UK Organizations Cite Phishing as the Most Disruptive Type of Cyberattack



Catphishing CasePhishing was the most prevalent and disruptive type of attack experienced by UK organizations over the past twelve months, according to the British government’s Cyber Security Breaches Survey 2025.

85% of businesses and 86% of charities in the UK reported sustaining phishing attacks last year.

“The qualitative interviews highlighted that phishing attacks were often cited as time-consuming to address due to their volume and the need for investigation and staff training,” the report says.

“The qualitative interviews also found that organisations had a growing consciousness that increasingly sophisticated methods, such as AI impersonation, were becoming mainstream.”

The survey respondents cited a variety of reasons why phishing was the most disruptive type of attack, with a majority pointing to impersonation of staff.

“New for 2025, those that experienced more than one type of breach or attack and then selected phishing as the most disruptive type of attack were asked a follow up question about why phishing was the most disruptive,” the report says.

“The most common reason given was that they resulted in people impersonating the organisation or staff in emails or online (19% of businesses and 25% of charities). This was followed, to a lesser extent, by breaches or attacks being reported as disruptive because they led to being targeted with malware (9% for both businesses and charities) or ransomware (7% of businesses and 1% of charities), or resulted in hacking (9% for businesses and 2% for charities).”

Additionally, organizations feel overwhelmed by the number of phishing attempts that target them.

“Qualitative interviews found similar reasons for phishing causing so much disruption to businesses and charities,” the report says. “Organisations in the interviews felt that the sheer volume of phishing attacks received led to staff time in dealing with each of these, even if it was just investigating it and then doing nothing further. For some organisations it was a daily occurrence that could not be ignored.”

New-school security awareness training can give your organization an essential layer of defense against phishing and other social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

SC Magazine has the story.


Will your users respond to phishing emails?

KnowBe4's Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!

PRT-imageHere's how it works:

  • Immediately start your test with your choice of three phishing email reply scenarios
  • Spoof a Sender’s name and email address your users know and trust
  • Phishes for user replies and returns the results to you within minutes
  • Get a PDF emailed to you within 24 hours with the percentage of users that replied

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-reply-test



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews