Mirror Network Rail Faces Over 7 Million Cyber Attacks in Three Months
Article Content
- •Network Rail blocked over 7.1 million cyber attacks in three months.
- •The majority of attacks were malicious emails, including 37,000 phishing attempts.
- •Experts urge public sector organizations to enhance their cybersecurity strategies.
Network Rail experienced over 7.1 million cyber attacks, primarily through malicious emails, from December 2025 to March 2026. This alarming statistic was revealed through a Freedom of Information request. The surge in attacks follows the guilty pleas of two members of the hacking group Scattered Spider, who previously disrupted Transport for London’s IT systems, costing £39 million. Network Rail successfully blocked most of these attacks, including 37,000 phishing threats. Experts warn that critical infrastructure like Network Rail is increasingly vulnerable to cyber gangs. The potential for a successful attack could lead to significant disruptions in public transport, affecting daily commuters. Cybersecurity professionals emphasize the need for robust security measures to protect against these threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Co-op in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2026-93425: Dokploy PaaS Critical RCE Leads to Container Root and Host Compromise TheHackerWire / 1d Telemetry Metric Intelligence Detail CVE Identifier CVE-2026-93425 CVSS Severity 9.9 CRITICAL Affected Target the Dokploy container Vulnerability Class Security Vulnerability Exploit Availability No Public PoC Indexed EPSS Threat Score Awaiting scoring CISA KEV Status Not Listed in CISA KEV Remediation Status Advisory / Mitigation In Review A critical command injection vulnerability, CVE-2026
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…