraud pattern in April 2018, but Ticketmaster took a further nine weeks to identify the source.
Aftermath: The ICO fined Ticketmaster UK Ltd £1.25 million in November 2020. Around 60,000 Barclaycard customers were victims of known fraud, and a group claim was brought on behalf of affected customers.
Source: Computer Weekly: Ticketmaster fined £1.25m by ICO
Records affected: Number not disclosed; M&S confirmed personal data of an unspecified portion of its customer base (the number affected has never been confirmed and should not be equated to the total customer base)
Date of breach: Initial access reported as February 2025, with disruption from April 2025
Date disclosed: April 2025; customer data theft confirmed May 2025
Sector: Retail
Attack vector: Social engineering of a third-party IT service desk to obtain credential resets, attributed to Scattered Spider, followed by DragonForce ransomware deployment
Data exposed: Names, dates of birth, home and email addresses, phone numbers, order history, and masked payment card digits; M&S stated no usable payment card details and no account passwords were taken
M&S suspended online ordering entirely for around six weeks, one of the longest e-commerce outages ever suffered by a major UK retailer. The attackers used help-desk impersonation rather than a technical exploit, which shifted the board-level conversation toward identity verification and outsourced IT support as the primary risk surface.
Aftermath: M&S estimated a roughly £300 million hit to 2025/26 operating profit before mitigation (which includes insurance and cost actions). The NCA arrested four people in July 2025, the ICO opened an investigation, and the incident fed into the UK Cyber Security and Resilience Bill debate.
Source: CNBC: M&S cyberattack to wipe out nearly one-third of annual profits
Records affected: A spreadsheet containing the details of 18,714 Afghan Relocations and Assistance Policy (ARAP) applicants; reporting cites figures of up to around 100,000 people when family members are counted (estimated and disputed)
Date of breach: February 2022 (spreadsheet emailed outside authorized government systems in error)
Date disclosed: Data surfaced online August 2023; publicly disclosed July 2025 when the superinjunction was lifted
Sector: Defence / government
Attack vector: Human error; a Defence official emailed a dataset believing it contained only a small extract, when hidden rows contained the full applicant list
Data exposed: Names, contact details, family member details, and application information for Afghans who had worked with or supported UK forces
A single mis-sent spreadsheet exposed the identities of Afghans who had assisted British forces, a group facing direct Taliban reprisal risk. The Ministry of Defence obtained a superinjunction in September 2023 that barred reporting of the breach and of the order itself, and it held for nearly two years.
Aftermath: The Government announced a compensation scheme, while separate group litigation could run far higher. Note that the ICO's £350,000 fine against the Ministry of Defence relates to a separate September 2021 incident in which ARAP email addresses were exposed in a mass email, not to the February 2022 spreadsheet leak.
Source: Forces News: MOD faces first legal claim over Afghan data breach
Records affected: Approximately 490,000 files, around 600GB of data, including internal HR and employee records; a subset of user data was also affected
Date of breach: October 2023
Date disclosed: October 2023, with data-leak confirmation November 2023
Sector: Culture / national institution
Attack vector: Rhysida ransomware; the likely entry point was compromised credentials on a terminal services server without multi-factor authentication
Data exposed: Employee personal data including HR records, plus internal documents; user data was among the leaked files
Rhysida encrypted and exfiltrated data, then ultimately dumped roughly 600GB when the Library refused to pay. What makes this the most instructive UK ransomware case is the Library's decision to publish a detailed public lessons-learned report in March 2024, citing legacy infrastructure and a highly customized on-premise estate as reasons recovery was so slow.
Aftermath: The Library estimated recovery costs of around £6 million to £7 million, drawn largely from its own reserves. No ICO penalty was issued, and its published cyber incident review became recommended reading across the UK public sector.
Source: British Library: Learning lessons from the cyber-attack
Records affected: 156,959 customers, including 15,656 with bank account numbers and sort codes
Date of breach: October 2015
Date disclosed: October 2015
Sector: Telecommunications
Attack vector: SQL injection against three legacy webpages inherited from TalkTalk's 2009 acquisition of Tiscali, running an outdated database version with a known, patchable vulnerability
Data exposed: Names, addresses, dates of birth, email addresses, phone numbers, account information, and bank account details and sort codes for a subset
The attack used a basic injection technique against pages TalkTalk did not know it still had, exploiting a vulnerability for which a fix had been available for more than three years. TalkTalk's chaotic public communications became a case study in how not to handle breach disclosure.
Aftermath: The ICO fined TalkTalk £400,000 in October 2016, at the time the largest fine the regulator had ever issued, followed by a separate £100,000 fine in 2017. TalkTalk reported around £42 million in costs and lost more than 100,000 customers.
Source: Pinsent Masons: Record £400,000 fine for TalkTalk following data breach
Records affected: 113,000 current and former employees
Date of breach: March to May 2020
Date disclosed: May 2020
Sector: Construction / outsourcing
Attack vector: A phishing email opened by an employee installed malware; the endpoint protection tool quarantined it and raised an alert that Interserve failed to investigate, allowing the attacker to move laterally, encrypt 283 systems, and exfiltrate data
Data exposed: Names, contact details, National Insurance numbers, bank account details, and special category data including ethnic origin, religion, disability, sexual orientation, and health information
The technical control worked, and the organization ignored it: Interserve's anti-virus flagged and quarantined the malware, but nobody followed up on the alert, and the attacker returned to complete the compromise. The ICO also found outdated software, unsupported operating systems, and inadequate staff training.
