Back to News

UK Cyber Attacks Surge 34% to 1,589 per Week — Check Point June 2026: The Gentlemen Ransomware Picks Victims by Unpatched Device, Not by Target

UK Cyber Attacks Surge 34% to 1,589 per Week — Check Point June 2026: The Gentlemen Ransomware Picks Victims by Unpatched Device, Not by Target

On 13 July 2026, Check Point Research published its June 2026 global threat intelligence, and the UK figure inside it should stop every business owner in the country: UK organisations now absorb an average of 1,589 cyber attacks every week, a 34% year-on-year increase that is running at roughly double the global rate of 17%. The global average sits at 2,270 attacks per week — up 17% year-on-year and 10% month-on-month — but it is the UK’s acceleration that stands out.

This is not a single spike caused by one large campaign. As Check Point’s Data Research Manager Omer Dembinsky put it, “June’s data shows a broad rebound in cyber activity, not a single isolated spike.” For UK SMEs, it means the question is no longer whether an attack will be attempted against your organisation but when, how frequently, and whether your defences will hold when it arrives.

UK weekly attacks per org
1,589
+34% year-on-year
Global weekly attacks per org
2,270
+17% year-on-year
Global ransomware incidents (June)
646
+33% year-on-year
Why device-centric targeting changes your risk calculation

For years, UK SMEs have quietly reassured themselves with “we’re too small to be a target.” The Gentlemen’s model dismantles that reassurance completely. Because the group pre-compromises firewalls first and picks victims second, your sector, size and profile are irrelevant to whether you are selected. What matters is whether one of your internet-facing devices was exploitable when the group was harvesting access.

Where the attacks are landing: the most-targeted sectors

Check Point’s June data breaks attack volume down by sector, and the pattern is instructive for UK SMEs deciding how seriously to take their own exposure. The chart below shows the most heavily targeted sectors globally by weekly attacks per organisation, alongside the UK and global per-organisation averages for context. These are the reported June 2026 figures where given; the shorter bars are indicative placements to show relative scale.

Education (~4,816/week, +16% YoY)
95%
Government (~2,836/week, +5% YoY)
78%
Telecoms (~2,835/week, +13% YoY)
78%
Global average (2,270/week, +17% YoY)
63%
Healthcare (indicative)
58%
UK average (1,589/week, +34% YoY)
44%
Manufacturing (indicative)
40%

Education tops the table at roughly 4,816 attacks per organisation per week (up 16% year-on-year), followed by government at around 2,836 (up 5%) and telecommunications at 2,835 (up 13%). These are the sectors with sprawling user bases, legacy estates and rich data — but the lesson for a UK SME is not “we’re not a school or a telco, so we’re fine.” The sector breakdown describes where volume concentrates in aggregate. It does not describe how The Gentlemen selects an individual victim, which is by device exploitability alone. A ten-person accountancy practice with an unpatched firewall is, in that model, a more attractive target than a well-defended hospital. Sector is a demographic; an exploitable device is an invitation.

The geography that proves the point

The single most revealing statistic in the June report is the geographic distribution of The Gentlemen’s victims. Ransomware campaigns overwhelmingly concentrate on the United States, which typically accounts for around half of all published victims because it holds the greatest density of high-revenue targets willing to pay. The Gentlemen break that pattern decisively.

12%
The United States accounts for just 12% of The Gentlemen’s victims — against the ~50% share typical of ransomware campaigns overall. The gap is direct evidence that this group follows vulnerable devices, not high-value geographies. Any organisation with an exploitable firewall is in scope, wherever it sits.

When only 12% of a group’s victims are in the country that normally dominates ransomware, the targeting logic has fundamentally changed. The group is not building a list of lucrative organisations and then finding a way in; it is compromising firewalls at scale first, then working out what sits behind each one and monetising the access. That inversion is what makes the model so dangerous for UK SMEs. In the old logic, obscurity and modest revenue offered a degree of natural cover. In the new logic, the only thing that determines whether you are attacked is whether your perimeter was patched when the harvesting ran. The UK’s 34% surge and the 14,000-device access pool are two halves of the same story: automated, indiscriminate compromise of whatever is left exposed.

