Russian hostile activity is costing the United Kingdom between £2 billion and £2.5 billion a year, a burden carried by taxpayers, businesses and public services without anybody in government totalling it up, according to a report published by Graeme Downie, the Labour MP for Dunfermline and Dollar.
The report, written with Dr Dominic Reed and titled The Putin Tax, describes itself as the first attempt to measure the economic burden of Russian hostile activity against Britain. It argues that confirmed attacks alone have already generated somewhere between £1.6 billion and £2.1 billion in losses, and that the real figure is almost certainly far higher once unreported incidents, resilience spending and wider economic damage are taken into account.
Mr Downie sets out the central argument in the executive summary: “Far from being solely a national security challenge, Russian hostile activity represents a significant and recurring economic cost that British taxpayers and businesses are already paying every year.”
The choice of phrase is deliberate, and the report explains why at some length. The burden, as it puts it, “is not listed on a payslip, and it is not collected by HM Revenue and Customs. Yet it is paid, nonetheless. It is paid when businesses are forced to spend millions recovering from cyber-attacks rather than investing in growth. It is paid when public bodies divert resources into security and resilience measures.”
Three incidents make up the floor of the estimate, chosen because meaningful public figures exist for each. The LockBit ransomware attack on Royal Mail in January 2023 cost its parent company around £10 million in remediation and resilience work, the Russian-linked arson attack on industrial units in Leyton in east London caused approximately £1 million in direct damage, and the cyber attack on Jaguar Land Rover in late 2025 produced economic losses of between £1.6 billion and £2.1 billion. The report calls that total “the basement of a floor, not a ceiling”, since it leaves out supply chain losses, infrastructure protection costs, general resilience investment and aviation disruption.
Layered on top of that are estimates drawn from industry and from the government’s own research. The cyber-risk analytics firm CyberCube identified more than 300 Russia-linked cyber attacks on British companies since 2022, a figure it believes significantly undercounts the true number because only a minority of attacks in its database carry reliable attribution and many businesses never report an incident at all. Applying the government’s own benchmark of almost £195,000 for a significant cyber incident gives a baseline of around £58.5 million, which the report notes is less than a thirtieth of what the Jaguar Land Rover attack cost on its own.
Research commissioned by the Department for Science, Innovation and Technology puts total annual cyber losses to British business at roughly £14.7 billion, about half a per cent of GDP. The report works through what different Russian shares of that would mean, finding that even a conservative tenth would come to £1.47 billion a year, with a fifth reaching £2.94 billion.
Subsea cables account for a further £250 million to £500 million of annual exposure, a figure the authors are careful to describe as an exposure range rather than a measured loss. CyberCube also assesses a five per cent chance that the United Kingdom will suffer a single attack by a hostile power costing one British company $4.4 billion, or around £3.3 billion, more than one and a half times the cost of the Jaguar Land Rover incident.
Running through the whole document is a complaint about measurement rather than about threat perception. “Nobody in Government is currently bringing this information together,” the report states. “Instead, a patchwork quilt of information was found, spread across Whitehall, regulators, security agencies, infrastructure operators, insurers and private companies. Each organisation possesses only part of the picture.”
The authors contrast that with how other national risks are handled, observing that the costs of flooding are estimated because flood defences cost money, and the costs of fraud are measured because anti-fraud work costs money, while no equivalent effort has been made for hostile-state activity. They also take issue with the vocabulary, arguing that the term sub-threshold “holds within its definition a reason not to act” and that a patient whose treatment is delayed by offline systems does not experience a sub-threshold disruption.
Four recommendations follow from that argument, and none of them asks for new money. The government should publish an annual report to Parliament estimating the economic cost of hostile foreign-state activity, with attribution to specific states wherever possible. The National Cyber Security Centre should publish annual assessments of significant hostile-state cyber activity including attribution and estimated economic impacts. The Ministry of Defence should develop and publish a methodology for costing physical hostile activity directed at British people, businesses, infrastructure and interests. The last asks for a national public awareness campaign on hostile-state threats, cyber resilience and preparedness.
To give the sums a public-service comparison, the report calculates that £2 billion a year would cover the starting salaries of around 62,000 newly qualified nurses or the same number of police constables, and that £2.5 billion would stretch to about 78,000 of either, or 73,000 teachers.
The authors are open about what the work cannot do, and the limitations section is unusually candid. It is a desk-based study carried out within a parliamentary office, undertaken principally by a single post-doctoral researcher with no access to classified intelligence, no analytical team and no research budget, relying on published material, parliamentary questions, Commons Library briefings and industry research. The figures are offered as illustrative and conservative, and the report is explicit that it does not claim to be definitive.
In GCHQ’s first annual lecture at Bletchley Park in May, the agency’s director, Anne Keast-Butler, gave the assessment the report builds on: “Russia is scaling up its daily hybrid activity against the UK and Europe, stretching from the seabed to cyberspace, relentlessly targeting critical infrastructure, democratic processes, supply chains and public trust.”
Mr Downie’s conclusion is that the argument has moved on from whether the activity exists. “The challenge now is not proving that the Putin Tax exists but ensuring Britain starts measuring it,” the report says.










