UK data breach statistics 2026: seven years of reports to the ICO
Every personal data breach report in the Information Commissioner's Office's published data, 2019 to 2025: how many, what kind, which sectors, and how quickly organisations reported them.
Updated 19 September 2026 · ICO data security incident trends (data to Q4 2025), Open Government Licence · method and dataset below
What these figures are, and are not
- Reported breaches only. The ICO: the data "contains only the data security incidents that were discovered and then reported to the ICO". Undiscovered and unreported incidents are absent.
- Not a count of organisations or incidents. The unit is a report; there is no organisation identifier, so repeat reporters and many reports arising from one supplier incident cannot be distinguished.
- Not a rate. There are no denominators (organisations per sector, records held), so counts and shares cannot rank how safe a sector is.
- 2025-Q4 is a first release: 649 of its reports have no incident type yet, so type-level results that depend on it are marked provisional.
What the ICO's data shows
This study analyses 77,222 personal data breach reports made to the Information Commissioner's Office (ICO) from 2019 to 2025, using the ICO's published data. Reports reached 13,457 in 2025, 10.3% more than in 2024 and the highest yearly total in the series. The ICO coded 23.4% of 2025 reports as cyber incidents; the most common single type was personal data emailed to the wrong recipient (2,459 reports). Ransomware reports peaked at 1,253 in 2023 and fell to 617 in 2025, a fall that also holds without the incomplete 2025-Q4. 63.4% of 2025 reports were recorded as made within 72 hours of discovery. The figures count reports, not breaches, and the latest quarter (2025-Q4) is a first release with incomplete incident-type coding.
- The ICO received 13,457 personal data breach reports in 2025, 10.3% more than in 2024 (12,195) and the most of any calendar year from 2019 to 2025. Reports have risen every year since 2022, the lowest year in the series (8,798).
- Most reports are not cyber incidents. The ICO coded 23.4% of 2025 reports as cyber (3,153 of 13,457), down from 30.0% in 2023, the highest year for that share. The most common single incident type in 2025 was personal data emailed to the wrong recipient: 2,459 reports, 18.3% of the year's total and its highest yearly count in the series.
- Ransomware reports peaked at 1,253 in 2023 and fell to 752 in 2024 and 617 in 2025, when they were 4.6% of all reports. The fall does not rest on the incomplete 2025-Q4: over the first three quarters, reports fell from 603 in 2024 to 469 in 2025. In 2024-2025, 11.1% of ransomware reports with a known count were estimated at the time of reporting to affect 10,000 or more people, against 3.0% of all reports.
- Retail and manufacture made the most ransomware reports in 2025: 227 of 617 (36.8%). Ransomware was 15.2% of that sector's own 1,497 reports, and the sector also made the most ransomware reports in 2024-2025 and across 2019-2025. Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents.
- Among named incident types with at least 100 reports in 2021, the fastest rises to 2025 were data of the wrong data subject shown in a client portal (103 to 228, up 121.4%), failure to redact (412 to 886, up 115.0%) and hardware or software misconfiguration (208 to 422, up 102.9%). Rises in report counts can reflect more incidents, more reporting or changes in coding; this data cannot separate them.
- 63.4% of 2025 reports were recorded as made within 72 hours of discovery, and 19.0% after more than a week. Of ransomware reports with an outcome recorded, the share recorded as "Investigation Pursued" was 3.7% in 2025 (18 of 481), 3.6% in 2024 and 6.9% in 2023; the ICO notes that this outcome "may not necessarily lead to a full investigation". 22.0% of 2025 ransomware reports had no outcome recorded yet, so the 2025 share is provisional.
Overall trend
The ICO's data security incident trends file holds 77,222 breach reports from 2019-Q1 to 2025-Q4. Yearly totals ranged from 8,798 in 2022, the lowest year, to 13,457 in 2025, and have risen every year since 2022. The 2019 total (12,259) includes 2019-Q1, which the ICO says was recorded differently; 2019-Q2 to 2019-Q4 alone come to 8,887. The ICO says a substantial drop in 2020-Q2 was "likely a result of the first national UK coronavirus lockdown". The highest quarter was 2025-Q4, with 3,677 reports, but it is a first release and its coding is less complete than for earlier quarters. As a cross-check, the file gives 12,301 reports for April 2024 to March 2025, 99.1% of the 12,412 data breaches reported in the ICO's annual report for 2024/25; the two use different bases. These are counts of reports received, not of breaches that occurred, and they are not rates.