Where UK SMEs are most exposed to the device-centric model

The Gentlemen’s approach is, in effect, a stress test of exactly the controls Cyber Essentials sets out — patch management, secure configuration and removal of unnecessary internet-facing services. Most UK SMEs fail that test in a small number of predictable places. The grid below maps where the exposure concentrates for a typical mid-market business.

Common exposure gaps against a device-centric attacker
Internet-facing firewall or VPN left unpatched past 14 daysHigh
Critical vulnerabilities not remediated within the CE windowHigh
No MFA on cloud services and remote-access accountsHigh
No inventory of internet-facing devices and servicesHigh
Management interfaces exposed to the public internetHigh
No documented patch-compliance evidence for auditMid
Default or unchanged configuration on perimeter devicesMid
No board-level owner accountable for patch cadenceMid

The consistency of these gaps is the point. A device-centric attacker does not need a sophisticated foothold; it needs one un-remediated critical vulnerability on a reachable device and one account without a second factor. CVE-2024-55591 is an authentication bypass — the class of flaw that lets an attacker skip the login step entirely on an unpatched device. The controls that neutralise it are not exotic: apply the vendor patch inside the mandated window, remove management interfaces from public exposure, and enforce MFA so that even a bypassed or stolen credential is not enough on its own. Each of those is a named Cyber Essentials requirement. The businesses that fall into the 14,000-device pool are, overwhelmingly, the ones that never operationalised those basics.

What Check Point Research actually found in June 2026

The June 2026 report is significant not just for its headline number but for the pattern behind it. The UK’s 1,589 weekly attacks per organisation represent a continuation of the acceleration that began in the second half of 2025. The global number — 2,270 per week — climbed 10% month-on-month from May, reversing a brief lull. The UK’s year-on-year rate is running roughly double the global average, suggesting that UK organisations are disproportionately exposed or disproportionately targeted.

H2 2025
UK attack volumes begin sustained acceleration
Weekly attack counts per UK organisation begin climbing above the global average, driven by increased ransomware-as-a-service activity and exploitation of unpatched edge devices.
Jan 2026
CVE-2024-55591 published and exploited at scale
Authentication bypass in Fortinet FortiOS and FortiProxy allows unauthenticated remote code execution. The Gentlemen immediately weaponise this to build a pre-compromised access inventory.
Mar 2026
The Gentlemen emerges as a major ransomware operator
Unit 42 publishes analysis of The Gentlemen. The group combines a device-first access model with a double-extortion playbook and a leak site to pressure victims. They are recorded as responsible for attacks on organisations in 18 countries.
May 2026
Brief global lull in attack activity
Global weekly attacks per organisation dip slightly in May 2026 before rebounding sharply. UK figures remain elevated throughout the lull.
Jun 2026
Check Point: The Gentlemen overtakes Qilin as global ransomware leader
646 ransomware attacks recorded globally in June 2026, up 33% year-on-year. The Gentlemen account for 17% of published attacks, overtaking Qilin (11%) and Akira (8%). UK weekly attacks hit 1,589 — the highest recorded figure for UK organisations to this point.

Where the attacks are landing: the most-targeted sectors

Check Point’s June data breaks attack volume down by sector. Education, Government, Healthcare, Finance, and Retail lead globally. UK SMEs in all sectors face elevated risk because the UK’s aggregate rate is 34% above last year.

Education (~4,816/week)
95%
Government & Military (~2,800/week)
75%
Healthcare (~2,400/week)
65%

What Cyber Essentials certification costs by business size

Cyber Essentials is deliberately proportionate — the scheme is built for organisations of every size, and the cost of certification scales with the complexity of the estate rather than the headcount alone. The table below sets out an indicative view of what certification and the underlying remediation typically involve across UK business-size bands. Figures are illustrative planning ranges for the combined certification and readiness work, not fixed quotes.

