NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 9 of 32
Chapter 01: Countering the cyber threat

The cyber threat to the UK
State actors continue to present a significant threat to UK and global cyber security, aided by an evolving cyber intrusion sector. As threats intensified, our incident management team faced a record number of nationally significant incidents.
The NCSC works across government, and in partnership with international allies, industry and academic colleagues, to deter, degrade and detect the cyber threat posed by hostile nation states and cyber criminals. Through timely advisories and public attributions, we help organisations understand the nature of these threats, assess their exposure, and take informed action to strengthen their defences.
China
China continues to be a highly sophisticated and capable threat actor, targeting a wide range of sectors and institutions across the globe, including the UK. In September 2024, the NCSC and international allies exposed a covert network operated by a China-linked company called Integrity Technology Group also known as Flax Typhoon. The actor managed botnet (that is, a network of internet-connected devices that are infected with malware to conduct co-ordinated cyber attacks) consisting of over 260,000 compromised devices around the world.
Further, in August 2025, the NCSC co-sealed a cyber security advisory with international partners linking three China-based companies to a campaign targeting foreign governments and critical networks. The activities described in the advisory partially overlap with campaigns previously reported by the cyber security industry most commonly under the name Salt Typhoon.
Russia
Russia continues to act as a capable and irresponsible threat actor in cyberspace. Russia’s most disruptive threat activity continues to be focused on Ukraine, in support of their illegal military campaign. The NCSC continues to publicly expose Russian cyber activity (such as the Authentic Antics malware which steals victims’ login details and tokens to enable long-term access to email accounts) and give mitigation advice. This creates a more challenging environment for Russian actors to operate in.
Russia’s invasion of Ukraine and the ongoing Israel-Gaza conflict have also inspired a growing number of Pro-Russia hacktivist groups seeking to target the UK, Europe, US, and other NATO countries in retaliation for what they perceive as the west’s support for Ukraine and Israel. These threat actors have varying degrees of association with the state, and they choose their targets (including ones in CNI sectors) based on what is vulnerable, which makes their activities less predictable.
Iran
Throughout early 2025, Iran has highly likely concentrated its cyber operations in support of its military and wider geopolitical objectives in relation to the Middle Eastern crisis. In June 2025, US government agencies issued a fact sheet detailing the need for increased vigilance for potential cyber activity by Iranian state-sponsored or affiliated threat actors against US critical infrastructure and other US entities. The NCSC assesses this threat highly likely extends to UK entities. The implications and impact of the Iran-Israel conflict are still developing, but the NCSC continues to work closely with government, industry and international partners to understand and mitigate the cyber threat from Iran.
Democratic People’s Republic of Korea (DPRK)
The DPRK’s cyber activity mainly seeks to raise revenue, to collect intelligence and to offset the impact of international sanctions. DPRK threat actors indiscriminately target cryptocurrency companies and users globally, and attempt to steal data from defence industries, governments, and academia to improve their internal security and military capabilities.
UK firms are almost certainly being targeted by IT workers from the DPRK – disguised as freelance third-country IT staff – to generate revenue for the DPRK regime. It is also highly likely that UK-based cryptoasset firms are currently at risk of being targeted by DPRK-linked hackers seeking to steal or obtain funds through illicit means. The DPRK remains a prolific and capable threat actor, and the NCSC continues to work with partners to understand and address the risk to the UK.
Ransomware
Ransomware remains one of the most acute and pervasive cyber threats to UK organisations. This was highlighted by ransomware attacks on Marks & Spencer, the Co-op and others across the retail sector, with the sight of empty shelves a stark reminder of the potential operational and financial impact on victims. However, most cyber criminals are sector agnostic, selecting victims based on organisations they believe:
- are most likely to pay a ransom
- are vulnerable to operational downtime
- hold sensitive data that would cause significant harm to UK citizens if leaked
Of course, this makes any organisation a potential victim of ransomware attacks, as the NCSC’s CEO points out in this year’s foreword. And despite the disruption of the LockBit ransomware operation in 2024 – one of the most deployed ransomware strains globally – the threat from ransomware remains high. The cyber crime ecosystem is resilient, and the ransomware threat is diversifying in response to international efforts to counter its malign impact on society and the economy.
NCSC guide to ransomware
The NCSC’s ransomware resources include guidance on mitigating malware and ransomware attacks, and advice on how best to recover should the worst happen.
Artificial intelligence (AI)
Threat actors of all types continue to use AI to enhance their existing tactics, techniques and procedures (TTPs), rather than to create novel attacks. That is, they are using AI to increase the efficiency, effectiveness, and frequency of their cyber intrusions. Actors linked to China, Russia, Iran and the DPRK are using large language models (LLMs) to evade detection, support reconnaissance, process exfiltrated data, access systems through social engineering, and support vulnerability research and exploit development (VRED).
In the last 18 months, security researchers have identified new techniques that exploit AI, including fully automated spear-phishing campaigns, hijacking cloud-based LLMs, automating post-breach attack stages and data exfiltration. The most significant AI-cyber development in the near-term will highly likely come from AI-assisted VRED, enabling access to systems through the discovery and exploitation of flaws in the underlying code or configuration.
Keeping pace with AI-cyber developments will almost certainly be critical to cyber resilience for the decade to come, as we explained in our recent assessment on the Impact of AI on cyber threat from now to 2027. AI will almost certainly pose cyber resilience challenges to 2027 and beyond, across critical systems and economy and society. These will range from responding to an increased volume of attacks, managing an expanded attack surface and keeping pace with unpredictable advancements and proliferation of AI-cyber capability.
Cyber proliferation
The global commercial cyber intrusion sector will almost certainly expand over the next five years with state demand for intrusion products to meet national security requirements being a key driver. Permissive operating environments in less-regulated regimes will almost certainly result in a growing number of cases which violate state legislation and privacy laws of victims.
Diversification in the commercial cyber intrusion market means the capability on offer across the market will highly likely enable the exploitation of an increased range of computer systems, thus moving beyond common personal devices. As the cyber intrusion market evolves there is likely an increasing number of smaller entities – vulnerability researchers and exploit developers – operating in formal and informal collaborations with other specialist entities, rather than working in large providers. Government and whole-of-society efforts to influence players in the market and counter proliferation will almost certainly continue to be necessary.
The Pall Mall Process
The UK and France-led Pall Mall Process brings together international partners and stakeholders for an ongoing and globally inclusive dialogue to address the proliferation and irresponsible use of commercial cyber intrusion tools and services. It acknowledges the importance of public-private partnership and multi-stakeholder collaboration for a more secure cyberspace.
The Pall Mall Process hosted its second conference in Paris in April 2025 resulting in 26 states signing up to a Code of Practice which sets out a series of detailed recommendations for States as responsible regulators, customers and users of commercial cyber intrusion capabilities. The NCSC plays a leading role in supporting the FCDO, working in partnership with France, to advance the Pall Mall Process.
Threat to critical national infrastructure (CNI)
Cyber threat to the UK CNI remains high. Cyber remains a discreet, low-cost, high-impact vector through which threat actors target the UK’s CNI for espionage, ransomware and disruptive purposes. Ransomware conducted by financially motivated criminals continues to be the most immediate, disruptive threat to CNI sectors. The high-profile cyber attacks by the DragonForce ransomware group left customers unable to make payments, and saw the data of all 6.5 million Co-op members stolen. More broadly, we’ve detected a shift in hacktivist activity to include low-skilled attacks against operational technology (OT) systems.