The ICO publishes report-level characteristics without organization names. Breach Gazette groups workbook rows by their source reference, excludes unresolved period conflicts, and retains only aggregate counts.
The figures cover reports received by the ICO, not every UK breach. Category totals can exceed unique reports because one report can hold multiple characteristics.
73,848unambiguous report references27comparable quarters23source sectors1 Apr 2019–31 Dec 2025observed window
Unique reports by quarter
Q1 2019 is omitted because the ICO identifies Q2 2019 as the comparable series start.
Quarter
Reports
Relative volume
2025 Q4
3,677
3,677 of 3,677
2025 Q3
3,464
3,464 of 3,677
2025 Q2
3,239
3,239 of 3,677
2025 Q1
3,076
3,076 of 3,677
2024 Q4
3,158
3,158 of 3,677
2024 Q3
3,002
3,002 of 3,677
2024 Q2
3,063
3,063 of 3,677
2024 Q1
2,971
2,971 of 3,677
2023 Q4
3,007
3,007 of 3,677
2023 Q3
2,711
2,711 of 3,677
2023 Q2
2,893
2,893 of 3,677
2023 Q1
2,458
2,458 of 3,677
2022 Q4
2,266
2,266 of 3,677
2022 Q3
2,318
2,318 of 3,677
2022 Q2
2,058
2,058 of 3,677
2022 Q1
2,156
2,156 of 3,677
2021 Q4
2,394
2,394 of 3,677
2021 Q3
2,409
2,409 of 3,677
2021 Q2
2,544
2,544 of 3,677
2021 Q1
2,395
2,395 of 3,677
2020 Q4
2,329
2,329 of 3,677
2020 Q3
2,580
2,580 of 3,677
2020 Q2
2,149
2,149 of 3,677
2020 Q1
2,644
2,644 of 3,677
2019 Q4
2,808
2,808 of 3,677
2019 Q3
3,002
3,002 of 3,677
2019 Q2
3,077
3,077 of 3,677
Source-labelled distributions
Membership counts preserve the ICO’s categories and do not imply mutually exclusive incidents.
Incident category
Source category
Reports
Non Cyber
55,676
Cyber
18,172
Incident type
Source category
Reports
Data emailed to incorrect recipient
12,188
Other non-cyber incident
12,143
Unauthorised access
7,722
Phishing
7,522
Data posted or faxed to incorrect recipient
5,924
Ransomware
4,645
Loss/theft of paperwork or data left in insecure location