News Hub

UK Science Funding HQ Hit by 5.4m Cyber Assaults as Attacks Increase 600%

Written by Wed 21 May 2025

People walking in the background. Overlayed are six images of padlocks, they are connected by a network.

UK Research and Innovation (UKRI) has reported a dramatic surge in cyber attacks this year, repelling more than 5.4 million attempts in the first four months of 2025 alone — a 600% increase compared to the whole of 2024.

The data, disclosed to The Express via a Freedom of Information request, highlighted escalating cyber threats targeting UK national research infrastructure, with phishing, malware and malicious email attacks posing daily risks to sensitive scientific and innovation data.

The FOI-disclosed figures show that of the 5,431,069 attacks logged in early 2025, 236,357 were phishing attempts, seeking to extract sensitive information from staff through deceptive communications. A further 11,226 were identified as malware-based attacks, involving malicious code intended to compromise systems or steal data. The remaining incidents were categorised as spam or malicious email campaigns.

“Growing volumes of increasingly sophisticated cyber attacks on critical national infrastructure and research centres underline the need for a comprehensive security strategy within the workforce,” said Sheila Flavell CBE, Chief Operating Officer of FDM Group.

“Cyber skills and threat awareness are no longer the preserve of the IT team; they should be built into the DNA of each and every employee.”

UK Cyber Protection Culture Must Extend Beyond IT Teams

This sharp increase has sparked calls from industry leaders to embed cyber awareness into organisational culture, particularly in sectors responsible for critical national services.

“These extensive incidents underline the severity of the threat facing public and private sector organisations on a daily basis,” said Rick Boyce, Chief for Technology at AND Digital.

“Burying your head in the sand is no longer an option – creating a security culture must be a priority in every board room, and cyber security awareness needs to be embedded in every function”

AI and Shadow IT Expanding the Attack Surface

Much of the growing risk stems from rapid shifts in digital behaviour and emerging technologies, such as generative AI. Employees working with unsecured tools or third-party platforms — often outside of sanctioned IT environments — can unintentionally expand the attack surface.

“With so many workers now casually using third-party AI tools and social platforms to collaborate and share confidential data, the risks of a cyber breach are now increasing dramatically,” warned Arkadiy Ukolov, co-founder and CEO of Ulla Technology.

“Tackling this problem requires a cyber-first approach, with staff fully trained on the risks of AI, as well as working from an enclosed, properly protected, secure IT system.”

The dramatic rise in threats to UKRI underscores a broader vulnerability across public sector organisations managing research, innovation, and sensitive citizen data. As the pace of digital transformation accelerates, so too does the imperative to build cyber-resilient systems supported by continuous education and a whole-organisation approach to security.

Join Cloud & Cyber Security Expo Frankfurt

4-5 June 2025, Messe Frankfurt

Cloud & Cyber Security Expo Frankfurt is one of the largest IT security events in Europe.

Don’t miss the chance to build partnerships and discover solutions to protect your business.

Written by Wed 21 May 2025

Send us a correction Send us a news tip


Subscribe for News in Your Inbox