Security-Stop Press : Worst Data Breaches of 2025 Show Cyber Attacks Are About Disruption

The most serious cyber incidents of 2025 showed a clear move away from data theft towards operational disruption and economic damage.

Globally, attackers exploited trusted platforms and supply chains, with US federal systems breached repeatedly and the Clop group stealing sensitive data by abusing an unknown flaw in Oracle E Business. More than one billion records were also accessed from Salesforce environments after hackers compromised connected third party platforms rather than Salesforce itself.

In the UK, disruption had immediate consequences. Cyber attacks on Marks & Spencer and Co-op exposed customer data and knocked systems offline, with Co-op later confirming all 6.5 million members were affected. The Cyber Monitoring Centre estimated the retail attacks caused up to £440 million in economic damage.

The most severe UK case involved Jaguar Land Rover, where a cyberattack halted production for months and destabilised its supply chain, prompting a £1.5 billion government guarantee to protect jobs and suppliers.

For businesses, the lesson from 2025 is that resilience is critical. Guidance from the National Cyber Security Centre emphasises patching, limiting third party access, tested backups, and rehearsed incident response, because fast recovery is now the key defence against disruptive attacks.

Company Check – What’s The Major ‘4chan’ Hack All About?

Infamous internet forum 4chan has suffered a major breach, leaking its internal systems, moderator identities, and possibly thousands of user IP addresses, fuelling speculation that this could mark the beginning of the end for the notorious platform.

What Is 4chan And Why Does It Matter?

Founded in 2003, 4chan is an anonymous imageboard often described as a digital Wild West. Users can post without usernames, and content is loosely moderated. While it’s credited with spawning viral memes like Pepe the Frog and rage comics, it’s also been home to some of the web’s darkest corners, from coordinated harassment campaigns to the early spread of far-right conspiracies.

The forum’s politics board has become notorious for radicalising users, some of whom have gone on to commit acts of real-world violence. It’s also where movements like QAnon first gained momentum. Despite being largely shunned by advertisers and mainstream platforms, 4chan remains a highly influential space where internet culture, politics, and trolling collide.

A Major Breach With Far-Reaching Impacts

This week, that chaotic ecosystem was rocked by a hack that insiders say may have been in motion for more than a year. The attack revealed source code, backend templates, moderator tools, and internal databases. Personal data linked to moderators and subscribers was also reportedly exposed, including names, emails, and in some cases IP addresses.

The site was intermittently offline for hours following the breach, with parts of the homepage reportedly defaced and inactive forums mysteriously reinstated. According to public posts by those claiming responsibility, the hack was less about ransom and more about revenge, i.e. an internal feud turned hostile.

One detail fuelling concern is that among the leaked email addresses were several ending in .gov and .edu, which suggests that users tied to government or academic institutions could now be vulnerable to doxxing or blackmail. The risk isn’t just reputational. Depending on how this data is used, it could lead to real-world consequences.

How Did It Happen?

While the full technical picture is still emerging, early reports appear to suggest 4chan had been operating on outdated, insecure software, including an obsolete version of PHP and deprecated methods for database access. If true, this combination likely left doors wide open for a patient and persistent attacker to get in, remain undetected, and eventually extract vast amounts of data.

In cyber terms, this is less of a smash-and-grab and more of a long con and, if a rival forum is to be believed, the intruders used their access to not only leak sensitive information but also revive banned boards and taunt current site administrators.

The Fallout So Far

Internally, 4chan is facing questions it may not be able to answer. For example, its reliance on pseudonymous volunteers, the informal way in which moderation is run, and its almost total lack of public accountability now seem like liabilities rather than strengths.

Externally, the consequences could actually be severe. For example, leaked identities could put moderators at personal risk, especially given 4chan’s history of revenge campaigns and vigilantism. There’s also now a renewed debate over whether parts of the site have effectively been functioning as havens for extremist content under the guise of free speech.

For some long-time observers, this incident could mark a turning point. Without a clear governance structure or commercial backing, the site’s ability to rebuild trust (or even operate securely) looks increasingly doubtful.

Could This Really Be the End of 4chan?

