This year
A special edition to mark the end of 2025: test yourself against a quiz covering some of the key events from the last 12 months. The answers, a quick summary of why it matters, and links to read more are in the second half of this edition.
Need to know
Twelve tantalising trivia titbits to test thy talent:
1. The cyber attack on which major UK retailer in April 2025 is expected to result in a £136 million fallout?
- A) Marks & Spencer
- B) Co-op
- C) Harrods
- D) John Lewis
2. The UK Home Office issued a ‘technical capability notice’ to which tech company, reportedly demanding an encryption ‘backdoor’ to access user data?
- A) Google
- B) Microsoft
- C) Meta
- D) Apple
3. Which nation-state link group did the FBI tie to a $1.5 billion cryptocurrency heist?
- A) Flax Typhoon
- B) Lazarus Group
- C) Sandworm
- D) APT41
4. A data breach at the UK Ministry of Defence, which was kept secret by a super-injunction, exposed the details of thousands of people from which country?
- A) Syria
- B) Afghanistan
- C) Iraq
- D) Ukraine
5. What was the primary cause of the major Amazon Web Services (AWS) outage that affected its US-EAST-1 region in October, causing a cascade of failures for customers?
- A) Exploitation of a zero-day vulnerability
- B) Failure in AWS’s DNS management system
- C) Compromise of a software supply-chain component
- D) Hyper-scale distributed denial of service attack
6. How many people does the United Nations estimate have been trafficked and forced to work on online scams in compounds in Myanmar, Cambodia, and Laos?
- A) 11,000
- B) 56,000
- C) 120,000
- D) 387,000
7. The US Securities and Exchange Commission (SEC) dropped its lawsuit against which company and its CISO over the ’Sunburst’ attack?
- A) F5 Networks
- B) Uber
- C) Oracle
- D) SolarWinds
8. What was the estimated financial impact on the UK economy from the cyber attack against Jaguar Land Rover (JLR) in August 2025?
- A) £850 million
- B) £1.9 billion
- C) £6.7 billion
- D) £15 billion
9. A critical vulnerability known as ‘Citrix Bleed 2’ (CVE-2025-5777) allowed attackers to steal what kind of information from Citrix NetScaler appliances?
- A) Encrypted credentials
- B) Post-authentication session tokens
- C) The system’s configuration files
- D) Private encryption keys
10. The United Nations adopted a Cybercrime Convention establishing an international framework for cooperation after five years of negotiations, based initially on a proposal from which permanent member of the UN Security Council?
- A) United States
- B) United Kingdom
- C) Russia
- D) China
11. The ‘Shai-Hulud’ campaign caused headaches for thousands in September and again in November 2025, but what is it?
- A) New ransomware strain used against virtual servers
- B) Self-replicating worm infecting developers and code repositories
- C) Prompt injection to break out of AI guardrails
- D) State-sponsored group targeting critical infrastructure
12. A ransomware gang named Medusa mistakenly tried to recruit a BBC employee for an insider attack, misinterpreting what job title?
- A) Data Protection Officer
- B) Weather Presenter
- C) Head of News
- D) Cyber Correspondent
Answers:
You’ll find further details and a link to read more for each question and answer in the section below. If you want to get straight to the answers, they are: ADBBBCDBBCBD.
How did you get on?
Share your results with me (and the world) using #RobinNeedsToKnow on LinkedIn.
Twelve things
-
A) Marks & Spencer: Throughout 2025, the UK retail sector faced a series of cyberattacks described by NCSC as a “wake-up call”. Marks & Spencer suffered the worst, with weeks of disruption costing an estimated £136 million, and lost orders totalling around £3.8 million per day. Other retail brands, such as Harrods and Co-Op, were also breached, with the latter losing the personal information of 6.5 million members. The retail sector has a lot of consumer information — names, contact information, loyalty or payment information — making it an attractive target for cybercriminals. The Scattered Lapsus Hunters (an amalgamation of the Scattered Spider, Lapsus$, and Shiny Hunters groups) were associated with the string of attacks, which mainly found their way in through social engineering targeting IT and outsourced help desks. (M&S, SCATTERED SPIDER)
-
D) Apple: In February 2025, Apple turned off its Advanced Data Protection feature in the UK market, amidst claims that the UK Home Office had demanded access to customers’ data. The secret Technical Capability Notice may require Apple to develop a backdoor into users’ accounts so that UK intelligence agencies can access encrypted user data. Apple’s revocation of its most advanced protection was seen as a canary in the coal mine. Apple is challenging the TCN in the courts, and ADP remains disabled for UK users. These types of capabilities introduce weaknesses into systems and open the door for other regimes around the world to exploit similar access requests. (E2EE)
-
B) Lazarus Group: North Korea continues to fund government activities by illegal means. Breaking into cryptocurrency exchanges and other digital currency markets is a popular tactic of the Lazarus Group, which gained notoriety following an attack on the Bank of Bangladesh. Other schemes include posing as IT workers for remote positions, using so-called laptop farms to appear to be connecting from the US, and funnelling funds back home. (NORTH KOREA)
-
B) Afghanistan: As the old saying goes, the cover-up is always worse than the crime, and so I expected news that the UK Ministry of Defence had obtained a ‘super-injunction’ to prevent media from reporting on a data breach to command more column inches. The incident stems from a MOD staffer who filtered rather than removed a spreadsheet containing details of 30,000 people who aided UK forces in Afghanistan and emailed it to someone. The data was posted on Facebook back in 2023 and led to a secret relocation scheme to repatriate those at risk to the UK, which has cost UK taxpayers around £850 million. Evidence submitted to the Defence Select Committee after the injunction was lifted suggests 87% of those named have faced threats or reprisal attacks from the Taliban. (AFGHANISTAN)
