State-sponsored cyber attacks are no longer a distant, government-only concern. They now shape the risk register of ordinary UK businesses, from energy suppliers to mid-sized manufacturers, whether or not those businesses have ever thought of themselves as a target of a cyber attack. The National Cyber Security Centre (NCSC) recorded 429 incidents needing its support between September 2024 and August 2025, and nearly half were classed as nationally significant, a marked jump on the year before.
This guide sets out what state-sponsored cyber attacks are, who is behind them, and why the distinction between a nation-state operation and ordinary cybercrime matters. It also covers the emerging cyber insurance gap facing UK organisations, the practical question of whether a smaller business could really be targeted, and the steps that build genuine resilience rather than false confidence. Throughout, the focus is on what this means specifically for UK and Ireland-based organisations, not just the global picture.
Table of Contents
What Is a State-Sponsored Cyber Attack?
A state-sponsored cyber attack is a digital operation carried out, funded or directed by a national government, usually through military or intelligence agencies, against another country’s government, infrastructure, businesses or citizens. Unlike ordinary cybercrime, the goal is rarely a quick payday, but espionage, disruption, or long-term strategic advantage.
Distinguishing Nation-States from Cybercriminals
The two are often confused in media coverage, but the difference matters enormously for how an organisation should respond. A criminal gang wants money and will often negotiate. A state-sponsored group wants access, information or disruption, and negotiation is rarely on the table because the cyber attacker’s government isn’t going to be discouraged by a company’s incident response plan. Recognising the difference early can determine whether an incident is a contained criminal extortion attempt or the opening stage of a longer state-sponsored cyber attack.
| Factor | Ordinary Cybercrime | State-Sponsored Cyber Attack |
|---|---|---|
| Motivation | Financial gain | Espionage, disruption, geopolitical advantage |
| Resources | Limited, though increasingly professionalised | Extensive, often near-unlimited state backing |
| Stealth | Often noisy (ransom notes, extortion demands) | Typically covert, designed to avoid detection for months or years |
| Primary targets | Any organisation with exploitable data or systems | Government, critical infrastructure, defence, and firms with sensitive intellectual property or supply chain access |
| Typical duration | Days to weeks | Months to years (advanced persistent threats) |
State-sponsored cyber attacks are frequently described using the term advanced persistent threat, or APT. This is not marketing language. It describes a genuine operational pattern: cyber attackers who get into a network and stay there, moving carefully, gathering intelligence, and avoiding the kind of noisy behaviour that would trigger an alert. Some APT groups have reportedly remained inside a target’s systems for years before being discovered.
What Do State-Sponsored Cyber Attackers Want? The Objectives Explained
Before looking at who is behind these cyber attacks, it helps to be direct about what they are actually trying to achieve, since this is one of the most searched questions on the topic and rarely gets answered clearly. State-sponsored cyber attackers generally pursue one or more of four objectives.
Espionage is the most common motive. This means quietly extracting information: government communications, defence research, or commercially sensitive intellectual property that would take a rival state years and billions of pounds to develop independently. Disruption is the second objective, where cyber attackers aim to degrade or take down services such as power grids, hospitals or transport systems, either as a direct act of aggression or as a demonstration of capability.
Financial gain sits alongside these for some states. North Korean state-linked groups, for example, are widely reported to target cryptocurrency exchanges and use fraudulent remote IT worker schemes to generate revenue for the regime. Finally, influence operations use compromised systems and stolen data to spread disinformation or manipulate public opinion, particularly around elections.
It’s worth being clear that these objectives frequently overlap in a single campaign. A cyber attacker might begin with espionage, then use the access gained to prepare a disruptive capability that can be triggered later if geopolitical tensions escalate.
The Big Four Behind State-Sponsored Cyber Attacks
Most public attribution of state-sponsored cyber attacks against the UK points to a small group of countries, generally referred to in security reporting as the “Big Four”. Understanding what each is currently doing helps explain why organisations of very different sizes and sectors have been affected.
According to the NCSC’s most recent Annual Review, China, Russia, Iran and North Korea remain the states posing the greatest cyber threat to the UK. China-linked group Flax Typhoon has been linked to multiple attacks on UK organisations, generally focused on espionage and on gaining a persistent foothold in networks rather than immediate disruption. Russia-linked activity in the same period included malware known as Authentic Antics, which steals login credentials and authentication tokens to give cyber attackers long-term access to victims’ email accounts, a technique that supports both espionage and future disruptive operations.
Iran’s state-sponsored cyber attacks have concentrated on its immediate geopolitical priorities. Throughout 2025, the NCSC assessed that Iran was highly likely to be directing cyber attacks in support of its position in the Iran-Israel conflict, with UK critical infrastructure assessed as a plausible target given the country’s close alignment with US and allied interests.
