Over 75% of UK councils hit with malware over the past year

Report - senior leaders say their current IT systems lack the capability to deal with new cyber threats


Over 75% of UK local councils and public bodies have been hit by cyberattacks over the past 12 months, according to new research by software security firm Malwarebytes.

The 38 local authorities surveyed said that legacy systems had become a major cause of concern, with 72% of survey respondents adding that it's particularly difficult to integrate new services and applications, leaving them exposed to emerging cyber threats.

Councils have become a key targeted for cybercriminals, according to the report, with 75.8% of authorities having fallen victim to malware, viruses or Trojans over the past year, while 50% said they have experienced a ransomware attack during the same period.

As a result, one-third of senior council officials said they had little confidence in the ability of their current systems to identify and remove suspicious traffic, and that there was no protection against zero-day vulnerabilities often exploited with ransomware.

Criminals have started to shift away from attacking large companies with sophisticated cybersecurity measures, towards relatively vulnerable public bodies that often hold vast amounts of personal data behind weak defences.

Advertisement - Article continues below
Advertisement - Article continues below

In May the NHS was one of those many public services brought to its knees by the WannaCry ransomware campaign, while in 2016, Lincolnshire City council was hit by similar ransomware after its systems were infected through a simple email phishing scam.

The UK parliament was also hit by a "sustained" cyber attack in June, in which 90 email accounts belonging to MPs were accessed. The resulting investigation led security experts to suspect the attack was state-sponsored, most likely originating in Russia.

Although 21 million has been put aside to help upgrade computer systems within the NHS to defend against WannaCry-style attacks, the majority of UK councils remain at risk. As a result, there is a general lack of understanding when it comes to cyber threats and how to deal with them at the local government level, according to the report.

In a separate report published in July, it was found that over 60% of Scottish councils had been targetted by criminals since 2014, with Aberdeen City Council being one of the hardest hit with 12 successful cyber attacks. Of the 19 incidents revealed through a freedom of information request, only 9 were reported to the police, according to the Scotsman.

"It's clear from these findings that there is widespread awareness of the threat of cyber-crime amongst high-ranking local government officials but many are not yet confident in their ability to deal with it," said Anthony O'Mara, VP EMEA at Malwarebytes.

Advertisement - Article continues below

"A lack of faith in legacy systems has led to a massive crisis in confidence within local government, which only adds to the vulnerability of these organisations," added O'Mara. "This, combined with a very noisy vendor marketplace, has meant many high-ranking government officials are now left confused as to how to best deal with these threats."

The UK government announced last year it would be spending 1.9 billion to shore up defences in UK infrastructure considered vulnerable to cyber attacks. As part of that investment, a National Cyber Security Centre was established which is working to "significantly enhance the UK's ability to deal with the full spectrum of cybersecurity threats," according to Prime Minister Theresa May.

Featured Resources

Digital Risk Report 2020

A global view into the impact of digital transformation on risk and security management

Download now

6 ways your business could suffer if you don’t backup Office 365

Office 365 makes it easy to lose valuable data regularly, unpredictably, unintentionally, and for good

Download now

Get the best out of your workforce

7 steps to unleashing their true potential with robotic process automation

Download now

8 digital best practices for IT professionals

Don't leave anything to chance when going digital

Download now



Hackers abuse LinkedIn DMs to plant malware

25 Feb 2019

Best free malware removal tools 2019

23 Dec 2019
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular


How to use Chromecast without Wi-Fi

5 Feb 2020
cyber security

McAfee researchers trick Tesla autopilot with a strip of tape

21 Feb 2020
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020

The top ten password-cracking techniques used by hackers

10 Feb 2020