Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Why 2026 World Cup is when AI becomes the interface between fans and football 

      GettyImages 2280946892: Professional meeting with diverse business executives discussing strategies in a modern office set...

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Why 2026 World Cup is when AI becomes the interface between fans and football 

      GettyImages 2280946892: Professional meeting with diverse business executives discussing strategies in a modern office set...

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      Fogo de Chao nominated for Best Casual Dining Toast award

      Fogo de Chão restaurant exterior with vibrant signage and bustling entrance at popular city location

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Tuesday 22 July 2025 8:00 am  |  Updated:  Sunday 20 July 2025 12:15 pm

Fraud risk surges as leaked files expose UK firms

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
law firms, are the "current flavour of the month" for cyberattacks

London’s cyber watchdogs are sounding the alarm over a growing wave of corporate data breaches, as new research reveals the vast majority of leaked datasets now include sensitive financial and personal files, fueling a sharp rise in fraud, cybercrime and reputational risk.

A landmark study published on Tuesday by Lab 1, an AI-driven cybersecurity platform, shows that 93 per cent of data breach incidents now involve financial documents, including bank statements, invoices and IBAN numbers.

Based on an analysis of 141 million leaked files from 1,297 publicly exposed breaches, the report paints a detailed picture of the increasing “blast radius” of cyberattacks on global firms.

The study claims to be the largest content-level analysis of breached datasets ever conducted, offering a granular look at the unstructured data such as emails, HR records, and code files, typically overlooked in traditional breach reviews.

Unlike credential-based dumps, these files often contain sensitive commercial information that can be exploited by fraudsters and attackers to launch follow-up attacks.

Employees and customers caught in the crossfire

Among the most common leaks were HR documents, including payroll information and CVs, found in 82 per cent of breaches.

Customer service records featured in two-thirds of cases, while emails were exposed in 86 per cent.

Notably, half of the incidents included US Social Security Numbers, potentially opening companies up to GDPR violations and regulatory fines under UK and US law.

Lab 1’s chief executive Robin Brattel said the findings mark a shift in how cybercriminals operate.

“They’re behaving like data scientists now – mining these leaks for high value assets that can be used for fraud or targeted attacks,” he said.

The average “blast radius” – a measure of how many organisations are indirectly exposed in each breach – has risen 61 per cent since 2022, the report shows.

On average, data from one incident is now linked to over 400 organisations, including partners and vendors, often without their knowledge.

Read more

ThetaRay Gamifies Financial Defense at Money20/20 Europe with a Compliance Twist on “Where’s Waldo”

Retail sector on the edge

The findings land amid growing unease in the UK retail sector following a series of high profile cyberattacks this spring.

Co-op confirmed earlier this week that the personal data of all 6.5 million of its members was accessed during an April hack, despite no financial information being compromised.

The retail giant’s chief executive, Shirine Khoury-Haq, called the breach “deeply personal” and warned the fallout had been significant.

That attack, which law enforcement believes was part of a wider coordinated campaign also targeting M&S and Harrods, resulted in disruption to contactless payments and customer service across Co-op stores.

Four suspects have since been arrested, including three teenagers.

M&S, which suffered operational losses estimated at £300m, is now preparing a £100m insurance claim.

But not all affected retailers had cyber insurance cover in place, potentially leaving them exposed to costly litigation and long-term brand damage.

Intensifying cyber threats

The Lab 1 study follows closely on the heels of another breach involving 16 billion login credentials, widely circulated across criminal forums earlier this month.

Though not the result of a single hack, the trove includes data scraped from malware known as “infostealers” and raises fresh questions about the viability of current password-based authentication systems.

Cybersecurity analysts have warned that such datasets give criminals the tools to carry out highly convincing phishing attacks and identity fraud at scale, particularly when combined with leaked unstructured data like HR files or internal emails.

With businesses under pressure to improve breach detection and response, Brattel says the focus needs to shift.

“It’s not just about stopping the breach. It’s about knowing what’s been leaked, who’s at risk, and how fast you can act before that data is turned against you”, he said.

Read more

cTAP Announces Novel Prognostic Score Developed for Duchenne Muscular Dystrophy Patients Offers Improved Prediction of Loss of Ambulation

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • anti fraud
  • Cyber
  • cyber attacks
  • fraud
  • leaked files
  • Marks and Spencer

Trending Articles

  • FTSE 100 Live: Pound dips and stocks slip as Andy Burnham victory triggers political uncertainty

  • Kaleb Cooper: Brits don’t care about the price of milk 

  • Judge rejects Gatwick Airport bid to block new relaxed runway slot rules

  • PwC UK chief swipes global role in international shake-up

  • Inheritance tax enquiries surge to six-year high after HMRC clampdown

More from CityAM

  • ThetaRay Gamifies Financial Defense at Money20/20 Europe with a Compliance Twist on “Where’s Waldo”

    Business Wire
  • cTAP Announces Novel Prognostic Score Developed for Duchenne Muscular Dystrophy Patients Offers Improved Prediction of Loss of Ambulation

    Business Wire
  • Smarsh Advances Compliance with AI Technologies That Cut Noise and Expose Risk Earlier

    Business Wire
  • NHS gives Palantir wider access to patient data amid growing backlash

    Tech
    NHS healthcare professionals in a hospital setting discussing patient care plans, wearing uniforms and medical equipment v...
  • Smarsh Introduces New Anthropic Integration to Capture and Govern Claude Enterprise Data Within Its Platform

    Business Wire
  • KRM22 partners with Sigma AI to enhance market surveillance and risk intelligence capabilities

    Business Wire
  • Visa data leak piles pressure on Britain’s digital ID push

    Tech
    UK work and study visas have fallen as Labour faces pressure to reduce immigration.
  • Key Mandelson file withheld by Cabinet

    Politics
    Lord Mandelson giving a speech at a business conference, addressing economic policies and industry challenges.

CityAM Canada — business, markets and opinion for Canadian readers.

Sections

  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities

Company

  • About
  • Contact

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 CityAM Canada. All rights reserved.
Terms · Privacy · Cookies