Aftermath: The ICO fined Interserve Group Ltd £4.4 million in October 2022, one of its largest security-failure penalties, pairing the announcement with a public warning about ignoring alerts and running unsupported software.
Source: CSO Online: UK ICO fines Interserve £4.4 million
Records affected: 79,404 people (final ICO figure, revised down from an initial 82,946), including 890 people receiving home care
Date of breach: August 2022
Date disclosed: August 2022
Sector: Health and social care software / NHS supplier
Attack vector: LockBit ransomware; initial access via a customer account on a Citrix server that lacked multi-factor authentication
Data exposed: Phone numbers, medical records, and for 890 people receiving care at home, details of how to gain entry to their homes
Advanced's systems underpin NHS 111 triage, out-of-hours GP services, and mental health records. When LockBit took them down, NHS 111 fell back to pen and paper for weeks, and the exposure of home-entry information for 890 vulnerable people receiving domiciliary care is among the most alarming data categories in any UK breach.
Aftermath: The ICO fined Advanced Computer Software Group Ltd £3,076,320 in March 2025, reduced from a provisional £6.09 million through a voluntary settlement, framing the case as a warning about multi-factor authentication gaps in critical health supply chains.
Source: The Register: ICO fines NHS software supplier £3M for ransomware failings
Records affected: Not disclosed; JLR confirmed that "some data" was affected. Record count remains unconfirmed
Date of breach: August to September 2025
Date disclosed: September 2025, with data impact confirmed September 2025
Sector: Automotive manufacturing
Attack vector: Not formally confirmed; claims of responsibility were made by a group associated with the Scattered Spider and ShinyHunters ecosystems
Data exposed: JLR stated that some data had been affected and notified those concerned; the company has not published a breakdown
JLR shut down its global IT estate to contain the attack, halting vehicle production for roughly five weeks and cascading through a supplier base employing tens of thousands of people. The Cyber Monitoring Centre modelled the total UK economic impact at around £1.9 billion (a range of £1.6 billion to £2.1 billion), making it, on that assessment, the single most financially damaging cyber event in British history.
Aftermath: The UK Government provided a £1.5 billion loan guarantee to support JLR's supply chain, an unprecedented state intervention in response to a cyber incident. The ICO was notified, and the incident became a central exhibit in the case for the UK Cyber Security and Resilience Bill.
Source: Cyber Monitoring Centre: Statement on the Jaguar Land Rover cyber incident
Records affected: Reported as around 8,000 children's profiles
Date of breach: September 2025
Date disclosed: September 2025
Sector: Childcare / education
Attack vector: Not fully disclosed; an extortion group calling itself Radiant claimed the attack and published stolen data
Data exposed: Children's names, photographs, dates of birth, addresses, safeguarding notes, and parent and guardian contact details
Attackers stole records from a London nursery group and published photographs and personal details of individual children on a leak site, then directly contacted parents to pressure the company into paying. This was the most explicit case yet of extortionists weaponizing children's data for leverage.
Aftermath: The Metropolitan Police made arrests in connection with the incident, and the attackers later claimed to have deleted the data. The ICO opened an investigation and issued sector-wide guidance to nurseries and schools.
Source: Malwarebytes: Hackers threaten parents to get nursery to pay ransom
Records affected: 1,097 people
Date of breach: December 2019
Date disclosed: December 2019
Sector: Government
Attack vector: Human error in a new automated process; a file containing home addresses was published on GOV.UK in error and remained accessible for over two hours, receiving 3,872 views
Data exposed: Names and unredacted home addresses of New Year Honours recipients
The Cabinet Office published the honours list with a column of home addresses left in, exposing the residential addresses of more than a thousand recipients including senior police officers, counter-terrorism officials, and people who had received honours for work in sensitive fields. Some recipients reported abusive or threatening contact afterward.
Aftermath: The ICO fined the Cabinet Office £500,000 in December 2021, later reduced to £50,000 on appeal in 2022, which found the original penalty disproportionate. The case is now a leading UK authority on proportionality in public-sector data protection fines.
Source: ICO Newsroom: ICO and Cabinet Office reach agreement on New Year Honours data breach fine
Learning how to prevent data breaches starts with reading this list top to bottom, where a pattern emerges: the heaviest recent UK incidents were not front-door break-ins. Synnovis, Advanced, Capita, SSCL, and Marks and Spencer were all third-party or supply-chain events, where the compromised organization was a supplier, contractor, or outsourced IT function rather than the brand in the headline.
The failure modes repeat across two decades of cases:
Supply-chain exposure is the throughline, yet oversight has not caught up, and the practical work of preventing third-party breaches still lags behind the risk. Continuous, outside-in monitoring of your own and your vendors' attack surface is what turns that blind spot into something you can act on before it becomes the next entry on a list like this.
Managing this kind of exposure means seeing your own attack surface and your vendors' at the same time, continuously rather than at a point in time. The UpGuard platform brings both together:
UpGuard is ranked number one for third-party and supplier risk management on G2. To see how continuous monitoring surfaces exposures before attackers do, start a free trial.
By records affected, the UK Electoral Commission breach is the largest, exposing the personal data of roughly 40 million registered voters over an eight-year window.
The 2026 Companies House WebFiling exposure is among the most recent, potentially affecting about 5 million registered companies, while Jaguar Land Rover was the most economically damaging 2025 event at an assessed £1.9 billion.
The Legal Aid Agency and Synnovis breaches rank highest by data sensitivity; the Synnovis attack was linked to the first UK patient death publicly attributed to a cyber attack.
Yes. The ICO has issued significant penalties, including £20 million against British Airways, £18.4 million against Marriott, and a combined £14 million against Capita.