Key takeaways
- The UK Government's Cyber Security Breaches Survey consistently finds that a large share of UK businesses experience a breach or attack each year.
- The Verizon DBIR shows exploitation of vulnerabilities and stolen credentials as leading routes into organisations.
- WordPress powers a very large share of the web, and plugin vulnerabilities make up the vast majority of reported WordPress flaws.
- Many headline "malware statistics" online are vendor estimates with no method behind them. Check the source before you quote a number.
- The practical message is steady, not sensational: most attacks are automated, so basic patching, credentials and monitoring matter most.
What does the data actually show about website malware?
The reliable data shows that cyber attacks on organisations are common, largely automated and mostly exploit ordinary weaknesses: unpatched software, stolen passwords and phishing. It does not support the dramatic, unsourced figures that circulate online. For website owners, the evidence points to steady, basic hygiene rather than panic.
There is no single official count of "hacked websites". Instead, a handful of well-established sources each measure part of the picture: government surveys measure how many organisations report attacks, breach reports analyse confirmed incidents, browser vendors publish how many sites they flag, and WordPress security researchers track disclosed vulnerabilities. Put together, they describe a consistent trend, even if no one number captures it.
This guide summarises what those sources say, qualitatively where exact figures change year to year, and explains how to use them sensibly. We name every source so you can check the latest edition yourself.
Note: survey figures are revised each year. Always check the current edition of a report before quoting it, and quote the year alongside the figure.
What does the UK Cyber Security Breaches Survey say?
The UK Government's annual Cyber Security Breaches Survey consistently finds that a substantial share of UK businesses, and a higher share of medium and large businesses, identify a cyber breach or attack each year. Phishing is by far the most commonly reported type, and larger organisations report attacks far more often than micro businesses.
The survey is commissioned by the Department for Science, Innovation and Technology alongside the Home Office and has run for more than a decade, which makes it one of the most useful sources for UK trends. In recent editions, somewhere between roughly two-fifths and a half of businesses reported a breach or attack in the previous twelve months, with the proportion rising sharply for medium and large firms.
Three findings are especially relevant to website owners:
- Phishing dominates. Most reported incidents start with phishing, which is also how many website, hosting and email passwords are stolen.
- Smaller firms under-detect. Micro and small businesses report fewer attacks, but the survey itself notes that this partly reflects less monitoring rather than less risk.
- Supplier risk is poorly managed. Only a minority of businesses formally review the cyber risks posed by their suppliers, which includes web developers, plugins and hosting providers.
The practical reading: if you are not monitoring your website, the absence of evidence is not evidence of absence. Our 24/7 monitoring exists precisely to close that gap.
What does the Verizon DBIR say about how attackers get in?
The Verizon Data Breach Investigations Report (DBIR) analyses thousands of confirmed breaches each year. Recent editions show stolen credentials, phishing and the exploitation of vulnerabilities as the leading ways attackers gain initial access, with vulnerability exploitation growing noticeably and web applications remaining a frequent target.
The DBIR is global and weighted towards larger organisations, but its patterns map closely onto what we see on compromised websites:
| DBIR theme | What it looks like on a website |
|---|---|
| Use of stolen credentials | Attackers logging into wp-admin, FTP, SSH or the hosting panel with a valid password |
| Exploitation of vulnerabilities | Automated attacks on outdated plugins and themes shortly after a flaw is disclosed |
| Third-party involvement | Compromised plugins, developer accounts or shared hosting neighbours |
| Basic web application attacks | Brute-force logins, file upload abuse and injected webshells |
The DBIR has also repeatedly highlighted the gap between a vulnerability being published and organisations patching it. On WordPress sites, that gap is often where the infection happens. See why malware attacks on websites are increasing for more on this.
What does Google Safe Browsing tell us?
The Google Safe Browsing Transparency Report shows how many unsafe websites Google detects over time, split between sites hosting malware and sites used for phishing. For several years, newly detected phishing sites have far outnumbered malware-hosting sites, which reflects attackers' shift towards stealing credentials and money directly.
This matters to legitimate site owners because many flagged sites are not attackers' own domains. They are ordinary business websites that have been compromised and then used to host phishing pages, malicious downloads or redirects. When that happens, Google shows warnings such as "Deceptive site ahead" or "This site may be hacked", and traffic from Chrome and other browsers drops sharply.
