Phishing was the most prevalent and disruptive type of attack experienced by UK organizations over the past twelve months, according to the British government’s Cyber Security Breaches Survey 2025.
85% of businesses and 86% of charities in the UK reported sustaining phishing attacks last year.
“The qualitative interviews highlighted that phishing attacks were often cited as time-consuming to address due to their volume and the need for investigation and staff training,” the report says.
“The qualitative interviews also found that organisations had a growing consciousness that increasingly sophisticated methods, such as AI impersonation, were becoming mainstream.”
The survey respondents cited a variety of reasons why phishing was the most disruptive type of attack, with a majority pointing to impersonation of staff.
“New for 2025, those that experienced more than one type of breach or attack and then selected phishing as the most disruptive type of attack were asked a follow up question about why phishing was the most disruptive,” the report says.
“The most common reason given was that they resulted in people impersonating the organisation or staff in emails or online (19% of businesses and 25% of charities). This was followed, to a lesser extent, by breaches or attacks being reported as disruptive because they led to being targeted with malware (9% for both businesses and charities) or ransomware (7% of businesses and 1% of charities), or resulted in hacking (9% for businesses and 2% for charities).”
Additionally, organizations feel overwhelmed by the number of phishing attempts that target them.
“Qualitative interviews found similar reasons for phishing causing so much disruption to businesses and charities,” the report says. “Organisations in the interviews felt that the sheer volume of phishing attacks received led to staff time in dealing with each of these, even if it was just investigating it and then doing nothing further. For some organisations it was a daily occurrence that could not be ignored.”
New-school security awareness training can give your organization an essential layer of defense against phishing and other social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
SC Magazine has the story.