What the ICO actually records
Those two facts sit oddly together, and both matter. Most reported breaches are small and accidental — a misdirected email, an unredacted document. But the handful that are deliberate intrusions are the ones that put millions of records into circulation at once, and those records are what turn a generic scam call into one that knows your name, your address and who you bank with.
Three cases that defined the period
Health, genetics, passwords: the sectors that keep paying later
A breach is rarely finished when it is disclosed. Several of the largest UK penalties of the period landed years after the intrusion itself, on organisations most people had never heard of — processors and suppliers rather than the household names whose customers were affected.
🏥Advanced Computer Software — the NHS supplier
On 27 March 2025 the ICO fined Advanced Computer Software Group £3.07 million for security failings that put the personal information of 79,404 people at risk, following a ransomware attack in August 2022 that disrupted NHS 111 and left healthcare staff unable to access patient records. It was the first time the ICO fined a data processor rather than a data controller — and the penalty was almost halved from the £6.09m originally proposed.
ICO, enforcement notice and press release, 27 March 2025.🧬23andMe and LastPass — data that cannot be reissued
Two further 2025 penalties for UK GDPR security failings involved categories of data that are effectively permanent: £2.31 million against the genealogy company 23andMe, and £1.23 million against LastPass UK. A password can be changed and a card reissued. A genetic profile cannot, which is precisely why that kind of record holds its value to a fraudster long after the incident has faded from the news.
ICO enforcement actions, 2025.🔍Lloyds — when it turns out not to be a breach at all
Not every alarming report is an intrusion. In one widely circulated case, Lloyds customers saw other people's details on screen — the hallmark of a breach — but the cause was a software defect, not an attacker. We keep the case on file precisely because the correction matters as much as the alert: reporting a bug as a hack inflates the record and makes the genuine incidents harder to take seriously. See the full write-up.
Egidio dossier, 2026.Method note: where an attacker claims a victim count and the organisation has not confirmed it, we treat the claim as a ceiling to investigate rather than a fact to repeat. The figures above are drawn from regulator findings, enforcement notices and company confirmations — not from the numbers attackers publish about themselves.
The vocabulary to know
Have I Been Pwned
A free service built by security researcher Troy Hunt: enter your email to check whether it appears in a known data breach.
Credential stuffing
An attacker takes credentials stolen in one breach and tries them en masse on other sites, betting that you reused the same password elsewhere.
Password spraying
The reverse of classic brute-forcing: an attacker tries one very common password across a large number of different accounts, to stay under detection thresholds.
MFA fatigue
An attacker who already has your password triggers a flood of push notification approval requests, hoping you'll eventually tap "approve" out of annoyance or mistake.
SIM swap, another technique that depends directly on leaked personal data, is detailed in the glossary.
Other markets we cover
The ICO publishes the UK's incident data. Other national regulators run their own tallies, and they point the same direction.
🇺🇸United States — a record 3,322 compromises
The Identity Theft Resource Center tracked 3,322 data compromises in 2025, an all-time record and a 79% rise over five years, with 278.8 million victim notices issued. See our US data breaches report.
ITRC, 2025 Annual Data Breach Report.🇦🇺Australia — a record 1,205 notifications
Australia's privacy regulator received 1,205 breach notifications in 2025, the highest since mandatory reporting began in 2018, with health providers the most affected sector. See our Australian data breaches report.
OAIC, Notifiable Data Breaches statistics, 2025.Go further
Frequently asked questions
How can I check if my data has been exposed?
Have I Been Pwned (haveibeenpwned.com) is a free service, built by security researcher Troy Hunt, that lets you check whether your email address appears in a known data breach.
How many data breaches are reported in the UK?
The Information Commissioner's Office received 3,600 data security incident reports in the fourth quarter of 2025 alone, a 16% increase year on year. Most were not hacks: 77% were non-cyber incidents, most commonly personal data emailed to the wrong recipient. Just over half of all breaches reported in 2025 affected only 1 to 9 individuals.
Why does a data breach lead to fraudulent calls and texts?
Because a breach often contains a name, phone number and sometimes details about your bank, employer or pension provider — enough to build a call or text that sounds credible and personal, far more effective than a generic message sent at random.
Was the Co-op breach really every member?
Yes. Co-op confirmed that the personal data of all 6.5 million of its members was taken in the April 2025 attack, including names, dates of birth, email addresses, phone numbers and home addresses. No financial or transactional data was taken, and the chief executive publicly apologised.
Egidio — The Threat Laboratory, "UK Data Breaches: the raw material behind personalised scams", egidio.app/en-gb/laboratoire/uk-data-breaches/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.