UK data breach trends 2026: quarter x sector x incident type table File: uk-data-breach-trends-2026.csv ATTRIBUTION Contains information from the Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0. Derived tables: CC BY 4.0. Source: Information Commissioner's Office (ICO), Data security incident trends. Source page: https://ico.org.uk/action-weve-taken/complaints-and-concerns-data-sets/data-security-incident-trends/ Source file: https://ico.org.uk/media2/ng3pl21l/data-security-incidents-trends-q1-2019-to-q4-2025.xlsx Source file sha256: 4179efdaa3ea4edbe41caef1ad3174f6d2a1454221138c588df5c2d8baaa7fa1 Open Government Licence v3.0: https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/ Derived tables licence (CC BY 4.0): https://creativecommons.org/licenses/by/4.0/ The ICO's statement: "All text content on this website is available under the Open Government Licence (OGL) v3.0, except where otherwise stated." The ICO data files carry no licence statement of their own and the dataset page states no exception; attribution follows the ICO's OGL wording. WHAT EACH ROW IS One row per quarter x sector x incident type x incident category, with the number of breach reports the ICO received. Rows: 7,619. Reports in total: 77,222. Quarters: 2019-Q1 to 2025-Q4. Unit: One personal data breach report received by the ICO (a case), not one breach and not one organisation. Rows with a zero count are not listed. COLUMNS quarter calendar quarter the report was received (YYYY-Qn) year calendar year quarter_number 1 to 4 sector sector as allocated by the ICO ("assigned as a best fit") incident_type incident type as recorded by the ICO (one per report: the most significant) incident_category the ICO's own coding: cyber or non-cyber reports number of breach reports source_file the ICO file the row is counted from source_url where that file was downloaded CAVEATS - Reported breaches only. The ICO: the data "contains only the data security incidents that were discovered and then reported to the ICO". Undiscovered and unreported incidents are absent. - Only notifiable personal-data breaches. ICO guidance: "If a risk is likely, you must notify the ICO; if a risk is unlikely, you don't have to report it." Incidents with no personal data, or judged unlikely to pose a risk, are not in it. - Not every report. ICO: "some cases are transferred to a separate system for review. As a result, these cases, which may include some of the larger and more serious breaches, are not included within this data." - Not a count of organisations or incidents. The unit is a report; there is no organisation identifier, so repeat reporters and many reports arising from one supplier incident cannot be distinguished. - Sector and incident type are assigned by the ICO as a best fit, one type per report (the most significant), not chosen by the reporting organisation. - A point-in-time record: ICO: "Data presented is generally based on the information provided when an organisation initially reports a breach." People affected are the reporter's initial estimate, in bands. - Not a rate. There are no denominators (organisations per sector, records held), so counts and shares cannot rank how safe a sector is. - Not the ICO annual report figure. The annual report counts "data breaches reported" per financial year on a basis the page does not define; the two are compared only as a cross-check. - No 2026 data: the latest published quarter is 2025-Q4. - 2025-Q4 is a first release: 649 of its reports have incident type "Not Provided". Later releases are expected mainly to add to 2025 type counts as the 649 uncoded reports are assigned, but in earlier releases some types' newest-quarter counts were also revised down. Type counts for 2025 are therefore provisional. - The ICO coded Unauthorised access as Cyber in every 2019-Q1 and 2019-Q2 report (88.8% across 2019) but in a minority each year from 2020 (41.2% in 2020, falling to 3.8% in 2024; 5.6% in 2025). The data cannot show whether this reflects a coding change or a change in the kind of unauthorised access reported. The ICO says its cyber/non-cyber split is under review. - Hardware/software misconfiguration is coded Non Cyber in every row-level release; the ICO's FY2021/22 aggregate tables listed it under cyber. - Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents. Built by Servnet from the ICO file above with scripts/research/ico-breach/build.py. The CSV has no personal data and no organisation names.