North Korea takes a distinctly different approach, driven largely by the need to fund a heavily sanctioned economy. Its state-linked actors are known for indiscriminately targeting cryptocurrency firms and for placing operatives inside Western companies through fake remote IT worker schemes, channelling salaries and access back to the regime.
It would be a mistake to assume the cyber attack threat is limited to these four. The NCSC has also noted that the global commercial cyber intrusion market, where private firms develop and sell hacking tools to governments, is expanding, meaning a wider range of states are gaining access to capabilities that were previously the preserve of a handful of major powers.
How Are State-Sponsored Cyber Attacks Attributed?
One of the most common and least satisfactorily answered questions about state-sponsored cyber attacks is how anyone actually proves who was behind one. Competitors on this topic tend to say attribution is “difficult” without explaining what that process involves, so it’s worth setting out properly.
Security researchers commonly use a framework called the Diamond Model of Intrusion Analysis, which examines four connected elements of any attack: the adversary carrying it out, the capability or malware used, the infrastructure it runs on, and the victim it targets. By comparing these elements against attacks with known origins, analysts can build a technical picture of who is likely responsible, based on shared code, reused infrastructure, or consistent operational habits.
This technical evidence is only part of the picture, though. Governments also weigh political and geopolitical context, such as whether an attack aligns with a state’s known strategic interests, before making a public attribution.
This combination of technical and political judgment is exactly why attribution disputes over state-sponsored cyber attacks happen so often. The UK government’s March 2024 attribution of the 2021 Electoral Commission breach to the China-linked group APT31, discussed further below, took place nearly three years after the attack began, illustrating how long proper attribution can take even when investigators are confident of the answer.
Why Your Organisation Might Be a Target of a State-Sponsored Cyber Attack
Many UK businesses assume state-sponsored cyber attacks are a problem for central government and large multinationals alone. That assumption is increasingly wrong, and understanding the three main reasons an organisation becomes a target is the first step towards proportionate defence.
Critical National Infrastructure in the UK and Ireland
Energy, water, healthcare and transport providers sit at the top of most nation-state target lists because disrupting them causes visible, high-impact consequences. The UK’s own experience with the WannaCry cyber attack in 2017 remains the clearest illustration. Although not specifically targeted at the NHS, the ransomware disrupted at least 34% of NHS trusts in England and led to 6,912 cancelled appointments and operations, according to the National Audit Office’s investigation.
Security researchers have linked the malware to North Korea’s Lazarus Group, though the NAO itself noted the attack lacked some of the hallmarks of a coordinated state campaign, a useful reminder that attribution isn’t always clean cut even in well-documented cases.
Ireland faces a parallel exposure through its position as a major European hub for data centres and cloud infrastructure. Disruption to this sector would have consequences that extend well beyond Ireland’s borders, which is part of why NCSC-IE, Ireland’s National Cyber Security Centre, works closely with its UK counterpart on shared threat intelligence.
Intellectual Property Theft and Economic Espionage
Not every target is critical infrastructure. Universities, pharmaceutical firms, defence contractors and technology companies hold research and designs that would cost a rival state years and enormous sums to develop from scratch. Quietly extracting that work is, from a cyber attacker’s perspective, a far cheaper route to the same result.
Supply Chain Attacks: The Modern Route In
Smaller organisations frequently believe their size makes them uninteresting to a nation-state actor. In reality, a small supplier with weaker defences and a trusted digital connection into a larger client’s network can be exactly what a patient cyber attacker is looking for.
This is one reason DSIT’s Cyber Security Breaches Survey continues to flag supply chain risk management as an area where UK organisations, particularly outside the largest businesses, still fall short. If your organisation has any digital connection to a larger client, a government body, or critical infrastructure, that connection alone can make you a target for compromise, regardless of your own size.
State-Sponsored Cyber Attacks and Insurance: The “Act of War” Question
For UK risk and finance leaders, one of the least understood consequences of the state-sponsored cyber attack threat sits not in IT but in the insurance policy. Since 2022, Lloyd’s of London has required standalone cyber insurance policies underwritten in its market to include a clause excluding cover for losses arising from state-backed cyber attacks, separate from any traditional war exclusion.
The requirement has been tightened several times since, most recently restricting which policies can offer any exemption for cyber attacks carried out as part of a conventional war. In practice, this means that if a cyber attack affecting your organisation is later attributed to a nation-state, your insurer may have grounds to decline the claim entirely.
This is not a theoretical risk. When pharmaceutical company Merck was hit by the 2017 NotPetya cyberattack, a state-linked operation that caused more than 10 billion dollars in damage globally after spreading from Ukraine, its insurers initially refused to cover around 1.4 billion dollars in losses, citing a war exclusion.
US courts ruled in Merck’s favour, finding that the war exclusion wording did not extend to a cyber attack of this kind, and the dispute was ultimately settled confidentially before reaching the state Supreme Court. The exclusion clauses now standard across the London market are written specifically to close that gap, which means UK organisations can no longer assume a similarly favourable outcome if a comparable dispute arose today.
