UK Government Devices Lost or Stolen in 2025 Exceeds 3,000 according to FOI Act Request

UK Government Devices Lost or Stolen - Exceeds 3,000 according to FOI Act Request
Image Credit: Freepik

Helping Keep Small Business CYBERSafe!
Gibraltar: Friday 15 August 2025 at 10:00 CET

UK Government Devices Lost or Stolen – Exceeds 3,000 according to FOI Act Request
By: Iain FraserCybersecurity Journalist
Published in Collaboration with: Nord VPN
SMECyberInsights.co.uk – First for SME Cybersecurity
Google Indexed P.Zero on 150825 at 10:48 CET
#SMECyberInsights #SMECyberSecurity #SMECyberAwareness #CyberSafe #SME #SmallBusiness

His Majesty’s Revenue and Customs (HMRC) has confirmed that almost 3,000 electronic devices have been lost or stolen over the past three years. This data, revealed through a Freedom of Information request analysed by Parliament Street, raises significant cybersecurity concerns as cyberattacks continue to target UK organisations.

The figures show that 2,897 devices, including mobile phones, tablets, and laptops, have been reported missing since 2022. The combined value exceeds £1.8 million. This disclosure comes weeks after an HMRC phishing scam led to £47 million being stolen from over 100,000 individuals.

For Small & Medium Enterprises (SMEs), these trends highlight why government security lapses should be on their radar. Government breaches often ripple through the private sector, increasing risks for suppliers, contractors, and any business handling sensitive client data.

The Facts

* 393 devices were stolen, valued at nearly £300,000.
* 2,504 devices were lost, including 2,181 mobile phones.
* 866 phones went missing in the past year alone.

HMRC stated that all missing devices are reported as security incidents and are encrypted to government standards. They are remotely deactivated upon being flagged. Many of the lost phones were legacy devices not properly decommissioned during audits, with some lost in transit.

Wider Public Sector Problem

This is not an isolated issue. The Ministry of Defence reported 1,166 lost or stolen devices over the same period. An additional 688 devices went missing across other government bodies, including the Bank of England and the Department of Health and Social Care.

Why SMEs Should Pay Attention

For SMEs, this is a clear warning. Government lapses create opportunities for cybercriminals. Stolen government data often fuels broader attacks, targeting private companies and SMEs through phishing, credential stuffing, and supply chain breaches.

SMEs are particularly vulnerable:

* They often lack dedicated cybersecurity teams.
* Supply chain links expose them to compromised government systems.
* Many rely on government platforms for payments, filings, and data exchange.

Practical Actions for SMEs

SMEs must take proactive steps to protect themselves:

1. Encrypt all devices and enable remote wipe functionality.

2. Regularly audit IT assets to ensure old or unused devices are securely decommissioned.

3. Implement strict access controls so that sensitive data is not accessible from personal or unsecured devices.

4. Conduct staff training on recognising phishing, social engineering, and AI-related threats.

5. Review supplier and government data interactions to identify potential security gaps.

As more government services move online, the risk of data leakage grows. SMEs must build resilience now to avoid becoming collateral damage.

Final Word: Stay Vigilant

This latest disclosure from Parliament Street reinforces the need for constant vigilance. For SMEs, the message is simple: do not assume government systems are fully secure. Treat every data exchange as a potential risk and invest in robust Cybersecurity practices to protect your business and your clients.

CYBERInsights | Practical Small Business Cybersecurity
Image Credit: IfOnlyCommunications

SMECYBER Insights – Helping Keep Small Business CYBERSafe! 

Launched in 2020 by Cybersecurity Journalist Iain Fraser and his team at IfOnly… SMECYBERInsights was developed to be the go-to platform providing definitive, reliable & actionable Cybersecurity News, Intel,  Awareness & Training specifically written and curated for Small Business & Enterprise Owners, Partners and Directors throughout the UK. #SMECyberInsights #SMECyberSecurity #CyberAttack #CyberAwareness  #Compliance #DDoS #Fraud #Ransomware #ScamAlert #SME #SmallBusiness #SmallBusinessOwner #ThreatIntel  

What is a VPN & Does my SME Need one? A VPN is a Virtual Private Network a method of securing your communications credentials. When it comes to SMEs, the choice of VPNs can significantly impact the security and efficiency of their operations. NordVPN secures your Internet data with military-grade encryption, ensures your activity remains private and helps bypass geographic content restrictions online.   Join NordVPN Today and Save up to 73% and Get 3 months Extra Free – Rude Not to …!