It’s too early to say for sure, but the signs are worrying. Between the reputational damage, the threat to key personnel, and a user base now questioning whether their own data might be at risk, 4chan’s foundations appear shakier than ever.

That said, the site has weathered controversy before, e.g. from the Gamergate harassment campaign to repeated calls for shutdown. However, for many, this time feels different. Unlike previous scandals, which typically involved offensive content or rogue users, this is a structural crisis, and it cuts to the core of who runs the site, how secure it is, and whether it can even survive without turning on itself.

What Does This Mean For Your Business?

If your company operates any kind of community platform, forum, or subscription-based service, this breach could be seen as a wake-up call. For example, it highlights the dangers of outdated code, minimal oversight, and neglecting basic security hygiene, especially when managing anonymous users or sensitive content.

More broadly, the 4chan hack serves as a reminder that digital subcultures can have very real business and societal impacts. It seems that what begins as online trolling can really escalate into public backlash, reputational crises, or even legal scrutiny.

For firms working in cybersecurity, law enforcement, or digital risk management, this incident essentially highlights the importance of monitoring fringe spaces. In short, today’s niche forum may be tomorrow’s national headline, and as this breach shows, even the most apparently chaotic platforms aren’t immune to internal implosion.

Tech Insight : Shadow AI and Shadow SaaS Risks?

A Next DLP survey (conducted at RSA Conference 2024 and Infosecurity Europe 2024) has revealed how the rise of ‘Shadow SaaS’ and ‘Shadow AI’ may be putting businesses at risk of data loss, lack of visibility, and data breaches.

What Are Shadow SaaS and Shadow AI? 

Shadow SaaS refers to the use of software-as-a-service (SaaS) applications within an organisation without explicit approval from the IT department. Similarly, Shadow AI involves the deployment of AI tools and solutions without official oversight. The issue for businesses is that these shadow technologies often bypass the stringent security protocols and oversight that sanctioned IT solutions are subjected to, thereby creating potential vulnerabilities.

Prevalent 

One notable fact that the Next DLP survey established is the prevalence of SaaS applications in organisations, with almost three-quarters of security professionals (73 per cent) admitting to using SaaS applications that had not been provided by their company’s IT team in the past year.

Key Findings from the Next DLP Survey 

The Next DLP survey, which captured insights from industry professionals at two major conferences, appears to have revealed some of the more potentially negative implications of the use of Shadow SaaS and Shadow AI in organisations. For example, the survey reveals three primary areas of concern – data loss, lack of visibility, and data breaches.

Data Loss 

The unregulated nature of Shadow SaaS and Shadow AI can mean that sensitive data can easily be transferred, shared, or stored outside the secure confines of the company’s IT infrastructure. However, one key issue highlighted by the Next DLP survey, is the apparent disparity between employee confidence in using unauthorised tools and the organisation’s ability to mitigate the risks. For example, 65 per cent of respondents named data loss as a top risk of using unauthorised tools, and it appears that (according to 40 per cent of security professionals) employees may not fully understand the data security risks posed by shadow SaaS and shadow AI.

The survey respondents noted multiple instances where critical business data was inadvertently exposed or lost due to the use of unauthorised applications and AI tools.

This data loss can not only hamper business operations but also puts companies at risk of non-compliance with data protection regulations.

Lack of Visibility 

Another significant challenge highlighted by the survey appears to be the lack of visibility over shadow technologies. Without proper oversight, IT departments cannot track or manage these applications, making it difficult to enforce security policies or detect anomalies.

The survey indicated, for example, that 62 per cent of respondents are concerned about the lack of full visibility and control of the SaaS and AI tools being used within their organisations, thereby leading to unmanaged risks and potential security gaps.

Data Breaches

The integration of unauthorised applications and AI tools also significantly increases the risk of data breaches for organisations. For example, shadow technologies often lack the strong security measures that are standard in approved IT solutions.

The Next DLP survey reflected this by showing that just over half (52 per cent) of respondents see data breaches as a top risk of using unauthorised tools. The survey also reported an apparent surge in security incidents linked to shadow applications, with many businesses experiencing breaches that compromised sensitive information. For example, 10 per cent of respondents admitted they were certain their organisation had suffered a data breach or data loss as a result of Shadow SaaS usage

Data breaches not only result in financial losses but also damage the reputation of the affected companies.