Scroll the chart sideways to see all of it →
Source: ICO data security incident trends (OGL v3.0). The 2020 Q2 dip coincides with the first national lockdown (ICO). 2025 Q4 is a first release and is drawn lighter; 2019 Q1 was recorded differently (ICO).
Cyber and non-cyber incidents, including human error
The ICO codes each report as cyber or non-cyber. In 2025 it coded 3,153 of 13,457 reports (23.4%) as cyber and 76.6% as non-cyber. The ICO-coded cyber share was 19.1% in 2019, peaked at 30.0% in 2023 and then fell back. The ICO coded unauthorised access as cyber in every 2019-Q1 and 2019-Q2 report (88.8% across 2019) but in a minority each year from 2020 (41.2% in 2020, falling to 3.8% in 2024; 5.6% in 2025), and the data cannot show whether this reflects a coding change or a change in the kind of unauthorised access reported. So this study also shows a constant-definition share: reports of the incident types the ICO always codes as cyber, as a share of reports with an incident type recorded. It was 13.9% in 2019, 29.3% in 2023 and 24.2% in 2025. Non-cyber reports include everyday handling errors. In 2025, data emailed to the wrong recipient (2,459 reports), failure to redact (886), failure to use bcc (434) and verbal disclosure of personal data (348) were each at their highest yearly count in the series, although the leads for failure to use bcc (18 reports) and verbal disclosure (9) are small while 2025-Q4 is provisional. The ICO says its cyber and non-cyber split is under review and should be read with caution. Reports with no incident type count as non-cyber in that split, including 649 in 2025-Q4.
Scroll the chart sideways to see all of it →
Source: ICO (OGL v3.0). The ICO says its cyber/non-cyber split is under review; a constant-definition series is in the dataset.
| Incident type (named types, by 2025 rank) | 2019 | 2020 | 2021 | 2022 | 2023 | 2024 | 2025 | Share of 2025 |
|---|---|---|---|---|---|---|---|---|
| Data emailed to incorrect recipient | 1,377 | 1,519 | 1,693 | 1,569 | 1,746 | 2,228 | 2,459 | 18.3% |
| Unauthorised access | 876 | 740 | 1,127 | 1,130 | 1,304 | 1,328 | 1,597 | 11.9% |
| Phishing | 1,103 | 1,035 | 1,045 | 716 | 924 | 1,380 | 1,526 | 11.3% |
| Failure to redact | 333 | 380 | 412 | 428 | 496 | 751 | 886 | 6.6% |
| Data posted or faxed to incorrect recipient | 1,717 | 998 | 831 | 760 | 688 | 738 | 735 | 5.5% |
| Ransomware | 158 | 447 | 723 | 739 | 1,253 | 752 | 617 | 4.6% |
| Loss/theft of paperwork or data left in insecure location | 1,052 | 614 | 610 | 572 | 612 | 584 | 588 | 4.4% |
| Failure to use bcc | 332 | 362 | 279 | 246 | 323 | 416 | 434 | 3.2% |
| Hardware/software misconfiguration | 45 | 81 | 208 | 231 | 284 | 478 | 422 | 3.1% |
| Verbal disclosure of personal data | 268 | 253 | 291 | 308 | 287 | 339 | 348 | 2.6% |
Scroll the table sideways to see every column →
Ransomware by year and sector
Ransomware reports rose from 158 in 2019 to a peak of 1,253 in 2023, then fell to 752 in 2024 and 617 in 2025, when they were 4.6% of all reports and 19.6% of ICO-coded cyber reports. The fall also shows on the first three quarters alone (603 in 2024, 469 in 2025), so it does not rest on the incomplete 2025-Q4. The peak quarter, 2023-Q2, had 511 ransomware reports, 201 of them from finance, insurance and credit; the data has no organisation identifier, so it cannot show whether several reports stem from one underlying incident. By sector, retail and manufacture made the most ransomware reports in 2025, in 2024-2025 and across 2019-2025. In 2025 it made 227 of the 617 reports, and ransomware was 15.2% of the sector's own reports, the highest share among sectors with at least 100 reports. Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents.