The report is also a useful reminder that Google checks sites continuously. If yours has been flagged, the fix is to clean the site and request a review in Search Console; our guide on removing a Google blacklist warning walks through it, and our blacklist removal service can handle it for you.
Security triage
Is your site showing any of this?
Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.
What do the numbers say about WordPress specifically?
WordPress powers a very large share of all websites, over two-fifths according to W3Techs' long-running CMS survey, so it is naturally the most attacked CMS. WordPress security researchers such as Patchstack consistently report that the vast majority of newly disclosed WordPress vulnerabilities are in third-party plugins, with only a tiny fraction in WordPress core.
This is the single most useful statistic for WordPress owners, because it tells you where to focus. Core WordPress updates are frequent and often automatic. Plugins vary enormously in quality, update frequency and whether they are still maintained at all. Abandoned plugins with known flaws are a routine cause of the infections we clean.
A quick way to see your own exposure is to list installed plugins and their update status from the server:
# List plugins with available updates (WP-CLI)
wp plugin list --update=available --fields=name,version,update_version
# List plugins that are installed but inactive (still exploitable)
wp plugin list --status=inactive --fields=name,version
Tip: inactive plugins are still reachable on disk and can still be exploited. If you do not use a plugin, delete it rather than deactivating it.
The same research also tends to show that a meaningful share of plugin vulnerabilities are never fixed by their developers, usually because the plugin has been abandoned. Those plugins keep working, so site owners rarely notice, but they will never receive a patch. Removing or replacing abandoned plugins is therefore one of the highest-value, lowest-cost security tasks available to any WordPress owner.
For a full list of controls, see our WordPress hardening checklist.
How should you read website malware statistics?
Read website malware statistics by checking who produced them, how they were measured and what they actually count. Government surveys count reported incidents, breach reports count confirmed breaches, and vendor figures often count their own customers' detections. None of them are wrong, but each answers a different question.
- Is there a named source and year? "Studies show" with no link is a warning sign.
- What is being counted? Attacks attempted, breaches confirmed, sites flagged and vulnerabilities disclosed are all very different things.
- Who was surveyed? A report based on enterprise incidents may not reflect a small UK e-commerce site.
- Does the vendor sell the fix? Vendor data can be useful, but check whether the sample is only their customers.
- Is it current? Figures quoted on the web are often several years old and re-circulated without dates.
We deliberately avoid the eye-catching, unsourced numbers common in this industry. A dramatic statistic is not a reason to buy security; understanding your own risk is. The fastest way to do that is to tell us about your site in our two-minute security triage.
What do these statistics mean for your website?
Taken together, the data means your website is most likely to be compromised through a routine weakness, such as an outdated plugin or a reused password, by an automated tool that is not targeting you personally. The most effective defences are therefore unglamorous: fast patching, strong unique credentials, server-side scanning and continuous monitoring.
- Patch quickly. Update plugins and themes promptly and remove anything abandoned.
- Protect credentials. Use unique passwords, two-factor authentication and SSH keys rather than passwords.
- Scan server-side. A Malware sweep checks every site on the server, not just the one you are logged into.
- Monitor continuously. Detecting an infection in hours rather than months limits the damage.
PatientZero combines all four with unlimited malware removal from £99 a month per site, with no contract. See pricing, or if you already suspect a problem, read the 12 signs your website has been hacked.
Frequently asked questions
How many websites are hacked every day?
There is no reliable, independent daily figure. Numbers quoted online are usually vendor estimates without a published method. Better indicators are the Google Safe Browsing Transparency Report, which shows sites Google flags as unsafe, and surveys such as the UK Cyber Security Breaches Survey, which show how many organisations report attacks.
Is WordPress less secure than other platforms?
WordPress core is actively maintained and reasonably secure. It is attacked more because it is so widely used, and because most sites add many third-party plugins of varying quality. Research from WordPress security firms consistently finds that plugins, not core, account for the vast majority of disclosed vulnerabilities.
Where can I find official UK cyber attack statistics?
The main official source is the Cyber Security Breaches Survey, published each year on GOV.UK. The National Cyber Security Centre publishes an annual review, and the ICO publishes data security incident trends based on breach reports it receives. Check the most recent edition of each.
Are small business websites really at risk?
Yes. Most website attacks are automated and look for weaknesses rather than for particular businesses. The UK Cyber Security Breaches Survey also notes that smaller organisations may under-report attacks simply because they monitor less, so a lack of known incidents is not the same as being safe.