Understanding of Shadow SaaS and AI Risks 

As previously touched upon, the Next DLP survey also revealed gaps in employee training and awareness regarding Shadow SaaS and AI risks in their organisation. For example, it showed that 40 per cent of security professionals believe employees do not understand these risks, and only 37 per cent have developed clear policies and consequences for unauthorised tool use. Also, 20 per cent admitted to being unaware of their company’s policy updates or training on these risks and 20 per cent also said they hadn’t received any guidance and updated policies in the past six months.

Such findings, therefore, appear to highlight the need for improved awareness and education on managing shadow technologies.

What To Do? 

To mitigate the risks associated with Shadow SaaS and Shadow AI, businesses may, therefore, benefit from adopting a proactive approach and using key strategies such as:

– Enhanced monitoring. Implementing advanced monitoring tools to detect and manage unauthorised applications.

– Employee education. Training employees on the risks of using unapproved technology and the importance of adhering to company policies.

– Robust policies. Developing and enforcing clear and comprehensive IT policies that address the use of SaaS and AI tools.

– Promote approved alternatives. For example, encouraging the use of approved and secure alternatives to unauthorised applications can help reduce reliance on risky shadow technologies. Currently, only 28 per cent of organisations promote such alternatives.

– Regular audits. Conducting regular audits to identify and remediate any instances of shadow technology usage.

What Does This Mean For Your Business? 

The findings from the Next DLP survey reveal a critical need for businesses to address the growing risks associated with Shadow SaaS and Shadow AI. The prevalence of unauthorised tools, combined with the significant risks of data loss, lack of visibility, and data breaches, all highlight the urgency for a strategic response.

For businesses, this means taking proactive steps to manage and mitigate these risks. For example, implementing advanced monitoring tools can help detect and control the use of unsanctioned applications and AI tools. By gaining full visibility into the tools employees use, businesses can better enforce security policies and detect anomalies early.

Employee education is another way to mitigate the risks. Training staff about the dangers of using unauthorised technologies and the importance of adhering to company policies can significantly reduce the likelihood of data breaches and other security incidents. Developing and enforcing clear and comprehensive IT policies can also help ensure that all employees understand the consequences of using unapproved tools.

Promoting the use of approved, secure alternatives, encouraging employees to rely on sanctioned applications and having regular audits are also ways that businesses can minimise the risks associated with Shadow SaaS and Shadow AI, identify and address any instances of shadow technology usage, and ensure continuous compliance and security.

Adopting these kinds of proactive strategies may mean that businesses can safeguard against the vulnerabilities posed by unauthorised applications and AI tools, protect their sensitive data, and enhance their overall security posture, thereby helping to avoid the pain of financial losses and reputational damage.

Thought About Cyber Insurance?

Here we take a look at cyber security, why you may decide you need it, how much it costs, and where to get it.

What Is Cyber Insurance? 

Cyber insurance is a type of insurance policy designed to protect businesses and individuals from internet-based risks, and more generally from risks relating to IT infrastructure and activities. It provides coverage for financial losses that result from cyber incidents such as data breaches, network damage, and cyber extortion. For example, businesses may face costs resulting from data/security breaches, media content liability (e.g. intellectual property infringement), GDPR defence costs or paying GDPR fines, credit/debit card breaches, data breach response services, data breach notification, legal fees, system repairs, and more.

Why Would Your Business Need Cyber Insurance? 

Just as we need to ensure our most valuable and valued physical-world possessions are protected (e.g. our homes and cars), we now live in a digital age where people and businesses now rely heavily on technology and online platforms to operate efficiently. However, this dependence makes businesses vulnerable to a range of cyber-threats, including data-breaches, ransomware attacks, and hacking incidents. Even a single cyber-attack can result in substantial financial losses, legal liabilities, and reputational damage. Cyber insurance, therefore, provides a safety net, so that businesses can recover financially and operationally from these incidents. By covering costs such as data-breach notification, legal fees, and system repairs, cyber insurance helps mitigate the financial burden of cyber-attacks.

