Connect with us

Hi, what are you looking for?

AI Cybersecurity

AI-Driven Cyber Attacks Surge in UK, Causing £1.9B Impact and Major Service Disruptions

DTP Group warns that AI-driven cyber attacks in the UK surged in 2025, resulting in £1.9 billion in losses and crippling service disruptions across major sectors.

Hybrid cloud services provider DTP Group has issued a stark warning that 2025 could mark a significant turning point for cyber security in the UK. The company has observed that attackers are increasingly leveraging artificial intelligence and exploiting vulnerabilities within supply chains to disrupt critical sectors. DTP’s analysis of the year’s most disruptive incidents reveals a troubling shift from data theft towards tactics aimed at halting operational functions.

The report indicates that approximately 16% of reported cyber incidents in 2025 featured attackers utilizing AI, including techniques such as deepfake voice and video, automated credential-stuffing, and AI-enhanced phishing schemes. The threat landscape has escalated, with nation-state and hybrid actors continuing their focus on critical national infrastructure and manufacturing supply chains.

Rather than solely targeting information, cybercriminals are increasingly intent on disabling business processes and disrupting supply chains. DTP noted a concerning trend of incidents that fused ransomware with large-scale data exfiltration, wherein criminals threatened to disclose sensitive information even when they did not encrypt systems.

The threat environment in the UK has intensified considerably. The National Cyber Security Centre reported a staggering 204 “nationally significant” attacks in the 12 months leading up to August 2025, a significant rise from 89 incidents in the prior comparable period.

DTP’s analysis detailed several major incidents throughout the year, including an attack on Marks & Spencer, which operates a substantial online retail platform. This incident, attributed to the Scattered Spider group, involved social engineering tactics such as SIM swapping and phishing against a third-party provider. As a result, online orders were suspended for approximately six weeks, disrupting click-and-collect services and contactless payments. DTP estimated that the incident resulted in a loss of more than £300 million in profit and revenue, alongside the exposure of personal customer data, including names, email addresses, dates of birth, and order histories.

Similarly, the Co-op Group experienced a substantial breach that disrupted its food and retail operations. Attackers used social engineering to gain insider access, leading to interruptions in stock ordering and leaving rural stores with empty shelves. The breach compromised personal data for 6.5 million members, with DTP estimating an impact of around £80 million on profit and a £206 million revenue loss in the first half of 2025.

The seriousness of the situation was further illustrated by the ransomware attack on Jaguar Land Rover, which halted production at its “smart factory” operations. DTP characterized this incident as potentially the costliest cyber event in UK history, with an estimated economic impact of £1.9 billion. The ramifications were wide-ranging, affecting not just Jaguar Land Rover but also rippling through the wider automotive supply chain.

Another significant disruption occurred at global beverage group Asahi, where ransomware infiltrated the organization through a compromised supplier account, impacting operational technology and industrial control systems across multiple sites in Europe and Asia. This attack resulted in production stoppages, global supply shortages, and delayed shipments, emphasizing that supply-chain compromises remain a highly effective avenue for attackers.

In an illustrative case outside the UK, DTP highlighted a breach at Qantas Airways in Australia, where attackers compromised a third-party vendor via social engineering, gaining access to customer information for 5.7 million customers. Although Qantas reported no impact on flight operations, the exposed data later surfaced on criminal forums, underscoring the risks posed to organizations by vulnerabilities among their vendors.

DTP’s Head of Cyber Security emphasized that these incidents highlight an urgent need for fundamental changes in security strategies. The company recommends that organizations operate under the assumption that credentials may already be compromised and advocate for the implementation of multi-factor authentication and least-privilege access. Strengthening third-party risk management is also crucial, with a call for businesses to map dependencies and conduct audits of access for software-as-a-service providers and supply-chain partners.

Additionally, DTP advocates for integrating cyber resilience into business continuity planning, highlighting the necessity for plans that address potential downtime, manual workarounds, and supply-chain disruptions. The company stressed the importance of enhancing security measures for operational technology and industrial control systems across various sectors, including manufacturing, logistics, and retail.

As cyber threats evolve, DTP underscores the importance of preparing staff for AI-amplified threats through training programs aimed at recognizing deepfakes and AI-driven social engineering attempts. A clear incident response and communication strategy is also essential for mitigating reputational damage following an attack.

The incidents observed in 2025 illustrate that cyber threats now represent business continuity challenges rather than mere IT concerns, directly impacting operations, supply chains, revenue, and customer trust. As organizations look ahead, those that invest in zero-trust security, supply-chain assurance, and operational technology defenses in the coming months will be better positioned to face the next wave of AI-driven threats as they enter 2026.

See also
Rachel Torres
Written By

At AIPressa, my work focuses on exploring the paradox of AI in cybersecurity: it's both our best defense and our greatest threat. I've closely followed how AI systems detect vulnerabilities in milliseconds while attackers simultaneously use them to create increasingly sophisticated malware. My approach: explaining technical complexities in an accessible way without losing the urgency of the topic. When I'm not researching the latest AI-driven threats, I'm probably testing security tools or reading about the next attack vector keeping CISOs awake at night.

You May Also Like

Top Stories

South Korea targets a 2% growth in 2026, unveiling a comprehensive AI strategy including a national computing center and a push for self-driving vehicle...

AI Cybersecurity

AI agents face escalating cyber threats, necessitating innovative security frameworks to protect them from manipulation and exploitation in an evolving digital landscape

Top Stories

DeepSeek expands its R1 paper from 22 to 86 pages, showcasing AI capabilities that may surpass OpenAI's models with $294,000 training costs and enhanced...

AI Education

UCL Computer Science will host its second all-girls hackathon on February 16, 2026, focusing on AI to empower Year 12 students from UK state...

Top Stories

Analysts predict monday.com's shift to AI-driven growth and enterprise clients could boost its value by 59%, targeting $2 billion in revenue by 2028.

AI Marketing

Braze's 25.5% revenue growth surpasses analyst expectations, bolstering its AI-driven customer engagement strategy for 6.2 billion monthly users.

AI Technology

Brookfield Asset Management signals a $10B infrastructure investment strategy for 2026, driven by soaring AI demand for power and data center resources.

AI Research

FactSet projects $2.4B in revenue by 2026 while intensifying AI integration, even as rising tech costs pose risks to profit margins.

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.