The UK now ranks as the third most targeted country for malware, facing more than 100 million cyber-attacks in just the past three months, according to research from NordVPN.
The cybersecurity firm found that everyday internet users are increasingly being targeted by cyber-criminals, falling victim to fraudulent email and text links, as well as malicious attachments and websites.
The US and Canada are the only countries that outstrip the UK when it comes to malware, which saw a 7% increase in the amount of malware from the first to the second quarter of 2025. While the US did see the most overall malware attacks (2.91bn), the UK actually had a higher concentration of malware relative to its population.
The UK’s increasingly digital economy – from a high uptake of smartphones and digital banking to the use of social networks and online shopping – makes it a prime target.
In the second quarter of 2025, the UK saw 1,473 incidents by device per month, versus just 1,281 incidents in the US. The UK was also the most targeted country in Europe when it comes to malware.
It may also be worth noting that the top three countries are also predominantly English-speaking nations (note: Canada also has French as its official language, and the US only made English its official language in March this year), which could also contribute to their targeting. Translation tools that rely on AI systems are often much more proficient at English than other languages.
NordVPN also reported that Google was the most impersonated brand by cyber-criminals, followed by Yahoo!, Telegram, Steam, Outlook, and Amazon. These are typically highly trusted brands, meaning that malware criminals still rely on user trust and people’s day-to-day online practices for exploitation.
Video hosting platforms were the most common vectors for malware, followed by streaming services, content delivery, files sharing, and entertainment platforms.
Recommended reading
- NCSC Warns Fancy Bear Malware Hijacking Email Accounts
- Report: AI-powered Malware Detection Sees 315% Increase
- Fake Dating Apps Uncovered in Global Malware Campaign
The most commonly blocked malware NordVPN identified was Advanced Persistent Cyber (APC) virus, which has many variants that all tend to target system configurations in an effort to disrupt automated processes.
“Our data shows that online threats are steadily increasing, not only in number but also in complexity,” Marijus Briedis, chief technology officer at NordVPN, said.
“Malware has become the Swiss Army knife of online crime. It’s fast, silent, and often invisible until it’s too late.” Briedis urged users to be vigilant, as most attacks rely on simple mistakes, stressing that “awareness and a few good habits go a long way” in protecting against these pervasive digital dangers.





