Looking Back at Recent Cyber Incidents (Part 1/2)

Heightened Threats, AI Capability and Destructive Access

From March to May 2026, the publicly reported cyber incidents showed how quickly security weaknesses can become operational problems.

Government warnings linked cyber risk to international conflict and covert networks. AI evaluations showed advanced models completing more complex offensive cyber tasks. Other incidents demonstrated how trusted platforms, privileged accounts and administrative tools can be used destructively once access is compromised.

In this first part, we will look more closely at the Spring 2026 cyber stories shaped by geopolitical risk, AI capability and the misuse of trusted access.

Review Your Cyber Security Posture

International conflict continues to create cyber risk for UK organisations

cyber-incidents-cicontinuity-security-UK-WalesIn March, the National Cyber Security Centre advised UK organisations to review their cyber security posture following events in the Middle East.

The NCSC stated that there was no significant change at that point in the direct cyber threat from Iran to the UK, but warned of heightened indirect risk for organisations with operations or supply chains in the region.

The advice specifically highlighted the risk of collateral damage from Iran-linked hacktivists, including denial-of-service attacks, phishing, and attacks on operational technology. For organisations delivering public services, supporting regulated sectors or relying on international suppliers, an incident that begins elsewhere can still affect access to systems, service availability or supplier performance in the UK.

In April, the NCSC and international partners also published guidance on covert networks associated with China-linked cyber activity. These networks can use compromised internet-connected devices, such as routers and other edge equipment, to disguise malicious activity, steal sensitive information and maintain access to targeted organisations.

Taken together, these warnings show why cyber continuity planning cannot be limited to malware or ransomware scenarios. Disruption can come from attacks intended to interrupt public services, compromised supplier connections, abused edge devices or activity that is difficult to attribute quickly.

Organisations need to know which services are most exposed, which suppliers are operationally critical and how essential activities would continue during a prolonged disruption.

AI cyber capability is progressing faster than many organisations can respond

Artificial intelligence featured heavily in cyber reporting throughout the quarter, particularly after the UK AI Security Institute published its evaluation of Anthropic’s Claude Mythos Preview model.

In its assessment of Claude Mythos Preview’s cyber capabilities, the Institute reported that the model became the first it had evaluated to complete a 32-step simulated corporate network attack from beginning to end. The model succeeded in three of ten attempts and completed expert-level cyber tasks at a considerably higher rate than earlier models.

This was controlled testing on simulated networks. It does not show an AI system independently attacking a defended business in real conditions. Even so, the results indicate that AI tools are becoming more capable of identifying weaknesses, chaining technical actions together and carrying out tasks that previously required significant specialist expertise.

Following the evaluation, the Department for Science, Innovation and Technology and the Cabinet Office issued an open letter to UK business leaders on AI cyber threats. The letter warned that newer AI models are becoming more capable of finding software weaknesses and writing code to exploit them at increasing speed and scale.

However, the risk is broader than offensive testing tools. A ZDNET report on enterprise AI agents and insider threat risk highlighted the implications of agents that can launch other agents, spend money and modify systems. As organisations give AI tools access to internal applications and business processes, permissions, monitoring and recovery controls require careful review.

On the other hand, making social engineering more convincing and harder to detect. A United Nations report on deepfakes, voice cloning and weaponised AI described how organised fraud operations across Southeast Asia are using impersonation and advanced cyber tools to defraud victims of billions of dollars.

Similar techniques could easily be used against organisations to persuade staff to disclose credentials, approve urgent access requests or bypass established controls.

The Stryker incident showed how trusted systems can be used destructively

cyber-incidents-cicontinuity-security-UK-Wales_2In March, medical technology company Stryker experienced a cyber attack that disrupted its internal Microsoft systems and affected business operations.

Bleeping Computer reported that tens of thousands of employee devices were remotely wiped after an attacker compromised an administrator account and created a new Global Administrator account. Stryker stated that its medical products remained safe to use, but electronic ordering systems were offline during the disruption, and customers were asked to place orders manually through sales representatives.

The incident was reported as a non-ransomware attack in which no malware was deployed on Stryker’s systems. Instead, the attacker used legitimate administrative capabilities after obtaining privileged access.

This is a significant continuity lesson. Organisations depend on Microsoft services, identity platforms, endpoint management tools and administrative accounts for routine operations. When those controls are misused, disruption can reach devices, communications, ordering processes and service delivery without a conventional ransomware infection.

Recovery arrangements should account for incidents where administrative accounts or cloud management platforms cannot immediately be trusted. Teams need a controlled method for restoring services, recovering clean data and maintaining essential activity while the affected systems are investigated and secured.

Deleted government databases demonstrated the need for recoverable data

The destructive misuse of privileged access was also illustrated by an incident involving two dismissed IT contractors in the United States. Ars Technica reported that the contractors deleted 96 US government databases after being fired, with their actions recorded because a Microsoft Teams meeting had remained active.

The incident demonstrates how quickly a failure to remove privileged access can affect data availability and public-sector operations. Databases supporting public services, financial processes or regulated records require protected backup copies, appropriate retention periods and restoration procedures that have already been tested.

It also highlights the importance of access controls during staff departures, supplier changes and contract terminations. When administrator privileges remain active after access is no longer required, critical records can be altered or deleted within minutes.

Recovery capability is therefore closely connected to identity and access management: organisations need to be able to restore affected data quickly, accurately and through a process that does not depend on compromised access routes.

What these incidents tell us about continuity planning

The first set of Spring 2026 cyber incidents shows that disruption can originate in many ways, including geopolitical activity, AI-assisted attack methods, compromised administrator accounts and privileged access that should have been removed.

This shows why continuity planning should concentrate on service impact rather than the initial cause of an incident. Plans need to identify what would stop first, which platforms and accounts could still be trusted, which data would need restoring first and which manual processes would keep activity moving while technical recovery is underway.

Part 2 will look at the patterns emerging within UK organisations, including phishing, breaches in the education sector, regulatory action, and sensitive data exposure through everyday applications.

In the meantime, if you would like to review your cyber security posture, backup arrangements or disaster recovery plans, CiContinuity can help assess your current position and identify where recovery processes may need strengthening.

Through our work with HPE and Veeam, we help customers strengthen resilience across infrastructure, backup and recovery, with solutions shaped around the systems, data and services they need to keep running.

Review Your Cyber Security Posture