New report names UK as Europe’s most targeted country for state-backed cyberattacks
The UK is Europe’s most targeted country for state-backed cyber activity as artificial intelligence helps attackers find vulnerabilities and launch attacks faster.
The findings come from Microsoft’s latest Digital Defence Report, which examines cyber activity observed across the company’s global networks.
The Microsoft report identifies the UK as Europe’s leading target for nation-state cyber activity, as cyber operations play an increasing role in geopolitical competition.
The UK’s National Cyber Security Centre (NCSC) revealed this year that around three-quarters of cyber incidents affecting the country’s critical infrastructure could be linked to state actors.
UK cyberattacks increasingly linked to hostile states
The NCSC said in June that it managed more than 200 incidents affecting UK critical national infrastructure and its supporting ecosystem in the year to May 2026.
Around 75% were believed to have links to state actors.
The figure does not mean state-sponsored attacks account for three-quarters of all cyberattacks against UK organisations. It relates specifically to incidents involving critical infrastructure handled by the NCSC.
However, state involvement is evident in the country’s most serious cyber incidents.
Speaking at CYBERUK 2026, NCSC chief executive Dr Richard Horne said the agency continued to handle around four nationally significant incidents each week.

“The majority of the nationally significant incidents that my teams are handling now originate directly or indirectly from nation states,” he said.
Horne has identified Russia, China and Iran among the hostile states increasingly targeting systems supporting essential UK services.
“In cyberspace, we are not preparing for tomorrow’s conflicts; to some degree we are fighting them today,” he said.
China, Russia and Iran pose growing threat
The NCSC has warned that geopolitical tensions are playing out online. Horne described China’s intelligence and military agencies as having an “eye-watering level of sophistication,” with their scale making China a “peer competitor in cyberspace.”
Russia, meanwhile, is applying techniques developed during its war against Ukraine beyond the battlefield.
“The tactics and techniques honed in conflict are now being directed at states it considers hostile,” Horne said.
Iran also uses cyber operations to advance state objectives. North Korean activity has included intelligence gathering, sanctions evasion and revenue generation.
Cyberattacks have consequently become an important part of the “grey zone” between peace and conventional warfare.
AI is speeding up cyberattacks
Microsoft’s latest research shows artificial intelligence is reducing the time required to conduct parts of a cyberattack.
AI can assist with vulnerability discovery, reconnaissance, social engineering, malware development and analysis of stolen information. Tasks that previously required substantial human effort can now be automated.
Microsoft says AI compresses parts of the attack process that once took days into minutes or seconds.
The NCSC has raised similar concerns. Its assessments of AI and cybersecurity warn that increasingly capable AI systems will accelerate vulnerability discovery and exploitation.
The agency expects AI-enabled capabilities to make it easier for attackers to exploit known vulnerabilities in legacy technology at scale. That presents a problem for critical infrastructure operators running older systems that cannot easily be replaced.
AI does not only benefit attackers. Defenders can use the technology to identify vulnerabilities, analyse large volumes of security data and detect suspicious behaviour. However, it also lowers some barriers for less sophisticated attackers.
Why is the UK a major cyber target?
The UK’s position as a major economy, NATO member, intelligence power and prominent supporter of Ukraine makes it an attractive target for governments seeking political, military and commercial intelligence.
The country also relies heavily on interconnected digital systems across finance, communications, transport, energy and public services.
Those networks create opportunities for espionage and disruption without requiring hostile states to resort to conventional military action.
The NCSC has urged organisations to treat cybersecurity as an operational resilience and national security issue rather than simply an IT problem.
Horne has warned that basic weaknesses continue to enable serious incidents.
“We still see far too many significant incidents today that are possible because the fundamentals are not in place,” he said.
Cyber defence becomes a national security priority
The growing threat has pushed cybersecurity higher up the UK’s national security agenda.
The government is strengthening requirements for organisations providing essential services, while the NCSC is urging company boards to understand their exposure and ensure essential operations can continue after a successful attack.
Microsoft’s findings suggest that the challenge is more urgent as geopolitical tensions meet rapidly advancing technology.
As Horne warned this year, cyber operations are now “as much a reality of modern warfare as drones and missiles.”
Sign up for our newsletter and get our latest content in your inbox.
Similar Reads
Sign up for our newsletter. Select all sectors relevant to you.
Related