Risk Management Too 

Cyber insurance can also play a crucial role in risk management. For example, it encourages businesses to assess their cyber vulnerabilities and implement robust security measures.

Insurers often require policyholders to adhere to specific security protocols, which enhances overall cybersecurity standards. This proactive approach not only reduces the likelihood of an attack but also ensures businesses are better prepared to respond effectively if one occurs. Therefore, having cyber insurance is not just about financial protection, but it’s also about fostering a culture of cybersecurity within the organisation.

Not Forgetting Regulatory Compliance 

In addition to financial and security benefits, cyber insurance is essential for regulatory compliance. Many industries are subject to strict data protection regulations, such as the General Data Protection Regulation (GDPR) in Europe and non-compliance can, of course, result in hefty fines and legal consequences.

Cyber insurance policies, therefore, often include support for regulatory compliance, helping businesses navigate complex legal requirements and avoid penalties. By providing resources for legal counsel and regulatory guidance, cyber insurance ensures that businesses can meet their obligations and maintain trust with customers and stakeholders.

What Kind Of Things Does It Cover?

As mentioned above, broadly speaking, cyber insurance aims to provide financial cover for things like data breaches, network damage, and cyber extortion. Cyber insurance for UK businesses actually provides comprehensive coverage for various cyber-related incidents. Here are some examples of what it typically covers:

Data Breach Response 

– Notification Costs: Covering the expenses of notifying customers and affected individuals after a data breach.

– Credit Monitoring Services: Providing credit monitoring to those whose personal information has been compromised.

Business Interruption 

– Loss of Income: Reimbursement for lost revenue due to a cyber-attack that disrupts normal business operations.

– Extra Expenses: Covering additional costs incurred to keep the business running while dealing with the cyber incident.

Cyber Extortion 

– Ransom Payments: Payments made to cybercriminals to regain access to data or systems.

– Negotiation Costs: Expenses related to negotiating with extortionists and managing ransom demands.

Legal Fees and Defence Costs 

– Third-Party Claims: Legal expenses arising from lawsuits due to a data breach or security failure.

– Regulatory Fines and Penalties: Coverage for fines and penalties imposed by regulators for data protection breaches, such as those related to GDPR.

Crisis Management 

– Public Relations: Costs associated with managing and repairing the company’s reputation after a cyber incident.

– Forensic Investigation: Expenses for investigating the cause and extent of the cyber-attack.

Network Security Liability

– Liability Claims: Coverage for claims arising from failure to protect data, resulting in data theft or corruption.

– Defence Costs: Legal defence costs for claims related to network security breaches.

Media Liability

– Defamation and Infringement: Coverage for claims of libel, slander, copyright infringement, or defamation resulting from digital content.

Technology and Data Recovery 

– Data Restoration: Costs of restoring and recovering lost or corrupted data.

– System Repair: Expenses for repairing or replacing damaged hardware and software

You may be thinking after looking at this list that there are many more costs than you may have thought associated with dealing with the results of a data breach, cyber-attack, or serious and disruptive network issue. These costs, plus the high levels of ever-more sophisticated cyber-crime, may be the arguments behind many businesses now having cyber insurance.

What Proportion of Businesses Now Have Cyber Insurance? 

Considering the large potential costs of dealing with a serious cyber / network incident (as shown above) it may be a surprise to know that the proportion of businesses with cyber insurance in the UK is still relatively modest. For example, the latest data shows that only 43 per cent (UK Home Office 2024) of UK businesses have a cyber insurance policy in place and within this group, a small fraction, around 5 per cent (Insurance Business UK), have specialised cyber insurance policies tailored to their specific needs. Most companies rely on broader policies that include some form of cyber risk coverage as part of their overall insurance package.

This may be particularly surprising given that according to the Cyber Security Breaches Survey 2024 by the Department for Science, Innovation and Technology (DSIT):

– 32 per cent of businesses and 24 per cent of charities experienced a cyber security breach or attack in the past 12 months.

– Among larger businesses, the figures are higher, with 45 per cent of medium businesses and 58 per cent of large businesses have reported cyber-crimes.

– The average short-term direct cost for businesses dealing with a cyber incident was £1,650, which increases to £6,490 for medium and large companies.

