Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationoperational-disruptioncritical-infrastructure-threatcybersecurity-regulation

Ransomware Elevates Cybersecurity to National Security Priority

Updated 3mo agoFirst seen Nov 27, 20252 sources

A surge in high-profile ransomware attacks targeting both the United Kingdom and the United States has prompted government officials to reclassify cybersecurity as a matter of national security. Anne Neuberger, former White House deputy national security adviser for cyber, emphasized at a London event that the societal and economic impacts of these attacks have become untenable, with incidents affecting major retailers like Marks & Spencer and manufacturers such as Jaguar Land Rover. The financial fallout from these attacks is significant, with cleanup and disruption costs reaching hundreds of millions of dollars for individual companies and broader economic impacts estimated in the billions.

In response, governments are increasingly engaging with private sector leaders to develop coordinated strategies for ransomware mitigation, recognizing that the threat extends beyond IT departments to affect national infrastructure and economic stability. The call for enhanced public-private cooperation reflects a shift in policy, as authorities seek to address ransomware as a systemic risk requiring unified action across both public and private sectors.

Share:
Ransomware Elevates Cybersecurity to National Security Priority
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Nov 27, 20257mo ago

Anne Neuberger frames ransomware as a national security priority

Speaking at a Royal United Services Institute event in London, Anne Neuberger said repeated high-profile ransomware incidents in the U.K. and U.S. have elevated cybersecurity from an IT issue to a national security priority. She called for coordinated public-private action, possible restrictions on ransom payments, and stronger efforts to disrupt ransomware financing.

U.S. sanctions crypto mixers Blender and Sinbad

The United States imposed sanctions on crypto mixers including Blender and Sinbad for their role in laundering illicit funds, including ransomware proceeds. Officials later argued such actions need to be faster and more aggressive because illicit actors can quickly reconstitute their infrastructure.

Ransomware attack affects Jaguar Land Rover

Jaguar Land Rover was also cited as a major U.K. victim of ransomware, with disruption affecting operations and supply chains and contributing to significant financial impact. The incident added to parliamentary scrutiny of how companies and government handle ransomware risk.

Ransomware attack hits Marks & Spencer

Marks & Spencer was among the major U.K. organizations cited as suffering a high-profile ransomware incident with broad operational and economic effects. The attack became part of a wider debate over corporate cyber preparedness and government support.

Feb 24, 20224y ago

Russia's invasion of Ukraine reduces viability of ransomware diplomacy

After Russia invaded Ukraine, U.S. officials assessed that diplomatic pressure on Russia over ransomware became less effective. This shift contributed to greater emphasis on other policy options such as restricting ransom payments and strengthening resilience measures.

May 7, 20215y ago

DarkSide ransomware attack disrupts Colonial Pipeline

A 2021 ransomware attack attributed to the DarkSide group hit Colonial Pipeline in the United States, becoming a major example of ransomware causing national-level disruption. The incident helped drive subsequent U.S. policy changes and diplomatic pressure on Russia.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
11 linked
Colonial PipelineGovernment TechnologyRoyal United Services InstituteSinbadBlender.ioJaguar Land RoverWashingtonDarksideAndreessen HorowitzMarks & SpencerJaguar Land Rover Automotive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.