Scroll the chart sideways to see all of it →
Source: ICO (OGL v3.0).
| Sector | Reports, 2025 | Ransomware | Share of the sector's reports | Share of all ransomware |
|---|---|---|---|---|
| Retail and manufacture | 1,497 | 227 | 15.2% | 36.8% |
| Finance, insurance and credit | 1,069 | 76 | 7.1% | 12.3% |
| Education and childcare | 1,830 | 44 | 2.4% | 7.1% |
| Legal | 962 | 42 | 4.4% | 6.8% |
| Land or property services | 768 | 39 | 5.1% | 6.3% |
| Online Technology and Telecoms | 338 | 39 | 11.5% | 6.3% |
| Transport and leisure | 535 | 32 | 6.0% | 5.2% |
| Health | 2,471 | 22 | 0.9% | 3.6% |
| General business | 292 | 20 | 6.8% | 3.2% |
| Charitable and voluntary | 979 | 19 | 1.9% | 3.1% |
Scroll the table sideways to see every column →
Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents. Shares of a sector’s own reports are shown only where it made at least 100 reports.
Fastest-growing incident types
Among named incident types with at least 100 reports in 2021, the fastest rises to 2025 were data of the wrong data subject shown in a client portal (103 to 228, up 121.4%), failure to redact (412 to 886, up 115.0%), hardware or software misconfiguration (208 to 422, up 102.9%), failure to use bcc (279 to 434, up 55.6%) and phishing (1,045 to 1,526, up 46.0%). The catch-all "other cyber incident" type rose faster (297 to 770) but is not ranked. Misconfiguration reports were lower in 2025 (422) than in 2024 (478), and also on the first three quarters (358 in 2024, 329 in 2025). From 2024 to 2025 the largest rises among named types were in unauthorised access (up 20.3%) and failure to redact (up 18.0%). Rises in report counts can reflect more incidents, more reporting or changes in coding, and this data cannot separate them. Falls are less certain, because 649 reports in 2025-Q4 have no incident type yet. Later releases are expected mainly to add to 2025 type counts as the 649 uncoded reports are assigned, but in earlier releases some types' newest-quarter counts were also revised down. Ransomware fell 14.7% from 2021 to 2025 on full years and 12.2% on the first three quarters; loss or theft of devices containing personal data fell 8.3% on full years but went only from 124 to 123 on the first three quarters.
| Incident type | 2021 | 2025 | Change |
|---|---|---|---|
| Data of wrong data subject shown in client portal | 103 | 228 | +121.4% |
| Failure to redact | 412 | 886 | +115% |
| Hardware/software misconfiguration | 208 | 422 | +102.9% |
| Failure to use bcc | 279 | 434 | +55.6% |
| Phishing | 1,045 | 1,526 | +46% |
| Data emailed to incorrect recipient | 1,693 | 2,459 | +45.2% |
| Unauthorised access | 1,127 | 1,597 | +41.7% |
| Verbal disclosure of personal data | 291 | 348 | +19.6% |
Scroll the table sideways to see every column →
Named incident types with at least 100 reports in the base year; catch-all “other” types are excluded. 2025 counts include the first-release 2025 Q4, so they may be revised.
