
City Hub Shortens Cybercrime Victim Response Window to Five Days in First Annual Tally
City of London Police said average victim update times on fraud reports fell from 37 days to five after reforms to the national Report Fraud hub.
House byline
Security correspondent
Daniel Okeke is a house byline for InfoHandle’s Security desk.

City of London Police said average victim update times on fraud reports fell from 37 days to five after reforms to the national Report Fraud hub.

Washington confirmed Sunday that every U.S. bomber has left the Gloucestershire base for home stations, two weeks after counter-terror arrests near the airfield and days after a sixth suspect faced terrorism charges.

The National Fraud Intelligence Bureau helped West Midlands Police seize about 2,400 SIM boxes in a Birmingham raid tied to pensions cold-calling, cutting a channel fraudsters used to spoof legitimate trustee numbers.

A 40-year-old man died after gunfire at a Braybrook Street junction where dozens had gathered for a memorial, including children; no arrests have been made.

Counterterror police say two Iranian nationals arrested in Manchester tried to source bomb components and scout sites ahead of Yom Kippur, as the Home Secretary links the case to wider Iranian threats.

Assessors auditing Cyber Essentials Plus renewals report exposed remote-desktop ports on NHS supplier portals, prompting NHS England to remind vendors of minimum connectivity standards.

Counter Terrorism Policing said Joshua Kerry, already accused of murdering Ann Widdecombe, was charged Friday with preparing terrorist acts that prosecutors say included plans targeting Reform UK leader Nigel Farage.

City of London Police flagged a surge in fake HMRC refund texts as the October self-assessment registration window opened, urging taxpayers not to tap embedded links.

Action Fraud recorded more than £12 million in romance and dating fraud losses reported in September, with City of London Police warning that autumn social-media campaigns are pushing victims toward crypto wallets and gift-card payments.

Northern Ireland’s chief constable ordered a major evidence-gathering operation as Hillsborough talks continued over the stalled Drumcree march and a residents’ blockade on Garvaghy Road.

Britain’s security service issued a rare public warning that more than 100 UK-linked academics unknowingly fed the Ministry of State Security through a front institute.

The National Cyber Security Centre said it helped remove more than 400 HMRC-themed phishing domains in September as self-assessment season approaches.

More than 800 Metropolitan Police officers raided 24 addresses before dawn, arresting 17 people on suspicion of organised-crime and money-laundering offences after an officer was stabbed in Cockfosters.

The National Cyber Security Centre urged UK organisations running on-premises Citrix NetScaler appliances to patch CVE-2026-88771 and CVE-2026-88772 after Citrix confirmed active exploitation of the twin zero-days.

The National Cyber Security Centre urged dissidents, journalists, and activists to scan Windows devices for CHOSEN BRICK spyware after a joint UK–US–Netherlands advisory detailed Iranian spear-phishing on messaging apps.

Armed officers halted three vans before dawn on Sunday, evacuated 85 households in Whelford, and handed the case to counter-terrorism police while bomb specialists examined the vehicles inside a 400-metre cordon.

Several men were held under the Explosives Act near RAF Fairford as Army bomb-disposal teams examined vehicles and residents were moved to a leisure-centre shelter.

Action Fraud data on booking-platform phishing meets a Liverpool conference weekend where delegates were urged to verify hotel payments only through official apps or listed phone numbers.

Translink has suspended trains through Lurgan after a security alert, with buses replacing rail between Lisburn and Portadown and passengers told to check before travelling.

Report Fraud logged 956 reports tagged as AI-related in 2025–26, up 395 per cent, with reported losses climbing from £1.2 million to £9.6 million. City of London Police points to deepfake endorsements and voice cloning — and the file on enforcement is split across several regulators.

The FCA's Conduct Rules now reach serious bullying, harassment and violence between colleagues at roughly 37,000 non-bank firms under COCON 1.1.7FR, in force since 1 September. Managers who fail to take reasonable steps, and findings that follow staff between employers, carry the personal exposure.

Emergency crews responded to a serious explosion and large fire at a printing warehouse on Crompton Road in Swindon's Groundwell Industrial Estate on Wednesday evening, with Wiltshire Police ordering nearby residents to stay indoors and Dorset and Wiltshire Fire and Rescue deploying ten engines and aerial water monitors.

Polish Digital Affairs Minister Krzysztof Gawkowski said an overnight blaze at an Exatel-operated Starlink ground station south of Warsaw was deliberate sabotage meant to disrupt connectivity for institutions including Ukraine’s military, while investigators and ABW officers comb the site.

