Skip to main content

Cybercrime Reporting in Depth: NCSC, NCA & Ransomware

From NCSC incident advisories to ransomware leak sites: a practical guide to covering cybercrime in the UK without breaking the Computer Misuse Act, amplifying extortion, or republishing stolen data.

Last reviewed: Next review due:

What is the cybercrime beat?

Cybercrime reporting covers ransomware attacks on companies and public services, data breaches and the ICO enforcement that follows them, fraud at national scale, the law enforcement response led by the National Crime Agency and regional cyber units, and the defensive work of the National Cyber Security Centre. It sits at the junction of crime, technology, and business reporting: a single ransomware incident can be simultaneously a criminal investigation, a regulatory matter, a corporate governance failure, and a public services story.

It is also a beat with unusual legal exposure for the reporter. The Computer Misuse Act 1990 has no public interest defence, so how you verify a breach matters as much as whether the story is true. The craft lies in extracting reliable facts from an ecosystem of criminals who lie for leverage, victims who minimise, and researchers of highly variable rigour — while never becoming a distribution channel for stolen personal data.

Responsible disclosure conventions matter here too: security researchers normally report vulnerabilities privately to vendors and allow time for a fix before publication. Understanding that etiquette helps you judge both a researcher who bypassed it and a vendor that sat on a warning — and it should inform your own decisions about when publishing technical detail would put users at avoidable risk.

Why this beat matters

  • 1Fraud and computer misuse account for a substantial share of all crime measured by the Crime Survey for England and Wales, yet receive a fraction of the coverage given to traditional crime — the gap between prevalence and attention is itself the story.
  • 2Ransomware attacks on hospitals, councils, schools, and suppliers disrupt real public services, turning an abstract technical subject into concrete local accountability reporting.
  • 3Data breaches expose readers' own personal information, and ICO enforcement action creates a public record of which organisations failed to protect it.
  • 4Attribution, sanctions, and the ethics of ransom payment are live policy debates in which reporting choices — what to amplify, what to withhold — have direct consequences.
  • 5The legal risks to journalists handling leaked and hacked material are real and poorly understood, and newsroom practice on this beat sets precedents for investigative journalism generally.

The regulatory landscape

National Cyber Security Centre (NCSC)

Part of GCHQ and the UK's technical authority on cyber security. Publishes incident guidance, threat advisories, and an Annual Review describing the incidents it has handled — the most authoritative on-the-record UK source for major incidents.

National Crime Agency (NCA)

Leads the law enforcement response to serious cybercrime through its National Cyber Crime Unit, running investigations, international takedowns, and disruption operations against ransomware groups and criminal marketplaces.

City of London Police / Action Fraud

The national lead force for fraud, operating Action Fraud as the UK's reporting centre for fraud and cybercrime. Its data measures reports, not prevalence — a caveat every story should carry.

Information Commissioner's Office (ICO)

Enforces data protection law, receives mandatory breach notifications, and publishes enforcement action including fines and reprimands against organisations that failed to secure personal data.

Office of Financial Sanctions Implementation (OFSI)

Part of HM Treasury, enforcing financial sanctions — including designations of individuals linked to ransomware — which can make facilitating a ransom payment itself unlawful.

Crown Prosecution Service (CPS)

Prosecutes Computer Misuse Act offences in England and Wales and publishes charging guidance; Scotland prosecutes via the Crown Office and Procurator Fiscal Service under its own arrangements.

UK public datasets for cybercrime reporters

Measurement caveats matter on this beat: survey data estimates prevalence, reporting-centre data counts only what victims report, and vendor threat reports serve marketing goals. State which kind of number you are quoting, every time.

FOI ideas for cybercrime reporters

Note: expect section 31 (law enforcement) and section 24 (national security) exemptions when asking about live incidents or defensive capability. Requests about the fact, cost, and recovery of past incidents fare far better than requests about how systems were compromised. Private companies are outside FOIA — go to the public bodies they serve or the regulators that oversee them.

