House of Commons have rejected over 51 million malicious emails over the past three years, highlighting the relentless spike in cyber threats targeting the UK’s public sector and government institutions.
The data, obtained through a Freedom of Information (FOI) request and analysed by Parliament Street think tank, reveals the scale of these malicious attacks towards House of Commons between July 2023 – May 2026. Among the 51,145,419 emails rejected were likely a mixture of phishing attempts, malware, and spam.
The number of rejected email attacks increased each year, rising by almost 20% over the three-year period. The House of Commons rejected 15,973,452 emails in 2023 – 2024, increasing to 16,272,909 in 2024 –2025 and 18,899,058 in 2025 – 2026.
Stuart Harvey, CEO of Datactics commented: “Modern email security systems generate real time data on attempted malware delivery and phishing attacks that help enable security teams to respond to threats proactively. Organisations must have control over their sensitive personal data as messy data increases exposure and makes breaches harder to contain. Good security starts with good data discipline, and if you don’t know your data, you can’t protect it.”
‘When organisations lack a clear structure and visibility over their data, even basic questions become difficult to answer: what was accessed? whose data is affected? and how serious is it? If your data is a mess, then security teams don’t stand a chance in the event of a cyber-attack or data breaches.”
Andy Ward, SVP International at Absolute Security commented: “The reality is that it only one high level one cyber-attack to cause irreversible financial and reputational damage to an organisation. Almost a fifth of organisations experienced operational disruptions that lasted as long as two weeks, with the majority facing downtime that lasted nearly five days, when hit with a cyber-attack.”
“These threats are not a matter of if but when, and organisations cannot avoid the inevitable. Therefore, it is essential that these government bodies have true cyber resilience embedded into their operations. This is not just to prevent attacks, but to anticipate them, withstand them, and recover quickly enough to keep business running.”
There’s plenty of other editorial on our sister site, Electronic Specifier! Or you can always join in the conversation by commenting below or visiting our LinkedIn page.