Britain's National Crime Agency detained a man in his 40s in West Sussex on Tuesday in connection with a cyber incident at Collins Aerospace that disrupted baggage and check-in systems at Heathrow, Brussels, and Berlin airports, with EU cyber authorities describing ransomware involvement; he was later released on bail.

The FCA has written to Premier League and other clubs urging due diligence on shirt sponsors from unauthorised crypto exchanges and trading platforms—warning that unlawful financial promotions or tainted sponsorship money could create criminal and money-laundering exposure without naming specific clubs as criminals.

A Royal Air Force Hawk T2 jet crashed near RAF Valley on Anglesey on Wednesday afternoon, with both crew members ejecting and receiving treatment for minor injuries, North Wales Police and the Ministry of Defence said.

Metropolitan Police fraud detectives arrested three men in Hertfordshire and Surrey after a pension cold-call ring tricked retirees into transferring six-figure pots to fake FCA-authorised platforms, with Action Fraud logging 214 Home Counties reports since July.

The NCSC warned English councils that ransomware crews are probing payroll and HR portals ahead of month-end pay runs, after LGSS Cyber and two district authorities reported lockouts on systems that feed BACS salary files.

Counter-terrorism police said Tuesday they believe a suspected plot against Manchester’s Jewish community was disrupted after two men were arrested on Sunday, as synagogues prepared for Yom Kippur amid heightened security across Greater Manchester.

Falmouth Docks remained closed Tuesday while Royal Navy bomb-disposal teams assessed a 250-kilogram U.S. World War II missile found in the water on Monday, keeping a 300-metre cordon and evacuating three homes overnight.

Lloyds Banking Group began filtering crypto investment promotions out of mobile push feeds and in-app message centres after internal fraud data showed two-thirds of reported investment scams still originate on social platforms that mirror bank notification styling.

The NCSC and airport operators warned drivers about quishing stickers on express pick-up lane payment boards after Action Fraud logged a cluster of fake QR portals mimicking Heathrow and Gatwick pay-by-phone flows.

The Ministry of Defence said Britain and the United States fired a heavyweight torpedo from the 12-metre autonomous submarine XV Excalibur in UK waters last week—the first live launch from an uncrewed undersea vessel in the AUKUS partnership.

Counter Terrorism Policing arrested two men on Newton Street in Manchester’s Northern Quarter at about 14:45 Sunday under Section 41 of the Terrorism Act, in a Met-led operation with GMP; police said there was no wider public threat.

SonicWall UK packaged attachment quarantine and sandbox routing for councils still on legacy Exchange after LGSS digital flagged proxy-log spikes, bundling Capture ATP with a council licensing tier that assumes on-prem mail through 2027.

NatWest shortened reimbursement clocks on authorised push payment claims tied to romance fraud and bulk gift-card loads after City of London Police shared terminal metadata from a Square Mile probe, telling victims who bought high-street vouchers for fake partners that cases with matching MCC codes now skip a second manual review.

Starling Bank shipped an emergency app build invalidating reused push-payment tokens after Liverpool trading-standards officers flagged a merchant terminal that replayed wallet authorisations across split-ticket card sales.

The FCA reissued a clone-firm alert after weekend SMS blasts mimicked Hargreaves Lansdown’s Bristol switchboard, steering savers toward spoof portals that replay genuine company numbers while stripping FSCS cover from any transfer.

Revolut will bind high-risk transfers to registered handsets after briefing the Payment Systems Regulator’s APP fraud taskforce, tightening in-app OTP flows that ombudsman cases show scammers still defeat through coached screen sharing.

The NCSC warned councils to lock OAuth redirect URIs after a Midlands authority lost staff SSO sessions to a forged callback domain, pushing suppliers to audit open redirectors on planning portals tied to Microsoft Entra logins.

Lloyds Banking Group is piloting mandatory out-of-band callbacks when its fraud desk contacts customers, after Authorized Push Payment reports showed criminals still spoof caller-ID on ‘bank safe account’ scripts.

NCSC told NHS trusts to treat flu-season supplier invoices as a phishing front after finance teams reported spoofed vaccine-logistics and linen contracts ahead of winter ward surges.

FTSE Friday 10,650.44 still last. Wolves won 1-0. Monday 8:00 has not opened.

FTSE Friday 10,650.44 still last. Wolves won 1-0. Monday 8:00 has not opened.