Financial services threat intelligence report — 13–19 June 2026
All assessments use estimative language and confidence ratings per Section 11.
SOC status:Duty analyst on shift
Topic
105 articles tagged Sector briefing.
All assessments use estimative language and confidence ratings per Section 11.
During the reporting period the principal observations were the continued sustained cyber pressure on the Western defence industrial base from Russia- and China-linked actors as documented by Mandiant / Google Threat Intelligence (April 2026 report describing China-nexus groups as the most active…
The trade-body and membership-organisation collection picture this week sits against persistent high-volume phishing pressure (APWG Q1 2026 records 971,181 attacks, up 13.8% from Q4 2025) and the Verizon 2026 DBIR's continuing observation that the human element dominates breach causation.
The retail-sector collection picture this week continues to be framed by the Scattered Spider / DragonForce campaign that disrupted M&S, Co-op and Harrods through April-May 2025 and which has carried forward into a sustained 2026 pivot toward retail BPO and outsourced customer-service helpdesks.
The maritime-and-logistics collection picture this week has been dominated by the convergence of the new no-patch network-edge defects (Cisco Catalyst SD-WAN Manager CVE-2026-20245 and Arista EOS CVE-2026-7473) with the still-current US Coast Guard MTSA Cyber Regulations compliance window.
The legal-sector collection picture this week sits against an unusually material regulatory backdrop: the Solicitors Regulation Authority's April 2026 consultation on compliance demonstration remains open…
The healthcare-sector collection picture this week sits against the Health-ISAC 2026 Global Health Sector Threat Landscape Report's documented 55% surge in incidents through 2025 and its identification of Qilin, INC Ransom and SAFEPAY as the most active ransomware groups targeting health entities.
The financial-services collection picture this week has been dominated by the addition of six further vulnerabilities to the CISA KEV catalogue, three of them confirmed under active in-the-wild exploitation against FS-relevant edge infrastructure: Cisco Catalyst SD-WAN Manager (CVE-2026-20245…
The R&D and defence-contractor collection picture this week continues to be defined by sustained China-, Russia-, DPRK- and Iran-linked cyber pressure against the Western defence industrial base…
The trade-body and membership-organisation collection picture this week has been shaped by continuing ransomware and data-extortion interest in member-data and event-attendee datasets, with the Lynx / ShinyHunters cluster the principal pure-data-extortion threat against the vertical.
The retail collection picture this week has been dominated by the continuing fallout from the 2025 Scattered Spider / DragonForce campaign against UK retailers, with M&S, Co-op and Harrods continuing to feature in trade-press analysis of the cyber-loss cycle.
The maritime collection picture this week is dominated by the convergence of three structural factors: continuing IT-side ransomware pressure against port operators and freight forwarders…