Looking Back at Recent Cyber Incidents (Part 2/2)

Phishing, Exposed Data and Recovery Readiness

The first part of our Spring 2026 review looked at publicly reported cyber incidents between March and May, including warnings linked to international conflict, AI capability and destructive use of privileged access.

In Part 2, we will look at the incidents and findings linked to everyday systems, user behaviour and sensitive data exposure.

Review Your Cyber Security Posture

Education institutions reported high levels of cyber incidents

cyber-incidents-spring-2026-cicontinuity-UK-Wales-Business-Continuity (2)The UK education sector continued to report high levels of cyber breaches during the quarter. The Cyber Security Breaches Survey 2025/2026 education findings, published by the Department for Science, Innovation and Technology, found that 73% of secondary schools, 88% of further education colleges and 98% of higher education institutions had identified breaches or attacks in the previous 12 months.

Secondary schools recorded a significant rise, from 60% in 2024/2025 to 73% in 2025/2026. Phishing remained especially prevalent. Among institutions that had identified a breach or attack, phishing was reported by 90% of primary schools, 96% of secondary schools and 96% of further and higher education institutions combined.

The effects extended beyond attempted access. Almost half of further and higher education institutions that identified a breach or attack reported an outcome affecting their systems, including compromised accounts being used for illicit purposes, online services becoming unavailable or slower, and loss of access to files or networks.

Schools, colleges and universities depend on email, cloud collaboration platforms, student information systems, teaching resources and administrative records. When access to these services is interrupted, teaching, communications and day-to-day administration can all be affected. Independent backup for Microsoft 365 data, agreed recovery priorities and tested restoration procedures give education institutions a route to restore essential information while investigation and wider incident response continue.

Phishing remains the most persistent route into UK organisations

The Cyber Security Breaches Survey 2025/2026, published in April by the Department for Science, Innovation and Technology and the Home Office, reported that 43% of businesses and 28% of charities had identified a cyber security breach or attack in the previous 12 months.

This represented approximately 612,000 UK businesses and 57,000 charities.

Phishing remained the most commonly identified type of attack, experienced by 38% of businesses and 25% of charities. Among organisations that had identified a breach or attack, 69% of businesses and 69% of charities described phishing as the most disruptive type.

Despite improvements in technical controls and staff awareness, phishing continues to succeed because it targets everyday activity: opening attachments, responding to messages, using shared services and approving requests under time pressure.

The survey also reported that only a third of businesses had a business continuity plan covering cyber security. This leaves organisations exposed to situations where staff recognise that an incident has taken place but do not have a tested process for restoring services, recovering data or communicating with affected customers and stakeholders.

The South Staffordshire fine linked basic control failures to serious consequences

cyber-incidents-spring-2026-cicontinuity-UK-Wales-Business-Continuity (3)In May, the Information Commissioner’s Office fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 following a major cyber attack and data breach.

The attack began with a successful phishing email in September 2020. According to the ICO, an attachment enabled the attacker to install malicious software that remained undetected within the organisation’s systems for 20 months. The attacker later compromised domain administrator privileges, and more than 4.1 terabytes of data were published on the dark web.

The personal information of 633,887 customers and employees was compromised. The ICO identified weaknesses, including limited monitoring and logging, obsolete and unsupported software, inadequate vulnerability management and insufficient controls preventing privilege escalation. At the time of the breach, only 5% of the organisation’s IT estate was being monitored.

The incident shows how a phishing email can develop into a long-running compromise with serious financial, regulatory and reputational consequences. It also shows why recovery planning needs to include more than restoring data from backup.

Following a serious breach, organisations must determine which systems and data can be trusted, how far an attacker moved through the network, which accounts require securing or replacing, and how normal services can resume without reintroducing compromise.

Sensitive data can escape through everyday applications

Not every security incident reported this quarter began with a breach of a corporate system.

In March, Le Monde reported that the French aircraft carrier Charles de Gaulle could be located in near real time after a naval officer recorded a run publicly through a fitness application while aboard the vessel.

In May, Reuters reported that US military personnel were being targeted using commercially available location data, following warnings received by US Central Command about adversaries exploiting location information connected to deployed personnel.

These cases concern defence activity, but the broader risk affects organisations across sectors. Sensitive information may be generated through mobile applications, cloud platforms, connected devices, supplier services and employee activity outside formal business systems.

Organisations need to understand where operationally sensitive data is created and shared. Staff guidance, approved application policies, supplier reviews and information handling controls can all reduce exposure during periods of heightened cyber risk.

What Spring 2026 means for continuity planning

The cyber stories reported this quarter are varied, but the operational requirements are consistent.

Organisations need to understand which systems support essential services and which dependencies could prevent recovery. That includes identity services, Microsoft 365 data, cloud administration platforms, endpoint controls, supplier connections and operational records.

Backup copies should be protected from the accounts and systems most likely to be targeted during an attack. If privileged credentials are compromised, recovery must still be possible through isolated, controlled processes.

Incident plans also need to reflect real disruption. An organisation may need to process requests manually, maintain communications while email systems are affected, restore systems in a defined order, or demonstrate to regulators that monitoring, response and recovery controls were in place.

Testing provides the evidence. Restore testing, recovery exercises and clear responsibilities allow organisations to identify weaknesses before a real incident forces decisions under pressure.

Building recovery capability with CiContinuity

cyber-incidents-spring-2026-cicontinuity-UK-Wales-Business-Continuity (1)The incidents reported during Spring 2026 show how cyber attacks can interrupt services, expose sensitive data and leave organisations managing operational and regulatory consequences long after the initial compromise.

CiContinuity supports organisations with backup, disaster recovery and cyber security consultancy services that help improve recovery capability across critical systems and data. This includes resilient infrastructure supported by HPE technologies, Veeam-powered backup and recovery, Microsoft 365 backup that creates an independent recovery route for business-critical email and collaboration data, disaster recovery planning aligned with operational priorities, and protected backup options that help preserve clean restore points during an attack.

For organisations reviewing their current arrangements, the priority is establishing what must be recovered first, how quickly recovery needs to happen, and whether the process can still work when production systems or privileged accounts cannot be trusted.

Speak to CiContinuity about reviewing your backup, disaster recovery and cyber security arrangements.

Review Your Cyber Security Posture