Theguardian 75% of Cyber Attacks on UK Infrastructure Linked to Hostile States, NCSC Reports
Article Content
- •75% of cyber incidents affecting UK CNI linked to hostile state actors.
- •AI advancements may escalate cyber threats by 2028, targeting legacy systems.
- •Urgent action needed from all organizations to strengthen cyber defenses.
The UK's National Cyber Security Centre (NCSC) reported that 75% of over 200 cyber incidents affecting critical national infrastructure (CNI) in the past year were linked to hostile state actors, including Russia, China, and Iran. Richard Horne, CEO of NCSC, emphasized that these attacks target essential services such as power plants, hospitals, and transportation systems. He described the cyber threat landscape as an ongoing contest, urging organizations to strengthen their defenses and improve resilience. Horne warned that vulnerabilities tolerated today could be exploited in future conflicts, particularly as artificial intelligence (AI) capabilities evolve. The NCSC anticipates that by 2028, AI-enabled attacks will exploit weaknesses in legacy systems. Horne called for immediate action from all sectors, stating that there are no spectators in this contest. The NCSC managed 200 incidents from June 2025 to May 2026, highlighting the urgency of addressing cybersecurity fundamentals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Following this threat?
Track Volt Typhoon and Jaguar Land Rover in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…