Newsgather
BackUK Faces ‘Hacktivist Attacks at Scale’ Risk in Conflict, Warns Cyber Security Chief
UK Faces ‘Hacktivist Attacks at Scale’ Risk in Conflict, Warns Cyber Security Chief
Developing
Guardian UK4/22/2026Defense2 min readUnited Kingdom

UK Faces ‘Hacktivist Attacks at Scale’ Risk in Conflict, Warns Cyber Security Chief

NCSC chief Richard Horne warns nation states now account for most significant incidents, echoes MI6 chief’s ‘space between peace and war’ warning

Quick Look

  • The UK could face hacktivist attacks at scale if embroiled in conflict, with impact similar to recent ransomware incidents, NCSC chief Richard Horne will warn at CyberUK conference.
  • Nation states now account for the most significant cyber incidents, with ransomware attacks hitting Marks & Spencer, Jaguar Land Rover and Royal Mail.
  • Horne echoed MI6 chief’s warning that the UK is in ‘a space between peace and war’ as geopolitical tensions rise with Russia.

AI-generated summary

Why It Matters

The UK has experienced significant ransomware attacks in recent years affecting major companies including Marks & Spencer, Jaguar Land Rover and Royal Mail. The JLR attack notably impacted UK economic growth by disrupting car production. NCSC is part of GCHQ and is the UK’s lead agency for cybersecurity.

Font size

The UK could face “hacktivist attacks at scale” if it becomes embroiled in a conflict and the impact could be similar to recent high-profile ransomware incidents, according to the head of the country's online security agency. Richard Horne, chief executive of the National Cyber Security Centre (NCSC), will warn today that nation states now account for the most significant incidents the NCSC deals with. “Were we to be in, or near, a conflict situation, the UK would likely face hacktivist attacks at scale. With similar effects and sophistication to the ransomware attacks we see today. But … no option to pay a ransom to help recover,” the NCSC chief will say in a speech on Wednesday opening the annual CyberUK conference in Glasgow. Ransomware gangs – who demand a payment in exchange for unlocking IT systems they have encrypted – have hit a host of British targets in recent years including Marks & Spencer, Jaguar Land Rover (JRL) and Royal Mail. In the case of JLR, the as-yet-unattributed attack slowed growth in the UK economy by hitting car production. Every public and private sector organisation needs to focus on cybersecurity in the face of such a threat, said Horne, whose agency is part of GCHQ. “Defending against that means every organisation embedding cybersecurity into their corporate mission,” he said. “Ensuring they understand the full extent of risk they face, build defence in depth so that initial footholds by an attacker don't result in catastrophic impact.” Referring to a typical resolution of ransomware attacks, where organisations pay to unlock encrypted IT systems, Horne said the UK should prepare for a future where “paying their way out just isn't an option.” The NCSC chief echoed the warning last year from Blaise Metreweli, the chief of UK spy agency MI6, who said the country was caught in “a space between peace and war” as tensions mount with Russia. “Let's be clear, cyberspace is part of that contest,” said Horne. “We're in a perfect storm. With the two forces of rapid technological change and rising geopolitical tensions creating what feels like tumultuous uncertainty.” Referring to the development of Mythos, a new AI model that can discover hacker-friendly vulnerabilities in systems at speed, Horne said frontier AI – the term for cutting-edge versions of the technology – will expose organisations that are not repairing gaps in their cybersecurity or updating old systems. Horne said the country was not seeing significant new attacks due to advanced AI systems but it must head off the threat by embracing AI as a means of defending against attackers.

What to Watch

AI outlook — possibilities, not facts

  • UK government will increase cybersecurity requirements for critical infrastructure

    Likely · Within months

  • More ransomware attacks on UK targets before end of 2026

    Likely · Within months

Open Questions

  • What specific nation states are behind the most significant incidents?
  • What defensive measures is the UK government implementing?
  • How will AI be used defensively to counter these threats?

Related Topics

This article was originally published by Guardian UK.

Related Stories

WW2 bomb detonated after building site discovery in Plymouth
Defense·5/1/2026

WW2 bomb detonated after building site discovery in Plymouth

A 250kg German SC250 WWII bomb discovered at a building site in Southway, Plymouth was successfully detonated by military explosives officers. More than 1,200 homes were evacuated with a 400m exclusion zone put in place. The bomb could not be moved due to unclear fuse readings from X-ray examinations, requiring it to be blown in situ. The controlled detonation used about a third of the explosives, with the bomb burning at 1,000C for approximately 10 minutes. Residents were allowed to return home after safety inspections found no significant damage.

BBC UK News
More on this topiccybersecurity