Business sizeTypical estate in scopeCertification pathIndicative investment
1–10 staffSingle firewall, cloud email and productivity suite, a handful of endpointsCyber Essentials self-assessment, with patch and MFA remediation£500–£2,000
10–50 staffFirewall plus VPN, multiple cloud services, mixed device fleet, some remote workersCyber Essentials or CE Plus with hands-on audit and documented patch evidence£2,000–£7,000
50–200 staffMulti-site perimeter, servers, several SaaS platforms, supplier integrationsCE Plus with vulnerability scanning, configuration review and remediation programme£7,000–£18,000
200+ staffComplex estate, regulated data, contractual security obligations, supply-chain scopeCE Plus plus continuous patch management and governance oversight£18,000+

The right figure for any given business depends on the state of the estate at the start — an organisation that already patches promptly and enforces MFA will spend far less than one starting from an un-inventoried, un-patched baseline. But the direction of travel is the same across every band: the cost of certification and the disciplined patch cadence behind it is a fraction of the cost of a ransomware incident. With the annual cost of cyberattacks to the UK economy now estimated at £14.7 billion, and only 5% of UK businesses holding Cyber Essentials (up from 3% in the previous Cyber Security Breaches Survey), the certification remains both the clearest signal of baseline competence and, structurally, the difference between being inside or outside the pool a device-centric attacker fishes from.

Reactive posture versus a certified, governed posture

The Gentlemen’s model exposes the gap between treating patching as an occasional chore and treating it as a governed, evidenced discipline — which is exactly what Cyber Essentials formalises. The comparison below sets out the two postures.

Reactive posture

How most uncertified SMEs run today

  • Firewalls and VPNs patched occasionally, when someone remembers
  • No inventory of which devices face the internet
  • Critical vulnerabilities left open well past 14 days
  • MFA optional or missing on cloud and remote access
  • Default configurations left in place on perimeter kit
  • No evidence trail to prove patch compliance to customers
  • Security treated as an IT cost, not a board responsibility

Certified, governed posture

Where Cloudswitched takes you

  • Patch management runs to a defined cadence within the CE window
  • Every internet-facing device and service inventoried and owned
  • Critical vulnerabilities remediated inside 14 days, evidenced
  • MFA enforced across cloud services and remote access
  • Secure configuration baselines applied and maintained
  • Documented patch-compliance evidence ready for CE Plus audit
  • Board-level ownership of cyber resilience, in line with the UK pledge

Moving from the left column to the right is not a single purchase; it is a shift from ad-hoc reaction to governed routine. Cyber Essentials is the framework that makes that shift concrete and auditable, and the v3.3 rules that took effect on 27 April 2026 sharpen it further — an automatic failure for cloud services without MFA, a firm 14-day patch mandate for critical vulnerabilities, and a requirement to produce documented patch-compliance evidence for the CE Plus audit. Those are not bureaucratic hurdles. They are, almost line for line, the controls that would have kept a business out of the 14,000-device pool.

37
Illustrative cyber-hygiene readiness score (out of 100) for a typical uncertified UK SME — unknown patch cadence, exposed management interfaces and incomplete MFA. A planning benchmark, not a measured figure; certification is what moves the needle.
A practical first move for any board this week

You do not need to start with a certification application. The single most valuable exercise a UK SME can run this week is an internet-facing exposure review: list every device and service reachable from the public internet — firewalls, VPN concentrators, remote-access gateways, exposed management interfaces — and for each one record the exact firmware or software version, the date it was last patched, and whether MFA protects any accounts behind it. Then check every critical vulnerability advisory from the last 90 days against that list and confirm each has been remediated. If any perimeter device is running unpatched firmware with a known critical flaw — the CVE-2024-55591 profile — patch it now, remove its management interface from public exposure, and enforce MFA. Most businesses cannot answer these questions today, and discovering that is the entire point: it converts an invisible exposure into a managed one, and it is the natural first step toward Cyber Essentials.