– Long-term direct costs, which include expenses incurred after the initial breach, averaged £782 for all businesses but reached £6,010 for larger firms.

Who Provides It? 

Several examples of the well-known insurers in the UK market that offer cyber security insurance include:

– AXA provides comprehensive cyber insurance that covers a range of cyber risks, including data breaches, business interruption, and cyber extortion.

– Aviva offers cyber insurance policies that can be tailored to businesses of all sizes. Their coverage includes protection against data breaches, cyber extortion, and business interruption caused by cyber incidents, and there is access to a 24/7 cyber incident helpline and expert support.

– Hiscox provides coverage which includes costs associated with data breaches, cyber extortion, and third-party liability, and it offers risk management tools and resources to help businesses improve their cyber security posture.

– Zurich’s offers cyber insurance policies covering a wide range of cyber risks, including data breaches, network security failures, and cyber extortion. Zurich also provides access to a global network of cyber experts and offers pre-breach services to help businesses mitigate their cyber risks.

There are, of course, many other companies that offer cyber insurance. For example, even Amazon now offers it with AWS Cyber Insurance Competency Partners, and through a partnership with Superscript is offering cyber insurance to small and medium-sized businesses in the UK. For example, Amazon Business Prime users can access it product by logging in to Superscript using their Amazon account.

How Much Does It Cost?

Obviously, the price of cyber insurance varies according to factors like the size of the business, the level of coverage, and the industry. However, as a very general guide:

– Small businesses in the UK may expect to pay around £115 per month for cyber insurance / £1,380 annually (Insureon), which can fluctuate depending on the specific risks associated with the business and the amount of sensitive data handled.

– Medium-sized businesses may see premiums ranging from £1,500 to £5,000 per year, with the variation being due to the higher risk and more significant potential losses associated with larger volumes of data and more complex IT systems.

– For large businesses, cyber insurance costs can range from £10,000 to £50,000 annually and can include higher coverage limits and broader protection against various cyber threats (reflecting the greater complexity and risk involved).

What Does This Mean For Your Business? 

The rising tide of cyber threats highlights the urgent necessity for businesses to not just strengthen their cyber security measures, but also to consider adopting comprehensive cyber insurance policies. Cyber-attacks are not only becoming more frequent but also increasingly sophisticated, posing severe risks to financial stability and operational continuity. For businesses, this means that traditional security measures alone may no longer be sufficient. Cyber insurance provides a critical safety net, offering financial protection against the costs associated with data breaches, business interruptions, and other cyber incidents.

Investing in cyber insurance can significantly mitigate the financial and operational impacts of cyber-attacks. Policies typically cover a range of expenses, from data breach notifications and legal fees to system repairs and business interruption losses. This ensures that businesses can recover more swiftly and maintain their operations with minimal disruption. Also, cyber insurance often includes access to expert support and resources, helping businesses to manage incidents more effectively and reduce the risk of recurrence.

In addition to financial protection, it’s important to remember that cyber insurance also plays a crucial role in regulatory compliance. For example, many industries are subject to stringent data protection regulations, such as the GDPR in Europe, and non-compliance can result in hefty fines and legal consequences. Cyber insurance policies frequently offer support for navigating these complex legal requirements, helping businesses to avoid penalties and maintain trust with customers and stakeholders.

For businesses evaluating their need for cyber insurance, it’s important to consider the broader benefits. Beyond immediate financial coverage, having a cyber insurance policy can drive improvements in overall cyber security practice. For example, insurers often require policyholders to implement robust security protocols, fostering a culture of proactive risk management within the organisation. This not only reduces the likelihood of successful cyber-attacks but also ensures that businesses are better prepared to respond effectively when incidents do occur.

Given the substantial costs associated with cyber incidents, the investment in cyber insurance becomes a strategic decision. Whether you are a small business, medium-sized or a large corporation, the protection and peace of mind offered by cyber insurance can be invaluable.

The evolving landscape of cyber threats, therefore, appears to necessitate a multifaceted approach to cyber security and you may decide, for all the reasons mentioned above, that cyber insurance should be a cornerstone of this strategy for your business.