# NCSC: state actors behind 75% of UK CNI attacks

Published: 2026-06-17 · Severity: routine · Sectors: infrastructure, energy, government-national, telecommunications, transportation, financial-services
Canonical: https://vorant.io/reports/27731499-a978-5228-9cd4-fb3aedac89a0/ncsc-state-actors-behind-75-of-uk-cni-attacks

> NCSC CEO says hostile states like Russia, China and Iran are linked to roughly three-quarters of over 200 cyber incidents hitting UK critical infrastructure in the past year.

NCSC CEO Dr Richard Horne used the RUSI Annual Security Lecture to disclose that the agency managed over 200 cyber incidents affecting UK critical national infrastructure (CNI) and its supporting ecosystem in the year to May 2026, with around 75% assessed as linked to state actors, naming Russia, China and Iran as key hostile states. The speech was strategic and policy-focused rather than technical, framing cyber security as an ongoing contest rather than a static risk, and calling on organisational leadership to strengthen resilience through three pillars: understanding threat exposure, building defences on security fundamentals, and ensuring operational continuity and rapid recovery after incidents.

Horne warned that unpatched vulnerabilities tolerated in peacetime will be exploited during future conflict, and stated that adversarial cyber activity against the UK is already ongoing rather than purely hypothetical. He also flagged that the NCSC assesses AI-enabled attack capabilities will likely be used by 2028 to exploit known vulnerabilities in legacy technology at scale across CNI, indicating an expected rise in automated, scaled exploitation of already-known flaws rather than novel attack techniques.

No specific incidents, malware, IOCs, or CVEs were disclosed in this speech; it serves as a strategic call to action for CNI operators to prioritise basic security hygiene, patch management, and incident recovery planning ahead of anticipated AI-accelerated threats. Defenders in CNI sectors should treat this as reinforcement to prioritise fundamentals (patching, asset visibility, resilience testing) given the stated intent of state actors and the anticipated scaling of automated exploitation.

## Mentioned in this report

- Threat actors: China-nexus activity (unattributed), Iran-nexus activity (unattributed), Russia-nexus activity (unattributed)

Source reporting: https://www.ncsc.gov.uk/news/ncsc-ceo-hostile-states-linked-to-three-quarters-of-cyber-attacks

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/27731499-a978-5228-9cd4-fb3aedac89a0/ncsc-state-actors-behind-75-of-uk-cni-attacks.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