-
B) Failure in AWS’s DNS management system: It’s always DNS! This incident shows the concentration of firms that use US-EAST-1 or rely on its availability to manage their distributed systems. It’s the default for AWS, but that doesn’t mean it needs to be your default. Also, cold starts of these hyper-scale systems can be tricky, ask Facebook. (AWS (FACEBOOK (OCT 21)))
-
C) 120,000: Online scams may seem like small fry compared to headline-grabbing cyberattacks against big company brands, but small-scale they are not. The UN estimates that organised crime gangs have trafficked over 120,000 people, lured in by promises of lucrative IT jobs, and then forced to work in appalling conditions and tortured if they refuse to defraud people via IT support, financial investment, and romance scams. Illicit gains are so substantial that they’re thought to equate to between 23% and 68% of Myanmar, Cambodia, and Laos gross domestic product. Amnesty International believes it has identified 53 active scam compounds, the largest of which appear more like cities, with Myanmar authorities taking what was described as ‘performative’ action by blowing up over 200 buildings (around one-third) of the illegal buildings in the KK Park compound. (MYANMAR)
-
D) SolarWinds: That legitimate device management software from SolarWinds had been compromised by a state-sponsored attacker made huge waves in Christmas 2020. Fast forward through 2023, and the Securities and Exchange Commission (SEC) brought charges against SolarWinds and its CISO, Timothy Brown, which were finally dropped in November 2025. Bringing the case, the SEC felt there was public interest in the difference between internal security reports and what was filed during the company’s IPO: security reports that the “current state of security leaves us in a very vulnerable state for our critical assets”, while the IPO filing only mentioned “generic and hypothetical cybersecurity risk disclosures”. There has been understandable concern from CISO communities over the case and the personal risks they face. (SOLARWINDS)
-
B) £1.9 billion: A cyber incident shut down production at multiple Jaguar Land Rover (JLR) factories through September and into October 2025, resulting in an estimated £1.9 billion impact on the UK economy. Over 5,000 businesses in JLR’s supply chain also needed to slow or stop production, causing cash flow issues for smaller firms less able to weather the turbulence. The UK government underwrote a £1.5 billion loan for JLR, should it be required. The fallout apparently contributed to the UK’s lacklustre economic forecasts. As with retail cyberattacks earlier in the year, the incident was attributed to Scattered Lapsus Hunters exploiting access via a third party. (JLR)
-
B) Post-authentication session tokens: The critical CitrixBleed 2 vulnerability allowed attackers to obtain session token information that, when presented to Citrix systems, fooled them into thinking that they were a legitimate user who had already authenticated. Handy, if you’re an attacker looking to bypass multi-factor authentication and other strong sign-in controls. Inherently, these solutions need to be on the edge of an organisation’s network to allow their promised remote access. Once in, they replicate substantial access, making them a desirable target for attackers. (CITRIX)
-
C) Russia: While the US and Russia initially tabled competing proposals, it was the latter that gained momentum and, ultimately, served as the basis for the United Nations cybercrime convention. Over 40 countries have signed up to the convention, which establishes a legal framework for law enforcement to investigate cross-border cybercrime and follows five years of negotiation. It’s not without its critics: dozens of groups, including Human Rights Watch, the EFF, and Privacy International, say it encourages or facilitates surveillance of citizens. This is a classic trade-off between perfection and success that’s likely to be found in international politics. The UK has signed up, but it’s unclear if there is sufficient US political will to follow suit. (CYBER-NORMS)
-
B) Self-replicating worm infecting developers and code repositories: Named after enormous worm-like creatures in the Dune franchise, Shai-Hulud is a self-propagating worm that steals credentials and secrets and then injects itself into other code libraries maintained by that developer. This, in turn, infects those who may maintain or use that code, and so on. The secrets stolen by the worm are published to public repositories, necessitating their immediate rotation. Over 25,000 developers and 400,000 secrets have been exposed. It’s unclear who is behind the worm: it’s a noisy campaign, and while credentials are stolen, making them public is a chaotic, rather than calculated move for a threat actor. (SHAI-HULUD)
-
D) Cyber Correspondent: Cybercriminals aren’t known for being the brightest crayon in the box — though, hey, it’s not dumb if it works — and it’s not the first time that they have mistaken who or what they are attacking. However, offering to ‘retire’ BBC cyber correspondent Joe Tidy was a special move. Rather than becoming an insider threat, Tidy strung them along for the story, then published the whole experience. Presumably, the Medusa group was looking up ‘cyber’ positions at the BBC on LinkedIn and thought the journalist had some sort of administrator privileges that would be useful in an attack. (BBC)
And finally
- As we approach the end of the year, I’d like to thank you for reading, and especially if you’ve shared or encouraged others to subscribe to. I really appreciate the time and trust you give me. If I may be a little cheeky… can I ask you for any feedback and, maybe, that you might share this link and your thoughts with your network?