Reporting speed and ICO outcomes
For a notifiable breach, UK GDPR expects the ICO to be told within 72 hours of becoming aware of it, where feasible. 63.4% of 2025 reports were recorded as made within 72 hours of discovery and 19.0% after more than a week. When only a date is given, the ICO enters midnight as the discovery time, which can place some on-time reports outside the window. By type in 2024-2025, 70.1% of reports of data emailed to the wrong recipient were recorded as made within 72 hours, against 61.0% for ransomware and 52.2% for unauthorised access. On outcomes, of ransomware reports with an outcome recorded, the share recorded as "Investigation Pursued" was 54.5% in 2021, 6.9% in 2023 and 3.7% in 2025 (18 of 481). Across all 2025 reports with an outcome recorded, the share was 2.0% (207 of 10,552). The ICO says this outcome "may not necessarily lead to a full investigation", its outcome definitions changed in April 2021, and 21.6% of all 2025 reports and 22.0% of 2025 ransomware reports had no outcome assigned yet, so the 2025 shares are provisional.
| Year | Reports | Recorded within 72 hours | After more than a week | Outcome recorded: investigation pursued | No outcome yet |
|---|---|---|---|---|---|
| 2019 | 12,259 | 63.3% | 16.3% | 17% (2,080 of 12,259) | 0% |
| 2020 | 9,702 | 63.4% | 16.8% | 19.1% (1,857 of 9,702) | 0% |
| 2021 | 9,742 | 64% | 17.1% | 12.4% (1,209 of 9,742) | 0% |
| 2022 | 8,798 | 57.8% | 20% | 6.3% (555 of 8,798) | 0% |
| 2023 | 11,069 | 57.4% | 20.4% | 5.4% (594 of 10,936) | 1.2% |
| 2024 | 12,195 | 60.3% | 18.6% | 3.5% (402 of 11,473) | 5.9% |
| 2025 | 13,457 | 63.4% | 19% | 2% (207 of 10,552) | 21.6% |
Scroll the table sideways to see every column →
UK GDPR asks organisations to notify the ICO “within 72 hours of becoming aware of the breach, where feasible”. The ICO says an “investigation pursued” outcome “may not necessarily lead to a full investigation”.
What this means for organisations
These figures count reports to the regulator; they do not measure the risk to any one organisation. Read alongside official guidance, they point to a few areas worth reviewing. Backup and recovery: ransomware reports fell to 617 in 2025, but in 2024-2025 11.1% of ransomware reports with a known count were estimated at the time of reporting to affect 10,000 or more people, against 3.0% of all reports. It is worth considering recovery that does not depend on the attacked systems, such as offline or immutable backup copies, with restores tested against an agreed recovery time. Email and document handling: data emailed to the wrong recipient, failure to redact and failure to use bcc all reached their highest yearly counts in 2025, so checks at the point of sending (recipient confirmation, a send delay, bcc defaults and a redaction review) may be worth a look. Phishing: phishing reports (1,526) were also at their highest in 2025; multi-factor authentication and a clear internal route for reporting suspicious messages can limit what a captured password can reach. Access controls: unauthorised access reports (1,597) were at their highest in 2025 too, but the ICO coded 1,507 of them as non-cyber (the type also covers people unlawfully accessing or disclosing information), so role-based access, access logging and staff guidance may also be worth reviewing. Configuration: misconfiguration reports rose from 208 in 2021 to 422 in 2025, and permission reviews, change control and configuration baselines for file shares, storage and cloud services are the usual controls to review. For context, the separate Cyber security breaches survey 2025/2026 found two-factor authentication in place at 47% of businesses and a formal incident response plan at 25% of businesses. The NCSC and ICO guidance linked below gives more detail.
Guidance: ICO: personal data breaches a guide · ICO: ransomware and data protection compliance · NCSC: mitigating malware and ransomware attacks
How the dataset was built
How these figures were produced
- Source: the ICO's data security incident trends file (row level, one row per report, subject type and data type), data to Q4 2025. Rows were collapsed to 77,222 reports, one per case reference and quarter.
- Every earlier release still on the ICO website was archived and compared, so revisions between releases are measured; series breaks (the unauthorised-access coding, hardware/software misconfiguration coding, and 893 reports missing from six earlier releases) are handled explicitly.
