Last reviewed: Next review due:
What is the cybercrime beat?
Cybercrime reporting covers ransomware attacks on companies and public services, data breaches and the ICO enforcement that follows them, fraud at national scale, the law enforcement response led by the National Crime Agency and regional cyber units, and the defensive work of the National Cyber Security Centre. It sits at the junction of crime, technology, and business reporting: a single ransomware incident can be simultaneously a criminal investigation, a regulatory matter, a corporate governance failure, and a public services story.
It is also a beat with unusual legal exposure for the reporter. The Computer Misuse Act 1990 has no public interest defence, so how you verify a breach matters as much as whether the story is true. The craft lies in extracting reliable facts from an ecosystem of criminals who lie for leverage, victims who minimise, and researchers of highly variable rigour — while never becoming a distribution channel for stolen personal data.
Responsible disclosure conventions matter here too: security researchers normally report vulnerabilities privately to vendors and allow time for a fix before publication. Understanding that etiquette helps you judge both a researcher who bypassed it and a vendor that sat on a warning — and it should inform your own decisions about when publishing technical detail would put users at avoidable risk.
Why this beat matters
- 1Fraud and computer misuse account for a substantial share of all crime measured by the Crime Survey for England and Wales, yet receive a fraction of the coverage given to traditional crime — the gap between prevalence and attention is itself the story.
- 2Ransomware attacks on hospitals, councils, schools, and suppliers disrupt real public services, turning an abstract technical subject into concrete local accountability reporting.
- 3Data breaches expose readers' own personal information, and ICO enforcement action creates a public record of which organisations failed to protect it.
- 4Attribution, sanctions, and the ethics of ransom payment are live policy debates in which reporting choices — what to amplify, what to withhold — have direct consequences.
- 5The legal risks to journalists handling leaked and hacked material are real and poorly understood, and newsroom practice on this beat sets precedents for investigative journalism generally.
The regulatory landscape
National Cyber Security Centre (NCSC)
Part of GCHQ and the UK's technical authority on cyber security. Publishes incident guidance, threat advisories, and an Annual Review describing the incidents it has handled — the most authoritative on-the-record UK source for major incidents.
National Crime Agency (NCA)
Leads the law enforcement response to serious cybercrime through its National Cyber Crime Unit, running investigations, international takedowns, and disruption operations against ransomware groups and criminal marketplaces.
City of London Police / Action Fraud
The national lead force for fraud, operating Action Fraud as the UK's reporting centre for fraud and cybercrime. Its data measures reports, not prevalence — a caveat every story should carry.
Information Commissioner's Office (ICO)
Enforces data protection law, receives mandatory breach notifications, and publishes enforcement action including fines and reprimands against organisations that failed to secure personal data.
Office of Financial Sanctions Implementation (OFSI)
Part of HM Treasury, enforcing financial sanctions — including designations of individuals linked to ransomware — which can make facilitating a ransom payment itself unlawful.
Crown Prosecution Service (CPS)
Prosecutes Computer Misuse Act offences in England and Wales and publishes charging guidance; Scotland prosecutes via the Crown Office and Procurator Fiscal Service under its own arrangements.
UK public datasets for cybercrime reporters
Measurement caveats matter on this beat: survey data estimates prevalence, reporting-centre data counts only what victims report, and vendor threat reports serve marketing goals. State which kind of number you are quoting, every time.
FOI ideas for cybercrime reporters
Note: expect section 31 (law enforcement) and section 24 (national security) exemptions when asking about live incidents or defensive capability. Requests about the fact, cost, and recovery of past incidents fare far better than requests about how systems were compromised. Private companies are outside FOIA — go to the public bodies they serve or the regulators that oversee them.
- Number of ransomware or significant cyber incidents recorded in the past three years, with recovery costs and whether personal data was affected (named local authority)
- Cyber incident reports, downtime, and remediation spending following any attack on trust systems (named NHS trust)
- Personal data breach notifications submitted to the ICO by the organisation in the past two years, in aggregate (named public body)
- Outcomes of reports referred by Action Fraud to the force for investigation, by category (City of London Police or named police force)
- Staffing levels and caseloads of the force cybercrime unit over the past five years (named police force)
- Spending on cyber security insurance and any claims made following incidents (named local authority)
- Incidents of unauthorised access to school or trust systems, including exam or coursework data (named academy trust)
Key UK organisations and contacts
Interview question bank
Remember that many commercial security sources have a product to sell and an incentive to inflate threats — ask every researcher what their evidence is and what interest their firm has in the story. Never ask a source to access a system, account, or dataset on your behalf: soliciting unauthorised access can implicate you in a Computer Misuse Act offence.
For Breached organisations and their spokespeople
- When did you first become aware of the incident, and when did you notify the ICO and affected individuals?
- What categories of personal data were accessed or exfiltrated?
- Has a ransom demand been received, and what is your position on payment?
- What independent forensic work has been done, and will its findings be published?
For Law enforcement and NCSC
- Is this incident linked to a known group or campaign you are already tracking?
- What support is being provided to the victim organisation and to affected individuals?
- What is the realistic prospect of arrests given the actors are likely overseas?
For Security researchers and analysts
- What is the actual evidence behind this attribution, and how confident are you in it?
- Have you verified the leak-site claims against real data, and how?
- What financial or commercial interest does your firm have in this incident being covered?
Jargon glossary
Story ideas and angles
- FOI every council in your region for ransomware incidents, recovery costs, and data loss over three years — build the local picture no national dataset shows.
- Track an ICO enforcement notice back to the original breach and test whether the organisation's public statements at the time matched what the regulator later found.
- Follow up a high-profile attack six months on: what did recovery actually cost, and what has the victim changed?
- Compare Crime Survey prevalence estimates for fraud with your local force's investigative capacity via FOI on cybercrime unit staffing.
- Investigate how schools and academy trusts in your patch handle attacks during exam season, using FOI and inspection records.
- Examine the cyber insurance market's role in ransom decisions through RUSI research and industry interviews.
- Report on the human cost of fraud through victim support organisations — romance and investment fraud victims are chronically under-covered.
- Scrutinise a vendor's breach research before covering it: what data underpins the headline claim, and does independent verification exist?
Pitch angles
Cybercrime pitches land best when they translate technical incidents into services, money, and accountability readers recognise. Try:
- Public services: “What the ransomware attack on [public body] actually cost — and who is still waiting for services to recover.”
- Accountability: “The regulator says [organisation] failed to fix known weaknesses before the breach. Its statements at the time said something different.”
- Data-led: “We asked every council in the region about cyber attacks. Here is what they admitted — and what they refused to say.”
- Human impact: “Fraud is among the most common crimes in the country. Meet the victims the system leaves behind.”