The practical difficulty, as insurers themselves acknowledge, is attribution. A policy exclusion that depends on proving a nation-state was responsible runs straight into the attribution challenges described earlier in this guide. Insurers are increasingly cautious about state-sponsored cyber attacks precisely because the potential losses are far larger than those in an ordinary cybercrime claim.
Organisations should review their current cyber policy wording carefully, understand exactly how their insurer defines and attributes a state-backed cyber attack, and treat cyber insurance as one layer of protection rather than a guaranteed safety net against this specific category of loss.
Building Resilience Against State-Sponsored Cyber Attacks
Complete prevention against a well-resourced state actor is not a realistic goal for any single organisation, however well defended. What is realistic, and what UK regulators and the NCSC increasingly emphasise, is operational resilience, meaning the ability to keep functioning, or recover quickly, when a cyber attack does succeed.
Moving from Perimeter Defence to Assume Breach
Traditional security focused heavily on keeping cyber attackers out. The current approach, reflected throughout the NCSC’s guidance, assumes that a sufficiently determined and resourced cyber attacker will eventually get in, and designs systems to limit the damage when that happens. This mindset matters particularly for state-sponsored cyber attacks, where the attacker’s resources make outright prevention unrealistic for most organisations.
NCSC chief executive Richard Horne made this point directly in the 2025 Annual Review, warning that any leader who fails to prepare for a serious cyber incident is jeopardising their organisation’s future. Practical steps include network segmentation so a single compromised account cannot reach everything, multi-factor authentication on all accounts, regular offline backups, and incident response plans that are actually tested rather than simply filed away.
Threat Intelligence for Mid-Market Businesses
Large enterprises and government bodies typically run dedicated threat intelligence functions. Mid-market UK businesses rarely have that budget, but they are not without options. The NCSC’s free Early Warning service flags known malicious activity connected to an organisation’s own systems, and joining an information-sharing community relevant to your sector can provide advance notice of the tactics currently being used against similar organisations. Combined with the basics, patched systems, staff phishing awareness, and a rehearsed response plan, this puts mid-sized organisations in a considerably stronger position without requiring their own security operations centre.
State-sponsored cyber attacks are not a hypothetical, future problem for UK organisations. They are already shaping insurance markets, national infrastructure policy, and the day-to-day risk decisions of businesses that never expected to be caught up in geopolitics. The organisations that fare best are rarely the ones that achieve perfect prevention. They are the ones that understand who might target them and why, read their insurance policies before a claim is disputed, and build the kind of operational resilience that keeps the business running when, not if, a cyber attack occurs.
For further reading on the wider cybercrime picture facing UK organisations, see our guide to cyber security facts and statistics, our overview of cybercrime statistics and news, and our full cyber attacks category. Smaller organisations concerned about supply chain exposure may also find our guide to antivirus software for small businesses useful, alongside our separate look at the security implications of 5G technology.
Frequently Asked Questions
Which countries are the biggest cyber threats to the UK?
According to the NCSC’s most recent Annual Review, China, Russia, Iran and North Korea are the states most frequently linked to state-sponsored cyber attacks against the UK, though each pursues different objectives, ranging from espionage and long-term network access to revenue generation and support for wider geopolitical conflicts.
Is my business too small to be targeted by a nation-state?
Not necessarily. Smaller organisations are sometimes targeted directly for the data or access they hold, but more often, they are used as a stepping stone into a larger client, government body, or piece of critical infrastructure they are connected to. Any digital relationship with a bigger or more sensitive target is a reason to take the risk seriously, regardless of your own size.
Will my cyber insurance cover a state-sponsored cyber attack?
Not automatically. Since 2022, Lloyd’s of London has required standalone cyber policies to include an exclusion for state-backed attacks, separate from any war exclusion, and this requirement has been tightened further in subsequent years. Whether a specific incident falls under that exclusion often depends on formal government attribution, which can take months or years, so organisations should read their policy wording closely rather than assume they are covered.
How do I know if a cyber attack against my organisation is state-sponsored?
There is rarely a single clear signal, but indicators include cyber attackers who remain undetected for unusually long periods, tools and techniques that match those of known advanced persistent threat groups, and an apparent interest in information or access rather than an immediate ransom demand. Formal attribution is a slow process usually carried out by government agencies rather than the affected organisation itself.
What is an advanced persistent threat?
An advanced persistent threat, or APT, describes a state-sponsored or state-aligned group that gains long-term, covert access to a target’s systems, often remaining undetected for months or years while gathering intelligence or preparing for future disruption, rather than acting quickly for immediate financial gain.
What should I do if I suspect a nation-state is targeting my organisation?
Contact the NCSC promptly, since it can offer specialist guidance even to organisations without a formal relationship with government. Alongside this, engage an incident response specialist, preserve evidence rather than immediately wiping affected systems, and review your cyber insurance policy to understand what attribution might mean for any claim.