FOI reference: FOI-2026-3623
You asked
Under the Freedom of Information Act 2000, please provide the following:
The number of malicious e-mails sent to your organisation that were blocked by your systems, for each of 2022, 2023, 2024 and 2025.
The number of Distributed Denial of Service (DDoS) attempts made against websites run by your organisation that were blocked or repelled, for each of 2022, 2023, 2024 and 2025.
The number of confirmed cyber security incidents in which a malicious actor gained unauthorised access to your systems, for each of 2022, 2023, 2024 and 2025.
The number of ransomware attempts detected against your systems, for each of 2022, 2023, 2024 and 2025, and how many, if any, resulted in a successful attack.
Whether staff phishing simulation tests have been run in each of those years and, if so, what percentage of staff clicked the simulated phishing link or otherwise failed the test.
We said
Thank you for your request.
Q1. The number of malicious e-mails sent to the organisation is only retained for 30 days, therefore we do not hold the information requested for 2022 to 2025.
Q2. During the period 2022 to 2025 there have been two Distributed Denial of Service (DDoS) attempts made against websites. One attempt was made in 2024 and two attempts in 2025. All attempts were mitigated by defensive counter measures.
Qs 3 and 5. We are unable to disclose the information requested in questions 3 and 5 of your request as this would pose a risk to our organisation’s ability to defend itself from malicious attacks by exposing possible vulnerabilities. As such, disclosure would prejudice the prevention or detection of crime and the exemption found under s.31(1)(a) of the Freedom of Information Act 2000 (FOIA) is engaged.
This exemption is subject to a public interest test. We recognise that releasing this information would aid transparency and accountability of the ONS, particularly regarding the security of the data we hold. However, we see greater value in the inherent public interest in crime prevention. ONS holds a large number of records containing sensitive personal information about business and individuals and we take our duty to safeguard this information very seriously. There is a strong public interest in preventing the disclosure of any information that would increase the possibility of a successful attack, which has the potential to cause emotional and financial distress and a loss of public trust in the ONS. The public interest test falls in favour of withholding this information.
Q4. There have been zero ransomware attempts for the period 2022 to 2025.