At-a-glance: the Check Point June 2026 report

FactDetail
SourceCheck Point Research June 2026 global threat intelligence, published 13 July 2026
UK attack volume1,589 attacks per organisation per week, up 34% year-on-year
Global attack volume2,270 per week, up 17% year-on-year and 10% month-on-month
UK vs global rateUK rate of increase roughly double the global rate
Ransomware volume646 attacks globally in June 2026, up 33% year-on-year
New ransomware leaderThe Gentlemen — 17% of published attacks, overtaking Qilin on 11%
Business modelRansomware-as-a-service combined with initial access broking
Access pool~14,000 FortiGate firewalls pre-compromised via CVE-2024-55591
Vulnerability typeAuthentication bypass in FortiOS and FortiProxy
Targeting logicDevice exploitability, not sector, size or geography
Geographic tellUS just 12% of The Gentlemen’s victims vs ~50% typical for ransomware
Top sectors globallyEducation (~4,816/week), Government (~2,836), Telecoms (~2,835)
Relevant standardCyber Essentials v3.3, in force 27 April 2026 — MFA auto-fail, 14-day patch mandate
UK certification rateOnly 5% of UK businesses hold Cyber Essentials (up from 3%)
Economic costCyberattacks cost the UK economy an estimated £14.7bn a year

How this connects to the wider 2026 threat picture

The Check Point June report does not stand alone. It is the latest thread in a year of UK developments all pointing the same way: attack volume is rising, the attacker is increasingly automated and indiscriminate, and the weakest link is the unpatched, internet-facing device. The device-centric model The Gentlemen have industrialised is the operational face of a broader shift toward faster, tool-driven compromise.

The perimeter-device dimension is exactly the exposure we set out in our coverage of the FortiBleed campaign and the 73,932 compromised Fortinet firewalls, the strategic counterpart to the same FortiGate weakness The Gentlemen are now monetising. The router and connectivity angle — the other end of the exposed-perimeter problem — is examined in our analysis of the NCSC and FSB router advisory for UK SMEs. The scale and pace of the patching challenge that CVE-2024-55591 exemplifies is captured in our reporting on the AI-driven CVE surge and why a real patch programme now matters. The breadth of UK exposure across ordinary businesses is quantified in our coverage of the Cyber Security Breaches Survey and the 612,000 UK businesses hit. And the changing nature of the adversary — automated, AI-assisted and regulated in parallel — runs through our look at the EU AI Act deadline and its implications for UK SMEs. Together these establish the same message the June report makes concrete: in a device-centric threat landscape, the basics — patching, secure configuration and MFA — are the whole game, and Cyber Essentials is the framework that enforces them.

The Gentlemen don’t pick you — your unpatched firewall does

Cyber Essentials is the framework built to keep your business out of the pool a device-centric attacker fishes from: patch management inside 14 days, secure configuration, no unnecessary internet-facing services and enforced MFA. Cloudswitched delivers end-to-end certification — gap analysis, remediation and audit — so those controls are real, evidenced and maintained, not just aspirational.

