Desk live·
ForensicPost
Breaches/Verification/File 25-0615b

Half of Businesses, a Third of Charities

A UK national survey found 50% of businesses and 32% of charities experienced a breach or attack in 2025, with phishing reported by more than four in five of each.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUK businesses and charities
ActorMultiple
D. Kennedy11 min readConfidence: high2 sources reviewed

UK national survey data records 50% of businesses and 32% of charities experiencing some form of cyber security breach or attack in 2025, with phishing the most commonly reported form — 84% of businesses and 83% of charities.

This Is The Instrument The Corpus Keeps Asking For

A government-run survey of a representative sample, repeated annually, covering organisations of every size including those far below any notification threshold.

It does not depend on an organisation choosing to disclose, on a leak site listing, on a vendor’s sensor population, or on a class action being worth bringing. It is the closest thing in this database to a measurement of incidence rather than of visibility — the gap named at 25-0613b and 25-1225.

And The Phishing Figure Is The Most Useful Number In The File

Eighty-four per cent, across organisations of all sizes. This corpus spends most of its pages on consent-grant abuse, connected applications, edge appliance zero-days and supply-chain campaigns.

For most organisations, most of the time, the answer is a phishing email. The sophisticated techniques this database records are what happens to organisations large enough to be worth the effort.

That is a genuine corrective to the corpus’s own emphasis, and it is consistent with the size-bias argument at 25-0613b.

Charities Reporting Less Is Probably Not Good News

32% against 50% could mean charities are attacked less. It could also mean they detect less — the same reading this desk applied to national comparisons at 25-1117 and 25-1206.

An organisation without monitoring reports fewer breaches, and 25-0614b records the sector describing its own resilience as insufficient. Graded high on the survey’s reliability; the interpretation of the gap is not established.

This is an analysis file

Built on published UK national survey data, listed below. The survey measures self-reported experience of breaches or attacks, which depends on detection. Corrections: corrections@forensicpost.com.

Sources
  1. Cyber security breaches survey findingsNI Cyber Security Centre
  2. The crucial role of cybersecurity for nonprofit organizations in 2025BDO
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary