United Kingdom

Anonymized national reporting

UK ICO data security incident trends

The ICO publishes report-level characteristics without organization names. Breach Gazette groups workbook rows by their source reference, excludes unresolved period conflicts, and retains only aggregate counts.

The figures cover reports received by the ICO, not every UK breach. Category totals can exceed unique reports because one report can hold multiple characteristics.

73,848unambiguous report references
27comparable quarters
23source sectors
1 Apr 2019–31 Dec 2025observed window

Unique reports by quarter

Q1 2019 is omitted because the ICO identifies Q2 2019 as the comparable series start.

QuarterReportsRelative volume
2025 Q43,6773,677 of 3,677
2025 Q33,4643,464 of 3,677
2025 Q23,2393,239 of 3,677
2025 Q13,0763,076 of 3,677
2024 Q43,1583,158 of 3,677
2024 Q33,0023,002 of 3,677
2024 Q23,0633,063 of 3,677
2024 Q12,9712,971 of 3,677
2023 Q43,0073,007 of 3,677
2023 Q32,7112,711 of 3,677
2023 Q22,8932,893 of 3,677
2023 Q12,4582,458 of 3,677
2022 Q42,2662,266 of 3,677
2022 Q32,3182,318 of 3,677
2022 Q22,0582,058 of 3,677
2022 Q12,1562,156 of 3,677
2021 Q42,3942,394 of 3,677
2021 Q32,4092,409 of 3,677
2021 Q22,5442,544 of 3,677
2021 Q12,3952,395 of 3,677
2020 Q42,3292,329 of 3,677
2020 Q32,5802,580 of 3,677
2020 Q22,1492,149 of 3,677
2020 Q12,6442,644 of 3,677
2019 Q42,8082,808 of 3,677
2019 Q33,0023,002 of 3,677
2019 Q23,0773,077 of 3,677

Source-labelled distributions

Membership counts preserve the ICO’s categories and do not imply mutually exclusive incidents.

Incident category

Source categoryReports
Non Cyber55,676
Cyber18,172

Incident type

Source categoryReports
Data emailed to incorrect recipient12,188
Other non-cyber incident12,143
Unauthorised access7,722
Phishing7,522
Data posted or faxed to incorrect recipient5,924
Ransomware4,645
Loss/theft of paperwork or data left in insecure location4,380
Failure to redact3,593
Other cyber incident3,189
Failure to use bcc2,303
Not Provided2,294
Verbal disclosure of personal data2,025
Hardware/software misconfiguration1,749
Loss/theft of device containing personal data1,400
Data of wrong data subject shown in client portal1,025
Malware813
Brute Force455
Incorrect disposal of paperwork270
Alteration of personal data115
Incorrect disposal of hardware42
Denial of service38
Cryptographic flaw13

Sector

Source categoryReports
Health13,781
Education and childcare10,285
Retail and manufacture7,133
Finance, insurance and credit6,853
Local government6,667
Legal5,324
Charitable and voluntary4,527
Land or property services3,486
General business3,151
Transport and leisure2,497
Social care2,034
Central Government1,880
Online Technology and Telecoms1,861
Justice1,269
Membership association1,039
Utilities720
Regulators290
Religious282
Marketing276
Media205
Political185
Unknown99
Unassigned4

Affected-population band

Source categoryReports
1 to 936,292
Unknown10,967
10 to 9910,580
100 to 1k9,560
1k to 10k4,511
10k to 100k1,345
100k and above593

Time taken to report

Source categoryReports
24 hours to 72 hours28,701
Less than 24 hours16,671
72 hours to 1 week14,883
More than 1 week13,593

Decision taken

Source categoryReports
Informal Action Taken40,472
No Further Action23,559
Investigation Pursued6,055
Not Yet Assigned3,760
Regulatory action taken2

Data-subject type

Source categoryReports
Customers or prospective customers23,260
Employees20,328
Unknown14,137
Patients10,126
Children9,425
Users6,808
Students5,830
Vulnerable adults5,442
Subscribers1,408

Data type

Source categoryReports
Basic personal identifiers59,944
Health data20,641
Economic and financial data12,582
Unknown9,492
Official documents6,352
Identification data6,122
Location data5,651
Data revealing racial or ethnic origin4,665
Criminal convictions or offences3,564
Religious or philosophical beliefs1,696
Sexual orientation data1,557
Sex life data1,075
Trade union membership688
Genetic or biometric data629
Gender Reassignment Data466
Political opinions393