- Cross-check: The quarterly file gives 12,301 reports for April 2024 to March 2025, 99.1% of the annual report's 12,412; the bases differ (for example, the trends data excludes cases moved to a separate system). The annual report's 17,431 for April 2025 to March 2026 includes January-March 2026, which the quarterly file does not yet cover; no quarterly figure for 2026 is derived from it.
- Checks: a second, independent parser re-read the source spreadsheet and recomputed every figure (about 2,080 values); the page wording was reviewed sentence by sentence, and the build fails if any number in the text is not found in the data.
- The ICO page lists the update as 11 March 2025; the file is dated 11 March 2026.
Contains information from the Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0. Derived tables: CC BY 4.0. Earlier analyses of this data: ICO dashboard (Power BI) and XLSX; Data Protection Network, "What data breach trends tell us" (April 2026); The Record (Recorded Future News), 3 October 2024; DAC Beachcroft, "Ransomware and the ICO: Examining enforcement trends", 4 October 2024; Mailock (formerly Beyond Encryption), analysis of 2023 ICO data. Downloads: CSV · README and attribution · JSON.
Questions
How many data breaches were reported to the ICO in 2025?
The ICO received 13,457 personal data breach reports in 2025, 10.3% more than in 2024 (12,195) and the most of any calendar year from 2019 to 2025. The busiest quarter was 2025-Q4, with 3,677 reports. These are reports of breaches that organisations discovered and reported to the ICO; they are not a count of all breaches.
What is the most common type of personal data breach reported to the ICO?
In 2025 the most common incident type was data emailed to the wrong recipient, with 2,459 reports (18.3% of the year's reports). Next came the catch-all "other non-cyber incident" (1,697), unauthorised access (1,597) and phishing (1,526). The ICO coded 76.6% of 2025 reports as non-cyber.
Is ransomware increasing in the UK?
Not in reports to the ICO. Ransomware reports peaked at 1,253 in 2023 and fell to 752 in 2024 and 617 in 2025; over the first three quarters they fell from 603 in 2024 to 469 in 2025. The separate Cyber security breaches survey 2025/2026 found ransomware attacks among businesses at 1%, down from 3% in both of the two previous years. The two sources measure different things and are not combined: the survey asks organisations about their own experience, while the ICO data covers only notifiable personal data breaches that were reported.
Which sectors report the most ransomware?
Retail and manufacture made the most ransomware reports in 2025 (227 of 617), followed by finance, insurance and credit (76) and education and childcare (44). Ransomware was 15.2% of retail and manufacture's own reports. Sectors differ in how readily they detect, assess and report breaches, and the ICO assigns sector as a best fit, so these figures do not show how safe a sector is.
How quickly do organisations report breaches to the ICO?
63.4% of 2025 reports were recorded as made within 72 hours of discovery, and 19.0% after more than a week. The share recorded within 72 hours was 63.3% in 2019 and 57.4% in 2023. When only a date is given, the ICO enters midnight as the discovery time, so some reports made on time may be labelled as late.
How often does the ICO investigate a reported breach?
Of 2025 reports with an outcome recorded, 2.0% (207 of 10,552) were recorded as "Investigation Pursued"; for ransomware reports the share was 3.7% (18 of 481). The ICO says this outcome means a case was passed to its investigations teams and "may not necessarily lead to a full investigation". 21.6% of all 2025 reports and 22.0% of 2025 ransomware reports had no outcome assigned yet, so both 2025 shares are provisional.
Does the data cover 2026?
No. The latest quarter in the ICO file is 2025-Q4. The ICO page lists the update as 11 March 2025; the file is dated 11 March 2026. The ICO's annual report gives 17,431 data breaches reported in 2025/26, a financial year that includes January to March 2026, but that total uses a different basis and no 2026 quarterly figure is derived from it.
Can I download and reuse the data?
Yes. The quarter by sector by incident type table is available as a CSV with 7,619 rows covering 77,222 reports, with a README that gives the attribution and caveats. The derived tables are licensed under CC BY 4.0; the underlying ICO data is under the Open Government Licence v3.0. Please credit: "Contains information from the Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0. Derived tables: CC BY 4.0."
Talk to a UK specialist
Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.