This Fortnight in Cyber Incidents November 26th 2025

Date range: 12–26 November 2025

A clear round up of UK focused breaches and security incidents reported in the last two weeks. What happened, why it matters, and what to do next.

Tate galleries job applicants’ data leaked online

What happened: Personal details of 111 applicants for a web developer role were found on an external website. The data included addresses, salary history, referee contacts and other application details. Tate is investigating and has notified the regulator.

Why it matters: Recruitment processes often hold rich personal data. Keep application portals locked down, minimise exports and check that any publishing or transparency steps do not expose attachments.

South Gloucestershire Council publishes residents’ consultation data

What happened: More than 600 residents’ names and contact details were inadvertently exposed in a worksheet that accompanied Local Plan consultation documents. The council removed the file and referred itself to the regulator.

Why it matters: Spreadsheet handling errors remain a common cause of exposure. Use redaction tools, remove hidden sheets and run a second person check before publishing any consultation pack.

Dentsu UK Merkle data security incident

What happened: Dentsu identified unusual activity in the Merkle network and confirmed that files containing staff information were taken. Data points include bank and payroll details, salary information, National Insurance numbers and contact details. Notifications to the ICO and NCSC have been made and affected staff are being offered monitoring.

Why it matters: Payroll and HR systems are prime targets for payment diversion and identity fraud. Tighten approval flows for bank detail changes and monitor for unusual access and mass file activity.

NHS England added to a criminal leak site linked to Oracle E Business Suite claims

What happened: The Clop group listed NHS England on its site while claiming exploitation of Oracle E Business Suite. NHS England has said it is aware of the listing and is investigating. At the time of reporting there was no confirmed public leak of NHS data.

Why it matters: Even before facts are confirmed, listings can drive convincing phishing and social engineering. Prepare holding statements and brief frontline teams so that queries are handled consistently.

Allianz UK named in Oracle E Business Suite extortion campaign

What happened: Allianz UK was listed by the same group that has been extorting organisations running Oracle E Business Suite. Reporting indicates a compromise of that platform and subsequent listing on a leak site.

Why it matters: Enterprise resource planning platforms hold finance and supplier data that criminals can monetise quickly. Patch aggressively, restrict access to admin interfaces and review app to app tokens.

Synnovis London pathology breach investigation concludes

What happened: The NHS supplier behind the major 2024 pathology outage said it has completed an eighteen month investigation and data reconstruction effort. The update confirms the scale and complexity of recovery and ongoing work with affected trusts.

Why it matters: Health sector attacks have long operational tails. Recovery and data assurance can run for many months which must be planned for in contracts and service level discussions with suppliers.

UK policy context moves with new cyber security and resilience bill

What happened: Government introduced a bill on 12 November to expand requirements on essential services and managed providers, including wider incident reporting obligations. While not a breach, it sets the regulatory direction that will follow these incidents.

Why it matters: Expect tougher reporting and oversight of service providers that support the NHS, utilities, transport and other essential services. Contracts and technical controls will need to keep pace.

What to do this week

  • Level up staff defences with Security Awareness Agency
    Deliver modern awareness training and targeted phishing tests in Microsoft 365 and Teams. Move at pace for new starters and high risk roles.
  • Stop email borne attacks at the edge
    Deploy advanced email security that blocks business email compromise, malicious OAuth consent and credential phishing before it reaches the inbox.
  • Harden identity and access
    Enforce phishing resistant multifactor, restrict administrative roles, remove legacy protocols and review guest and supplier access regularly.
  • Lock down your software as a service and suppliers
    Audit app permissions, rotate tokens and review integrations like Oracle E Business Suite, Salesforce and Microsoft 365.
  • Close technical gaps quickly
    Run rapid vulnerability scanning and targeted penetration testing. Prioritise remediation that removes real risk first.
  • Strengthen endpoints and servers
    Use next generation endpoint protection and managed detection and response. Enforce device encryption and application control.
  • Be ready to recover
    Test restores for critical systems, confirm recovery time objectives and rehearse executive and technical playbooks.

Enquire with us to better protect your organisation and avoid headlines. We will help you reduce supplier risk, harden identity and access and build incident readiness that works in the real world.

USEFUL LINKS
SERVICES
CONTACT US