Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Endpoint Security - Thousands of UK Government Devices Lost or Stolen, Raising Cybersecurity Fears
Endpoint Security Business and Policy Data Protection Hardware Security Latest News News & Analysis Security

Thousands of UK Government Devices Lost or Stolen, Raising Cybersecurity Fears

Kirsten DoyleBy Kirsten DoyleJune 24, 2025Updated:June 24, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
UK Government Devices Lost
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

More than 2,000 government-issued laptops, phones and tablets were lost or stolen across Whitehall departments over the past year, as reported by The Guardian. The estimated replacement cost? £1.3 million. The broader cost to national security is a lot harder to calculate. 

Departments including the Ministry of Defence (MoD), the Department for Work and Pensions, and the Cabinet Office reported hundreds of missing devices in 2024 and early 2025. In just the first five months of this year, the MoD alone reported 103 laptops and 387 phones gone missing. The Home Office, Treasury, and Bank of England were among other departments affected. 

Cybersecurity experts say the scale of the losses poses a systemic risk. While most devices are encrypted, that doesn’t rule out all potential compromise. If a phone is unlocked at the moment, it’s taken (a common scenario in street thefts) a bad actor could potentially access sensitive data or authentication tokens tied to government systems. 

“These are surprisingly large numbers,” said Prof Alan Woodward of the University of Surrey. “Even if 1% belonged to system administrators, that’s enough to get in.” 

Government departments insist protections are in place. The MoD and Bank of England both said they take data security seriously and have robust procedures to prevent and investigate losses. A government spokesperson said devices are encrypted to prevent unauthorised access, and every incident is investigated. 

Still, critics say the rising number of incidents points to a broader problem. David Gee, CMO at Cellebrite, warned that the loss of devices from agencies handling sensitive national data,  including defence and healthcare, is a major security concern. 

The Department for Science, Innovation and Technology, which oversees the UK’s cybersecurity strategy, also reported 101 devices lost or stolen over the past year. With departments increasingly dependent on mobile and remote systems, experts say securing the endpoint, particularly in the hands of staff, is now mission critical. 

Risk Beyond Financial Loss 

Javvad Malik, Lead Security Awareness Advocate at KnowBe4, says this represents a cybersecurity risk that extends beyond the financial loss. “While the government assures us about encryption, the sheer number of missing devices creates a significant attack surface for potential bad actors. Encryption is a great control to have in place, but it’s not a silver bullet. Unlocked devices or misconfigurations could still pose risks. This situation requires a thorough review of current security practices and their real-world effectiveness.” 

We need a multi-pronged approach here, says Malik. “Raising awareness for staff on securing devices and the risks, implementing device tracking systems, and creating transparent, accountable processes for handling losses. Also, every lost device should be a learning opportunity to strengthen the cybersecurity culture of an organisation. It’s not just about ticking boxes; it’s about constantly evolving our defences to stay ahead of threats.” 

Refurbished, Then Sold  

“Stolen hardware is often “refurbished” and then sold as used devices,” adds Boris Cipot, Senior Sales Manager at Black Duck. “This is because modern encryption software on these devices makes it difficult to access the data stored on hard drives or other storage media. However, even the most advanced encryption is ineffective if the encryption key or user password is weak.” 

Cipot says strong encryption software cannot protect data if the user password is easily guessable. 

“There are several methods that can be used to break into a system, and the weaker the password, the easier it is to crack. Therefore, companies should not solely rely on the technical capabilities of protection software. They must also ensure that the passwords used to access and disable encryption are as strong as possible.” 

For government-issued laptops and phones, Cipot says it is particularly recommended to implement MFA. “MFA can take the form of digital methods, such as biometric verification, or physical methods, such as a USB key or ID card. This additional layer of security significantly enhances the protection of sensitive data and reduces the risk of unauthorized access, furthering ensuring uncompromised trust in software.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Attackers Tricked IT Help Desks at M&S and Co-op into Resetting Passwords

May 7, 20252 Mins Read

EDR and Vendor Consolidation are a Losing Approach to Cybersecurity

March 7, 20254 Mins Read

Securing the Endpoint: Automating Security and Identity Management for Better Digital Experiences

February 11, 20255 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}