  • Number of ransomware or significant cyber incidents recorded in the past three years, with recovery costs and whether personal data was affected (named local authority)
  • Cyber incident reports, downtime, and remediation spending following any attack on trust systems (named NHS trust)
  • Personal data breach notifications submitted to the ICO by the organisation in the past two years, in aggregate (named public body)
  • Outcomes of reports referred by Action Fraud to the force for investigation, by category (City of London Police or named police force)
  • Staffing levels and caseloads of the force cybercrime unit over the past five years (named police force)
  • Spending on cyber security insurance and any claims made following incidents (named local authority)
  • Incidents of unauthorised access to school or trust systems, including exam or coursework data (named academy trust)

Key UK organisations and contacts

NCSC Press Office
National incident response and threat assessment — the authoritative line on major UK incidents.
NCA Press Office
Investigations, arrests, and international disruption operations against cybercrime groups.
ICO Press Office
Breach notifications, investigations, and enforcement against organisations that lost personal data.
City of London Police
National lead force for fraud and home of Action Fraud reporting data.
OFSI (HM Treasury)
Sanctions designations and the legality of payments touching sanctioned ransomware actors.
UK Finance
Banking trade body publishing regular industry data on payment fraud and scams.
RUSI
Security think tank with published research on ransomware policy, cyber insurance, and the payment debate.
CyberUp Campaign
Campaign for Computer Misuse Act reform — useful on how the current law affects researchers and journalists.

Interview question bank

Remember that many commercial security sources have a product to sell and an incentive to inflate threats — ask every researcher what their evidence is and what interest their firm has in the story. Never ask a source to access a system, account, or dataset on your behalf: soliciting unauthorised access can implicate you in a Computer Misuse Act offence.

For Breached organisations and their spokespeople

  • When did you first become aware of the incident, and when did you notify the ICO and affected individuals?
  • What categories of personal data were accessed or exfiltrated?
  • Has a ransom demand been received, and what is your position on payment?
  • What independent forensic work has been done, and will its findings be published?

For Law enforcement and NCSC

  • Is this incident linked to a known group or campaign you are already tracking?
  • What support is being provided to the victim organisation and to affected individuals?
  • What is the realistic prospect of arrests given the actors are likely overseas?

For Security researchers and analysts

  • What is the actual evidence behind this attribution, and how confident are you in it?
  • Have you verified the leak-site claims against real data, and how?
  • What financial or commercial interest does your firm have in this incident being covered?

Jargon glossary

Ransomware
Malware that encrypts a victim's systems, with the criminals demanding payment for restoration — now usually paired with data theft for added leverage.
Double extortion
The tactic of stealing data before encrypting systems, so victims can be threatened with publication even if they restore from backups.
Leak site
A criminal-run website, typically on the dark web, where ransomware groups name victims and publish stolen data to pressure payment.
CVE
A Common Vulnerabilities and Exposures identifier — the standard reference for a publicly disclosed software flaw, enriched with severity scoring in the NVD.
Zero-day
A vulnerability exploited before the vendor knows about it or has released a fix — rarer and more significant than routine exploitation of unpatched systems.
Responsible disclosure
The convention of privately reporting a vulnerability to the vendor and allowing time for a fix before publication — context for judging both researchers and reluctant vendors.
Business email compromise (BEC)
Fraud built on impersonating executives or suppliers by email to redirect payments — consistently among the most costly fraud categories.
Initial access broker
A criminal who compromises networks and sells that access to other groups, including ransomware operators — part of the service economy behind attacks.

