NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 9 of 33
Cyber crime
The UK is exposed to a wide variety of cyber crime threats – from those that have the potential to be national security threats, such as ransomware, to commodity cyber crime campaigns (attacks that use readily available tools that require little or no customisation) which seek to defraud the UK public and businesses.
Low sophistication cyber crime
The cyber security threat that most of the British public are likely to experience is low sophistication cyber crime. Cyber criminals deploy commodity attacks, such as phishing or malware with the aim of scamming the public and businesses.
Phishing emails continue to be a successful attack vector for criminals. In many cases, these attacks are designed to mimic those online services that people use and often trust. In the last year, COVID-19 and the Russian invasion of Ukraine were prominent themes that criminals used to lure the public.
More recently, cyber criminals used the energy regulator Ofgem as a lure for over 50 phishing campaigns used to harvest financial credentials in response to rising energy costs. To mitigate this specific threat Ofgem wrote to all energy supplier CEOs asking they have clear, up-to-date and accessible information on their websites advising customers what to do in case of a scam.
Hacking of social media and email accounts, to financially extort victims for access to their accounts, or to compromise data to commit or enable fraud offences, has also grown over the past year. In 2021/22, there were a total of 8,023 reports of social media hacking, an increase of 23.5% on the previous year.
Ransomware
Ransomware is one of the most significant cyber security threats facing businesses and organisations in the UK. When ransomware is successfully deployed, it has the potential to prevent public services and businesses operating and put their data at significant risk.

What is ransomware?
- Ransomware is a type of malware which prevents users from accessing their device or network and the data stored on them, usually by encrypting files.
- A criminal group will then demand a ransom in exchange for decryption.
- The computer itself may become locked, or the data on it might be encrypted, stolen or deleted.
- The attackers may also threaten to leak the data they steal.
How does ransomware work?
- Access: Attackers gain access to victim’s network. They establish control and plant malicious encryption software. They may also take copies of data and threaten to leak it.
- Activation: The malware is activated, locking devices and causing the data across the network to be encrypted, meaning it can no longer be accessed.
- Ransom demand: Usually victims will then receive an on-screen notification from the cyber criminal, explaining the ransom and how to make the payment to unlock the computer or regain access to data. Payment is usually demanded via an anonymous web page and usually in a cryptocurrency, such as Bitcoin.
For this reason, it is important to always have a recent offline backup of the most important files and data. Visit our ransomware hub for more advice and tools.
During the last year, the NCSC co-ordinated the national response to 18 ransomware attacks including the attacks on a supplier to NHS 111, and South Staffordshire Water. But the true numbers of ransomware attacks in the UK each year are far higher, as organisations often do not report the compromises.
Last year, the NCSC joined forces with the FBI, CISA, the National Security Agency (NSA) and the ACSC to highlight that there had been an increase in sophisticated, high-impact ransomware incidents against critical infrastructure organisations globally. Given its potential impact on critical national infrastructure and essential services, ransomware is considered a national security risk.
Ransomware is an illicit commercial enterprise: a threat that continues to evolve as the criminals behind it pursue the best ways to make money. In earlier years, the threat from ransomware was principally that criminals were able to block organisations accessing their systems through encryption. Increasingly the NCSC is seeing data extortion as a fundamental part of the ransomware business model, as criminals realise that many organisations are willing to pay to avoid their data being leaked.

Law enforcement does not encourage, endorse nor condone the payment of ransom demands. If you do pay the ransom:
- there is no guarantee that victims will get access to their data or computer;
- computer or networks will still be infected;
This year, Lindy Cameron, CEO of the NCSC, wrote jointly with the Information Commissioner, John Edwards, to the Law Society and Bar Council. The letter made clear NCSC advice that payment of a ransom incentivises harmful behaviour by malicious actors and does not guarantee decryption of networks or return of stolen data, and the ICO position that payment of a ransom will not reduce any penalties incurred through their enforcement action.
The NCSC continued to see increased use of Ransomware as a Service (RaaS) where ransomware variants are leased to less-skilled affiliates who can launch cyber attacks without building the ransomware themselves. This opens the ransomware attack vector to a wider range of criminal actors where previously it was restricted to those with the requisite technical expertise.
In May 2022, it was reported that the Conti ransomware strain was discontinued. However, by August of that year it had not led to a reduction in the threat of ransomware to the UK as some members of the organised crime group behind it moved to other ransomware groups, meaning the NCSC is expecting to see a more diverse and capable ransomware landscape.
Most of the ransomware criminal groups that target the UK continue to be based in and around Russia. While it is not clear the degree to which these ransomware groups are directed by the Kremlin, those operating from within Russia’s borders benefit from the tacit consent of the Russian State.