Analysing cyber threats to protect the United Kingdom

SUVAT is an independent research body focused on analysing spam, phishing and hostile digital activity affecting the United Kingdom. We publish technical analysis, share research with relevant stakeholders and provide advisory best practice guidance to help individuals, businesses and organisations stay safe online.

What SUVAT does

SUVAT operates across three principal areas of work.

Cybercrime prevention

Identifying, analysing and disrupting spam networks, phishing campaigns, ransomware operations and other forms of cyber criminality targeting UK citizens and organisations.

Threat research and analysis

Publishing assessments of the cyber threat landscape based on publicly available reporting and industry telemetry, producing malware analysis reports, and maintaining the SUVAT Cyber Threat Assessment.

Advisory guidance and research

Publishing technical analysis of suspicious digital activity, sharing research with relevant stakeholders, and providing advisory best practice guidance to help organisations respond to cyber threats.

SUVAT Cyber Threat Assessment

The SUVAT Cyber Threat Assessment is an independent analytical model based on publicly available reporting, industry telemetry and open-source intelligence. This assessment does not represent the position of the UK Government or any statutory body.

Current assessment
Low Moderate Substantial Severe Critical
Current level: SUBSTANTIAL

A cyber attack against UK interests is a strong possibility. Assessment published by SUVAT on 8 February 2026.

Active advisory

Coordinated phishing campaign affecting UK public sector. SUVAT has identified a large-scale credential-harvesting operation targeting NHS trusts, local authorities and educational institutions. Emails impersonate government digital services. All public sector organisations should review their email filtering rules and brief staff immediately.

Published 6 February 2026 — SUVAT/ADV/2026/003

About SUVAT

The Spam & Unwanted Virus Analysis Team (SUVAT) is an independent cyber threat analysis organisation based in the United Kingdom. It was founded to provide impartial, evidence-based research into spam, phishing and hostile digital activity.

SUVAT publishes technical analysis, shares research with relevant stakeholders, and provides advisory best practice guidance on threats arising from spam, malware, ransomware, phishing and other forms of unsolicited or hostile digital activity.

Our principal office is located in London, with research teams in Edinburgh, Cardiff and Belfast.

Independence. SUVAT's threat assessments and technical analyses are produced independently. Our work is based on publicly available data, open-source intelligence and industry collaboration, ensuring that analysis is assessed solely on its merits.

Organisational structure

SUVAT is led by a Director General and governed by a non-executive board. The organisation employs approximately 280 staff across its offices, structured into three directorates.

Director General
Catherine Langford — Appointed March 2024
Director of Operations
James Whitfield — Leads incident analysis, advisory services and stakeholder engagement
Director of Analysis
Dr Meera Patel — Responsible for malware research, threat modelling and analytical output
Director of Corporate Services
David Hargreaves — Oversees finance, governance, estates and information assurance

Governance and transparency

SUVAT is led by a Director General and governed by an advisory board. The organisation publishes an annual review of its activities and finances. Operational and editorial decisions are taken independently by the Director General.

Organisation type
Independent research body
Focus area
Cyber threat analysis, spam, phishing and malware research
Transparency
Annual review published; methodology publicly documented

Legal framework

SUVAT operates within the legal framework of the United Kingdom, including applicable data protection and computer misuse legislation. Our work references publicly available material from organisations including the National Cyber Security Centre, the National Crime Agency and Ofcom.

Guidance and resources

Updated 6 February 2026. Guidance on email authentication has been revised following the increase in phishing activity targeting the public sector. Organisations should review SPF, DKIM and DMARC configurations.

For organisations

For individuals

For organisations

Latest news and advisories

View all news and publications →

Report suspicious digital activity

If you have encountered a suspicious email, website, application or other digital threat, you can report it to SUVAT using the form below. Reports are reviewed for research and analytical purposes only. SUVAT does not conduct criminal investigations and does not provide emergency response services. In case of an active crime, contact your local police force.

If you believe a crime is in progress or there is an immediate threat, call 999. This form is for non-emergency reporting only.

We will use this to send you a confirmation and submission reference number\.
Include dates, sender details, URLs, file names or IP addresses where possible. Do not attach classified material.

This form is transmitted over TLS 1.3 encryption. By submitting, you confirm the information provided is true and accurate to the best of your knowledge.

Latest updates

Advisories, threat research and publications from SUVAT.

6 February 2026

Coordinated phishing campaign targeting UK public sector

SUVAT has identified a large-scale credential-harvesting operation targeting NHS trusts, local authorities and educational institutions using spoofed government domains.

Advisory
21 January 2026

SUVAT supports NCA in ransomware infrastructure disruption

SUVAT analysts published technical research on ransomware-as-a-service infrastructure used against UK targets, sharing findings with relevant stakeholders.

Press release
9 January 2026

Annual Review 2024–25 published

The Director General has published SUVAT's third Annual Review, covering the organisation's activities, threat assessments and performance during the 2024–25 financial year.

Publication

View all news and publications →

Stop. Think. Report.

SUVAT supports the national Stop. Think. Report. campaign. If something online looks suspicious — an unexpected email, an unusual request for personal information, or a link that doesn't seem right — take a moment, verify it, and report it. Your reports help protect the entire country.

Report suspicious activity