Reports of phishing increased by 64% last year, with the Information Commissioners Office receiving 3,366 reports of phishing between January and September 2024 – equivalent to twelve every day.
However, according to ICO data analysed by Reboot Online, phishing was the only kind of cyber-incident which saw any increase over 2023, with malware, the second most reported incident type, seeing an 8% YoY fall, with just 362 cases.
Reports to the ICO of ransomware (-13%), brute force (-32%), unauthorised access (-45%), and denial of service attacks (-83%) all fell significantly over the period, with the study finding just one incidence of denial of service compared to the six recorded in 2023.
Reboot Online also discovered that during the first three-quarters of 2024, the majority of cyber-incidents were reported between 24 and 72 hours after the initial breach – an increase of 26% from 2023, and accounting for 51% of all reports.
The figures, published to mark the beginning of Data Privacy Week, show there was a 14% reduction in the number of reports made by businesses more than one week after the incident occurred, at 15% of all reports, although there was a 12% decrease in reports made within the first 24 hours.
Unfortunately, despite most businesses being faster to report cyber-attacks, there has been a marked increase in the number of breaches across some sectors.
The ICO data found the marketing sector to be the worst affected, with a 190% increase in reported cyber-incidents, going from 40 in 2023 to 116 last year. Also badly impacted were membership associations, with a 84% increase, social care (74%), justice (67%) and the healthcare sector (62%).
However, there was some good news too, with several industries seeing a year-on-year fall in the number of cyber-incidents they reported.
The media sector reported the largest decrease in cybersecurity incidents, with 68% fewer than in 2023 – down to just 15 reports – followed by regulators, which reported 47% fewer incidents in 2024, while the finance, insurance and credit industries noted a 40% fall in security breaches.
Recommended reading
- ICO: Data Protection Not An Excuse When Tackling Scams, Fraud
- Meta’s Pay or Consent Model Found in Breach of EU’s Market Rules
- Data Privacy Day: Where are We and How Did We Get Here?
“With data breaches costing businesses an average of $4.45 million globally in the last year, it raises the question of just how critical it is for organisations to provide employees with comprehensive training on what constitutes sensitive data and how they can protect it,” said Venky Sundar, founder of cybersecurity firm Indusface.
“Regular training and guidance will ensure that employees receive tailored guidance on securing their work equipment, home offices, use of VPNs, and recognizing the unique threats posed by both in-office and home working environments.”





