Over 75% of UK councils hit with malware over the past year

Report - senior leaders say their current IT systems lack the capability to deal with new cyber threats


Over 75% of UK local councils and public bodies have been hit by cyberattacks over the past 12 months, according to new research by software security firm Malwarebytes.

The 38 local authorities surveyed said that legacy systems had become a major cause of concern, with 72% of survey respondents adding that it's particularly difficult to integrate new services and applications, leaving them exposed to emerging cyber threats.

Advertisement - Article continues below

Councils have become a key targeted for cybercriminals, according to the report, with 75.8% of authorities having fallen victim to malware, viruses or Trojans over the past year, while 50% said they have experienced a ransomware attack during the same period.

As a result, one-third of senior council officials said they had little confidence in the ability of their current systems to identify and remove suspicious traffic, and that there was no protection against zero-day vulnerabilities often exploited with ransomware.

Criminals have started to shift away from attacking large companies with sophisticated cybersecurity measures, towards relatively vulnerable public bodies that often hold vast amounts of personal data behind weak defences.

In May the NHS was one of those many public services brought to its knees by the WannaCry ransomware campaign, while in 2016, Lincolnshire City council was hit by similar ransomware after its systems were infected through a simple email phishing scam.

Advertisement - Article continues below
Advertisement - Article continues below

The UK parliament was also hit by a "sustained" cyber attack in June, in which 90 email accounts belonging to MPs were accessed. The resulting investigation led security experts to suspect the attack was state-sponsored, most likely originating in Russia.

Although 21 million has been put aside to help upgrade computer systems within the NHS to defend against WannaCry-style attacks, the majority of UK councils remain at risk. As a result, there is a general lack of understanding when it comes to cyber threats and how to deal with them at the local government level, according to the report.

In a separate report published in July, it was found that over 60% of Scottish councils had been targetted by criminals since 2014, with Aberdeen City Council being one of the hardest hit with 12 successful cyber attacks. Of the 19 incidents revealed through a freedom of information request, only 9 were reported to the police, according to the Scotsman.

Advertisement - Article continues below

"It's clear from these findings that there is widespread awareness of the threat of cyber-crime amongst high-ranking local government officials but many are not yet confident in their ability to deal with it," said Anthony O'Mara, VP EMEA at Malwarebytes.

"A lack of faith in legacy systems has led to a massive crisis in confidence within local government, which only adds to the vulnerability of these organisations," added O'Mara. "This, combined with a very noisy vendor marketplace, has meant many high-ranking government officials are now left confused as to how to best deal with these threats."

The UK government announced last year it would be spending 1.9 billion to shore up defences in UK infrastructure considered vulnerable to cyber attacks. As part of that investment, a National Cyber Security Centre was established which is working to "significantly enhance the UK's ability to deal with the full spectrum of cybersecurity threats," according to Prime Minister Theresa May.

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now


cyber security

Zoom hires ex-Facebook CSO Alex Stamos to boost platform security

8 Apr 2020

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020

A critical flaw in 350,000 Microsoft Exchange remains unpatched

7 Apr 2020