Site navigation

Almost 20 Million UK User Accounts Leaked This Year

Tom Quinn

,

tech startup security
One user account was leaked every second over Q3 2024 in the UK, according to new data. 

The UK witnessed 8.3 million leaked online user accounts in Q3 2024, a 42% increase compared to Q2 2024’s 5.9 million, according to new data from cybersecurity company Surfshark.

According to Surfsharks global monitoring tool, a total of almost 423 million accounts were breached across the world this quarter, 96% higher compared with the 215 million data leaks seen in Q2 2024.

In other words, the third quarter saw 3,261 accounts breached every minute around the world, with the UK suffering 45 to 64 breached accounts per minute.

Despite those numbers, the UK ranked 6th for the number of breaches, behind the US (93.7m), France (17.2m), Russia (16.5m), Germany (14.6m), and Japan (9.7m).

After North America, Europe saw the second-highest number of breaches in the most recent quarter with 88 million, an increase of over 70% from the previous quarter, with European accounts making up over a fifth (21%) of all those breached.

“Access to user accounts is extremely valuable for cyber crooks who are looking to exploit personal data in nefarious ways. Account breaches can have really serious, real-world consequences,” said Sarunas Sereika,  privacy and security expert at Surfshark.

“Hackers can use financial and personally identifiable information to make fraudulent payments, open new online accounts via Facebook, X or Amazon, or sell this information on the dark web. When account details are leaked, reacting quickly is key. Users should immediately seek to change any passwords for accounts that have been compromised.”

Surfshark said that the spike in account breaches could be tied to the rising use of deepfakes, with scammers using images and videos to assume the identities of victims, and create convincing fake videos or audio clips to trick friends, family, or colleagues into sharing personal information or even money.


Recommended reading


To counteract attackers, victims should act fast to secure their accounts, replacing old passwords with stronger ones of twelve or more characters, making sure to include numbers, symbols, uppercase and lowercase letters.

Experts warn that if financial details have been compromised, individuals should contact their bank and keep track of their finances for any fraudulent transactions. If an account is no longer being used, users should take advantage of GDPR rules and the ‘right to be forgotten’ to have accounts deleted and limit future exposure.

Tom Quinn

Staff Writer, DIGIT

Latest News

Editor's Picks Gaming

Xbox Rolls Out Disc-to-Digital Feature

Business Editor's Picks

Report: Scottish SMEs Face Mounting Cost and Revenue Pressures

Cybersecurity

Five Actions CISOs Can Take to Stay Ahead of Disruptions

Events Featured Finance

Just One Week to Go Until Fintech Summit 2026