This Fortnight in Cyber Incidents January 21st 2026

Date range: 7 to 21 January 2026

A clear UK focused round up of breaches and cyber incidents reported in the last two weeks. What happened, why it matters, and what to do next.

Westminster and Kensington and Chelsea councils continue recovery and notifications

What happened: Service updates confirm ongoing restoration work after the late November attack on the shared platform. Councils are prioritising critical services, issuing rolling updates, and warning residents about scams during recovery.
Why it matters: Shared environments amplify impact across services and residents. Expect convincing follow on phishing about council tax, benefits and housing.

Inverclyde Council reports incidents affecting education users

What happened: Inverclyde Council disclosed cyber incidents including a compromised education user account and published a parent message on 18 January. Local coverage highlights disruption to school services.
Why it matters: Even a single account compromise can cause widespread disruption across classrooms and parent communications. Identity controls and monitoring are essential.

Higham Lane School reopens after start of term cyber attack

What happened: Higham Lane School in Nuneaton closed for several days while specialists investigated and restored systems. The school has now reopened with staged return and limited IT access while recovery continues.
Why it matters: Education settings hold sensitive pupil and family data but often run lean IT. Early term disruption increases safeguarding and operational risk.

Pax8 partner email error exposes UK MSP commercial data

What happened: Cloud distributor Pax8 mistakenly emailed a spreadsheet to about forty UK partners that exposed business sensitive data relating to around 1,800 MSP customers, including licence counts and renewal dates. No credentials or payment data were included.
Why it matters: Even without personal data, exposure of renewal schedules and portfolios can drive targeted poaching and timed phishing. Treat this as a supplier risk and adjust your renewal processes and comms.

NCSC warns of increased denial of service against UK public services

What happened: The National Cyber Security Centre highlighted continued activity by Russian aligned hacktivist groups targeting public facing services in the UK with denial of service attacks.
Why it matters: Availability attacks disrupt citizen services and can mask other activity. Resilience and rapid mitigation matter even when no data theft is confirmed.

Legal Aid Agency incident hub updated with new guidance

What happened: The Legal Aid Agency updated its cyber incident guidance page on 16 January, providing the latest information for providers and users following last year’s attack on digital services.
Why it matters: Large public sector incidents have long operational tails. Keep an eye on official guidance, temporary processes and data handling instructions during recovery.

Nottinghamshire Police publishes update on data integrity breach investigation

What happened: Nottinghamshire Police issued a 13 January update on a security breach identified by audit, confirming an internal investigation into suspected alteration or deletion of information in a live operation.
Why it matters: Not all breaches are external. Insider and process risks can undermine case data integrity and trust. Monitoring, audit trails and prompt internal action are critical.

What to do this week

  • Level up staff defences with Security Awareness Agency
    Deliver modern awareness training and targeted phishing tests in Microsoft 365 and Teams. Auto enrol new starters and run executive simulations.
  • Stop email borne attacks at the edge
    Deploy advanced email security that blocks business email compromise, credential theft and malicious OAuth consent before it reaches the inbox.
  • Harden identity and access
    Enforce phishing resistant multifactor and conditional access. Remove legacy protocols and review admin roles, guest accounts and third party access. We can implement and manage this for you.
  • Lock down your software as a service and suppliers
    Audit app permissions, rotate tokens and review integrations across Microsoft 365, Google Workspace and Salesforce. Baseline key suppliers and set clear incident duties.
  • Close technical gaps quickly
    Run rapid vulnerability scanning and targeted penetration testing. Prioritise fixes that remove real risk first.
  • Be ready to recover
    Test restores for critical systems, confirm recovery time objectives and rehearse executive and technical playbooks.

Improve your security with us. Contact Cyber Protection UK and Security Awareness Agency today to reduce supplier risk, harden identity and access, stop email threats and build real incident readiness so your organisation stays out of the headlines.

USEFUL LINKS
SERVICES
CONTACT US