Story ideas and angles

  • FOI every council in your region for ransomware incidents, recovery costs, and data loss over three years — build the local picture no national dataset shows.
  • Track an ICO enforcement notice back to the original breach and test whether the organisation's public statements at the time matched what the regulator later found.
  • Follow up a high-profile attack six months on: what did recovery actually cost, and what has the victim changed?
  • Compare Crime Survey prevalence estimates for fraud with your local force's investigative capacity via FOI on cybercrime unit staffing.
  • Investigate how schools and academy trusts in your patch handle attacks during exam season, using FOI and inspection records.
  • Examine the cyber insurance market's role in ransom decisions through RUSI research and industry interviews.
  • Report on the human cost of fraud through victim support organisations — romance and investment fraud victims are chronically under-covered.
  • Scrutinise a vendor's breach research before covering it: what data underpins the headline claim, and does independent verification exist?

Pitch angles

Cybercrime pitches land best when they translate technical incidents into services, money, and accountability readers recognise. Try:

  • Public services: “What the ransomware attack on [public body] actually cost — and who is still waiting for services to recover.”
  • Accountability: “The regulator says [organisation] failed to fix known weaknesses before the breach. Its statements at the time said something different.”
  • Data-led: “We asked every council in the region about cyber attacks. Here is what they admitted — and what they refused to say.”
  • Human impact: “Fraud is among the most common crimes in the country. Meet the victims the system leaves behind.”

Recommended tools

Related guides

Primary sources

Frequently asked questions

Can I legally examine leaked or hacked data as a UK journalist?
With real care. The Computer Misuse Act 1990 criminalises unauthorised access to computer material (section 1), unauthorised acts impairing a computer (section 3), and obtaining or supplying articles for use in such offences (section 3A) — and it contains no public interest defence. Receiving and analysing a dataset someone else exfiltrated is legally different from accessing a system yourself, but logging into leaked accounts, using stolen credentials, or probing a company's systems to verify a breach can all cross the line. Take legal advice before touching live systems, document your public interest reasoning, and never solicit or direct a hack.
How should I cover a ransomware attack without helping the criminals?
Ransomware groups use media coverage as leverage: their leak sites exist to pressure victims into paying. Report the incident and its impact on services, but avoid uncritically amplifying the gang's claims about what data it holds, avoid linking directly to leak sites or stolen files, and never republish stolen personal data. Verify claims independently — victims, regulators, and security researchers can often confirm or contradict what a gang asserts, and gangs routinely exaggerate. Name the group where it is editorially relevant, but frame its statements as claims by criminals, not established fact.
What does OFSI sanctions designation mean for ransomware coverage?
The UK has sanctioned individuals linked to ransomware operations, and the Office of Financial Sanctions Implementation enforces the resulting asset freezes. For journalists the practical point is that facilitating a ransom payment to a sanctioned entity can itself breach sanctions law, which sharpens the story when a victim is weighing payment. Sanctions designations are published and quotable, and they give you a documented, on-the-record basis for attributing an operation to named individuals — far safer ground than repeating attribution claims from anonymous researchers. Check the OFSI consolidated list when a group is named in your story.
Where do reliable UK cybercrime and fraud statistics come from?
The Crime Survey for England and Wales, published by the Office for National Statistics, includes fraud and computer misuse modules and is the best measure of prevalence because most incidents are never reported to police. Action Fraud, run by the City of London Police, is the national reporting centre, and its figures measure reports rather than true prevalence — a distinction worth making explicit in copy. The NCSC Annual Review describes the incidents it handled at the national level. Scotland is covered separately by Police Scotland and the Scottish Crime and Justice Survey, so state your jurisdiction.
How do I verify a hacker's claims without republishing stolen data?
Treat a breach claim like any other unverified tip. Ask the alleged victim organisation directly and give it meaningful time to respond; check whether the ICO has been notified, since serious personal data breaches must be reported to it; consult independent security researchers who can inspect samples without you distributing them; and look for corroboration such as affected customers receiving notification letters. If you must reference sample data to establish credibility, describe its nature generically rather than publishing records, and strip anything that identifies individuals. Fabricated and recycled breach claims are common, and running one uncritically hands criminals free leverage.

Related guides