Talk to us about Cyber Essentials Certification

Frequently asked questions

We’re a small business — are we really a target for a group like The Gentlemen?
Yes, and the June 2026 data is what makes that answer definitive. The Gentlemen do not build a list of attractive companies and then break in; they compromise firewalls at scale first, through the CVE-2024-55591 authentication bypass, and only afterwards work out what sits behind each device and sell that access. Your size, sector and revenue play no part in whether you are selected — only whether your perimeter device was exploitable when the group was harvesting access. The clearest proof is geography: the United States, which normally accounts for around half of ransomware victims, is just 12% of The Gentlemen’s. A small UK firm with an unpatched firewall is a more attractive target to this group than a well-defended large enterprise. Being small or obscure is no longer any kind of protection.
What is CVE-2024-55591 and why does it matter to us?
CVE-2024-55591 is an authentication bypass vulnerability in Fortinet’s FortiOS and FortiProxy software — the operating systems that run on FortiGate firewalls and related appliances. An authentication bypass means an attacker can gain privileged access without going through the normal login process, effectively skipping the front door on an unpatched device. The Gentlemen used it to pre-compromise a standing pool of roughly 14,000 FortiGate firewalls, which they then sell access to. It matters to any organisation running a Fortinet perimeter device that has not been patched, because that device is precisely the kind of internet-facing appliance the group harvests. The fix is straightforward in principle — apply Fortinet’s security update, remove the management interface from public exposure, and enforce MFA — but it only helps if it is actually done, and done inside the window before the device is harvested.
Why is the UK rising at 34% when the global rate is only 17%?
Check Point’s report does not attribute the gap to a single cause, but the pattern is consistent with a UK business base that is heavily digitised, cloud-dependent and rich in the kind of internet-facing infrastructure automated attackers harvest, combined with a relatively low baseline of formal cyber hygiene — only 5% of UK businesses hold Cyber Essentials. When attackers move to a device-centric model, the countries with the most exposed, unpatched devices see the sharpest rises, because targeting follows exploitability rather than geography. The UK’s 34% increase, at roughly double the global rate, is best read as a signal that a large share of British perimeter estates remain reachable and unpatched. That is uncomfortable, but it is also actionable: the same exposure that drives the rise is closed by exactly the controls Cyber Essentials mandates.
How does Cyber Essentials specifically protect against this attack model?
Cyber Essentials is built around five technical controls, and three of them target the exact weaknesses The Gentlemen exploit. Patch management requires critical vulnerabilities to be remediated within 14 days, which closes the CVE-2024-55591 window before a device is harvested. Secure configuration requires default settings to be hardened and unnecessary services removed, which takes management interfaces off the public internet. And the v3.3 rules that took effect on 27 April 2026 add an automatic assessment failure for cloud services without MFA, so a bypassed or stolen credential is not enough on its own. In combination, these controls remove the device from the pool an access broker can compromise and sell. Certification does not make you invulnerable, but it structurally moves you out of the indiscriminate harvesting pool that this model depends on.
What changed in Cyber Essentials v3.3, and does it affect us?
Cyber Essentials v3.3 came into force on 27 April 2026 and tightened several requirements that map directly to the June threat data. The most significant change is an automatic assessment failure for any cloud service that does not have multi-factor authentication enabled — MFA is no longer a recommendation but a pass/fail condition. The update also reinforces the 14-day patch mandate for critical vulnerabilities and, for the Cyber Essentials Plus audit, requires documented patch-compliance evidence rather than a simple attestation. If you are certified or planning to certify, these changes affect you directly: you will need enforced MFA across cloud services and a genuine, evidenced patch cadence. If you are not yet certified, they set the bar you should be aiming at regardless, because they encode the controls that defend against device-centric attackers.
We already have antivirus and a firewall. Isn’t that enough?
Not against this model. Antivirus addresses malicious files on endpoints; a firewall filters traffic. Neither protects a firewall that is itself the vulnerability. CVE-2024-55591 is a flaw in the firewall’s own software, so the device meant to defend your perimeter becomes the way in. The controls that actually neutralise a device-centric attacker are patching the perimeter device within the mandated window, removing its management interface from public exposure, and enforcing MFA so a bypassed credential does not grant access. Those are process and configuration disciplines, not products you can buy once and forget. Having a firewall is necessary but not sufficient; keeping it patched, hardened and behind MFA is what matters, and that is precisely the discipline Cyber Essentials formalises and audits.
