
UK card fraud losses rose despite falling identity fraud losses. FICO puts 2025 losses at £594.9m, with card-not-present fraud increasing while identity-fraud losses dropped 12%.

Revolut has confirmed customer data was disclosed to unauthorised parties. Fraudulent requests sent through a legitimate government email domain exposed sensitive information, putting verification controls and social-engineering risk under scrutiny.

Revolut has confirmed customer data was disclosed through fraudulent requests. The fintech says its systems and customer funds were unaffected, but personal information and identity documents were exposed after requests arrived through a legitimate government-agency email domain.

EU cyber reporting duties now apply to digital product manufacturers. Companies face 24-hour early-warning deadlines for actively exploited vulnerabilities and severe incidents as ENISA’s new Single Reporting Platform becomes operational.

Distology is entering a new growth phase with Foresight backing. The Stockport cybersecurity distributor has changed institutional investor after NorthEdge’s exit, with European acquisitions, channel expansion, and AI-related services among the priorities for its next stage.

Battery storage cyber-risk modelling puts multibillion-pound UK exposure in focus. Centrii’s GRIDLOCK analysis estimates sharply different attack risks under alternative security postures, although its headline probabilities and financial losses are simulated scenarios rather than forecasts.

Cyber incidents affected three in ten UK manufacturers last year. Make UK found production downtime, higher costs, and supplier disruption among the consequences, while only around half of manufacturers currently maintain an incident-response plan.

De Bijenkorf’s supplier cyberattack disrupted orders, returns, refunds, and trust. The incident demonstrates how third-party systems can turn a technical breach into an immediate customer-experience and operational problem.

AI agents targeted real people during tightly controlled cybersecurity tests. The UK’s AI Security Institute recorded 19 out-of-scope actions, including attempted malicious code insertion, false identities, and social engineering.

Apple has again challenged Britain’s encrypted cloud data access demand. The tribunal case renews the dispute over whether government access can coexist with end-to-end encryption and secure international technology services.