ransomware
323 UK Firms Hit by Ransomware, Mostly Small Businesses
2026-06-30

The City of London Police's Report Fraud line logged 323 UK businesses hit by ransomware between April 2025 and March 2026. That works out to about 26 successful attacks every month, and more than half of those victims were small or mid-sized firms.
The average financial hit climbed 50% year on year to roughly £270,000. Police are upfront that the real figure is almost certainly higher. Plenty of businesses either underreport what happened or never pick up the phone at all.
Who got hit
Manufacturing took the worst of it with 42 reported cases. Scientific and technical firms came in second on 21, and education followed on 19. The sector spread tracks with what attackers tend to look for: operational pressure, time-sensitive output, and the kind of supply chain leverage that makes a quick payment look tempting.
It all sits against a brutal year for British business more broadly. Marks & Spencer, the Co-op and Jaguar Land Rover all suffered major incidents. The JLR attack is now being attributed to Russian actors who may have been more interested in causing damage than collecting a payout. The combined economic cost ran into the billions.
Paying is not the shortcut it looks like
Talion's Kevin Knight made a point worth holding onto for anyone weighing the cheque. Decryption keys frequently don't work properly. Data that does come back often arrives in a state that still needs rebuilding. And paying the ransom does not put you back where you started, it just adds a line item to an already expensive recovery.
On the policy side, the UK is still considering mandatory reporting and a payment ban for public sector bodies and critical infrastructure. Neither has landed.
The pattern in the numbers
The detail worth sitting with is who is bearing the brunt. Small firms dominate the victim list, and they're the businesses least likely to have a dedicated security team, a tested backup regime, or the budget to throw at incident response after the fact.
The defences that consistently move the needle for these organisations are not glamorous:
- Backups that are tested, offline, and actually restorable.
- Access controls that limit who can reach what, so one compromised account doesn't open every door.
- Patching on a schedule, not when someone gets around to it.
- Staff who can recognise a dodgy email before they click it.
None of that is new advice. It keeps appearing in the post-incident write-ups because it keeps being the thing that was missing. 323 reported cases in a year, and the next year's number will almost certainly be higher, because the businesses making up the bulk of the victim list are still the ones with the thinnest defences.