Does Cyber Essentials help us win contracts as well as improve security?
Yes, and increasingly so. Cyber Essentials is already mandatory for many UK government contracts, and the trend is spreading through private-sector supply chains. The UK Cyber Resilience Pledge signed on 7 July 2026 by more than 60 major firms — including M&S, Nationwide, Cloudflare, Microsoft UK and Deloitte — includes an explicit commitment to require Cyber Essentials across supply chains. In practice that means the businesses those firms buy from will increasingly be asked to demonstrate certification as a condition of doing business. Holding Cyber Essentials therefore does double duty: it closes the technical gaps a device-centric attacker exploits, and it provides the recognised proof of baseline competence that larger customers now expect from their suppliers. For a growing SME, it is as much a commercial credential as a security one.
How quickly can we get certified, and what does it involve?
Timelines depend on the starting state of your estate. A small business that already patches promptly and enforces MFA can often complete the Cyber Essentials self-assessment within a few weeks, while an organisation that needs to inventory devices, close patch gaps and roll out MFA should plan for a few weeks to a couple of months of remediation before assessment. Cyber Essentials Plus adds a hands-on technical audit with vulnerability scanning, which requires the documented patch-compliance evidence introduced in v3.3. A managed approach typically runs a gap analysis first, then a remediation phase to fix the issues found, then the assessment or audit itself. The remediation is usually the substantive part — the certification simply verifies that the controls are genuinely in place. The value is in the disciplined baseline it forces, not the certificate alone.
Only 5% of UK businesses hold Cyber Essentials — is that really a problem?
It is the crux of the problem. If only 5% of UK businesses are certified — even though that is up from 3% — then the overwhelming majority have no externally verified assurance that they patch critical vulnerabilities within 14 days, harden their configurations or enforce MFA. In a threat landscape where an access broker harvests whatever is left exposed, that uncertified 95% is, structurally, the pool being fished from. The device-centric model does not need most businesses to be certified to be profitable; it needs enough of them to be unpatched, and at a 5% certification rate that supply is abundant. Getting certified does not just protect your own business; it removes you from the population that makes this model viable. The low national rate is exactly why individual action still moves your own risk so sharply.
How does Cloudswitched help us respond to this?
Cloudswitched delivers Cyber Essentials and Cyber Essentials Plus as a managed, end-to-end service rather than a box-ticking exercise. We begin with a gap analysis against the five controls and the v3.3 rules, identifying every internet-facing device, unpatched critical vulnerability and account without MFA. Our engineers then do the remediation — applying patches inside the mandated window, hardening configurations, removing exposed management interfaces and enforcing MFA across cloud services — before coordinating the assessment or hands-on Plus audit and preparing the documented patch-compliance evidence the audit now requires. Because we are an established IT company rather than a certification-only consultancy, we can also put a repeatable patch cadence and named ownership behind the certificate, so the controls stay in place after the badge is issued. The outcome is a business that is genuinely outside the device-centric harvesting pool, with the evidence to prove it to customers and auditors alike.

Get out of the pool before the next harvest

The Gentlemen’s 14,000-device access pool exists because most businesses never operationalised the basics. Cloudswitched turns Cyber Essentials into a real, maintained programme — patch cadence inside 14 days, secure configuration, enforced MFA and audit-ready evidence — so your perimeter is a defended asset, not a product on an access broker’s shelf.

Talk to us about Cyber Essentials Certification
Tags:Cyber SecurityCyber EssentialsIT SupportNetwork Admin
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Cyber Essentials Certification

End-to-end Cyber Essentials Plus certification and ongoing security services

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

23
  • IT Support

How to Budget for IT Support as a Small Business

23 Oct, 2025

Read more
18
  • Cloud Email

Microsoft Entra ID: What Businesses Need to Know

18 Mar, 2026

Read more
27
  • Cloud Backup

Multi-Cloud Backup: Spreading Risk Across Providers

27 Feb, 2026

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.