Financial services threat intelligence report — 27 April – 3 May 2026
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.
- Reference: TI-2026-0504-001 (public edition)
- Sector: Financial services, banking, fintech and insurance
- Reporting period: 27 April – 3 May 2026
- Issued: 4 May 2026 · Lead analyst: Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers. The principal observations are a continued lead position for Qilin among ransomware affiliates with 103 confirmed leak-site postings during April, sustained Cl0p and ShinyHunters/WorldLeaks data-extortion activity exploiting trusted file-transfer and SaaS platforms, and a measurable uplift in Scattered-Spider-style social-engineering tradecraft following the M&S / Co-op campaign.
Key Judgements
1. It is highly likely that ransomware and pure data-extortion crews — Qilin, Akira, Cl0p, and the ShinyHunters / WorldLeaks cluster — will continue to drive the majority of the material risk to the vertical over the next reporting cycle, with double and triple extortion tradecraft now baselined. (HIGH confidence)
2. It is likely that Scattered-Spider-style social-engineering of IT helpdesks and managed-service providers, in the pattern observed in the M&S / Co-op intrusions, will be replicated against UK financial services in 2026, particularly where retail-banking helpdesk operations have been outsourced. (MEDIUM-HIGH confidence)
3. There is a realistic possibility that the Citrix NetScaler vulnerabilities CVE-2026-3055 and CVE-2026-4368 announced in early May will be weaponised against financial-services edge appliances within the next two reporting cycles; emergency-patch posture is warranted. (MEDIUM confidence)
2. Sector threat landscape
The financial services vertical continues to absorb the dominant share of organised criminal cyber activity directed at the United Kingdom and European markets, with FS-ISAC reporting in early 2026 that the financial and insurance sub-sector accounted for approximately eight per cent of identified data leaks attributable to ransomware groups in 2024 and that 2024 was, despite a fall in the total number of reported attacks, one of the highest-grossing years on record for ransomware operators in the sector. The same reporting attributes much of this profitability to the maturation of generative-AI-assisted phishing and to the continued availability of ransomware-as-a-service offerings that lower the technical barrier to entry.
The reporting period saw 772 victims claimed across ransomware leak sites globally, distributed across approximately seventy distinct groups. Qilin retains the leading position with 103 victims posted in April, although the gap to second place narrowed from 47 victims in March to 21 in April. Akira posted 48, LockBit 39 (well below their pre-disruption peak), and TheGentlemen and DragonForce both moved up in absolute terms. A growing share of activity — ShinyHunters, WorldLeaks, and Cl0p — now skips encryption entirely and runs as pure data-extortion, with Cl0p in particular continuing to favour the trusted file-transfer / SaaS exploitation pattern that has characterised its operations since the MOVEit campaign.
Geopolitical pressure remains a factor. NCSC issued an alert on 19 January 2026 regarding sustained activity from Russian state-aligned hacktivist groups targeting UK organisations, and the response to evolving events in the Middle East has prompted NCSC to advise UK organisations to review their cyber security posture. Financial services entities with sanctions-regime exposure or visible support for Ukraine remain at heightened risk of disruptive activity from such groups, although the operational impact of hacktivist DDoS in the vertical remains substantially below the impact of organised-crime ransomware.
Regulatory pressure has not eased. The UK Cyber Security Breaches Survey 2025/2026 reported 43% of businesses experiencing a cyber incident in the past 12 months, with phishing remaining both the most common (38%) and the most disruptive type. In the financial-services sub-sector, the Information Commissioner's Office continues to publish breach-notification data which remains the most reliable open-source benchmark for actual incident frequency in UK markets.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
| THREAT ACTOR PROFILE — Qilin | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal — RaaS |
| Primary Motivation | Financial — ransomware and data extortion |
| Sector Targeting | Financial services, healthcare, professional services, manufacturing |
| Geographic Focus | Global; sustained activity against UK, EU, and North American organisations |
| Signature TTPs | Initial access via stolen / brute-forced credentials and exposed RDP / VPN; abuse of legitimate remote-management tooling for persistence; double extortion with fast time-to-encrypt |
| Tooling / Malware Families | Qilin / Agenda Rust- and Go-based encryptor variants; living-off-the-land; AnyDesk, RustDesk and ScreenConnect for hands-on-keyboard |
| Recent Activity | 103 leak-site postings in April 2026 — leading position globally for the fourth consecutive month; financial services among the most-targeted verticals |
| Assessed Threat to Vertical | HIGH — vertical-aligned victimology, mature TTPs, sustained operational tempo |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — Cl0p | |
|---|---|
| Aliases | TA505 affiliate, FIN11-adjacent |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal |
| Primary Motivation | Financial — data extortion |
| Sector Targeting | Financial services, healthcare, public sector — any vertical operating exposed managed file-transfer or SaaS platforms |
| Geographic Focus | Global |
| Signature TTPs | Mass-exploitation of zero-day / n-day vulnerabilities in trusted file-transfer products (MOVEit-style); pure data extortion without encryption; coordinated leak-site posting |
| Tooling / Malware Families | Custom web shells; Truebot loader; Cl0p leak portal |
| Recent Activity | Sustained leak-site activity during the reporting period; continues to favour single-point trust-platform exploitation as its core access strategy |
| Assessed Threat to Vertical | HIGH — disproportionate impact-per-campaign for finance and insurance with file-transfer dependencies |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — Scattered Spider / DragonForce affiliate cluster | |
|---|---|
| Aliases | UNC3944, Octo Tempest, Muddled Libra |
| Suspected Origin | Western (UK / US, English-speaking) |
| Suspected Sponsor | Organised criminal — affiliate of multiple RaaS |
| Primary Motivation | Financial — ransomware, data theft, extortion |
| Sector Targeting | Retail, hospitality, financial services, telecoms, BPO |
| Geographic Focus | Global; high-tempo UK and North American operations |
| Signature TTPs | SIM-swap and helpdesk social engineering; MFA fatigue; abuse of identity providers (Okta, Azure AD); rapid pivot to cloud admin planes |
| Tooling / Malware Families | Living-off-the-land; commercial RMM tooling; DragonForce ransomware payload |
| Recent Activity | Cluster assessed responsible for the M&S and Co-op intrusions in spring 2025; campaign costs estimated £270m–£440m. Tradecraft has become the reference template for follow-on actors targeting UK retail- and SME-banking helpdesks |
| Assessed Threat to Vertical | HIGH — the helpdesk social-engineering vector is poorly mitigated in many UK financial-services support operations |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — TA577 / Pikabot operators | |
|---|---|
| Aliases | Various — initial-access broker cluster |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal |
| Primary Motivation | Financial — initial-access brokering for ransomware affiliates |
| Sector Targeting | Financial services, professional services, manufacturing |
| Geographic Focus | Global — sustained UK activity |
| Signature TTPs | Email thread-hijacking; ZIP/ISO/HTA droppers; living-off-the-land for in-network discovery; hand-off to Qilin / Akira affiliates |
| Tooling / Malware Families | Pikabot, Latrodectus, ScreenConnect |
| Recent Activity | Continued thread-hijacking against UK finance professional inboxes during the reporting period |
| Assessed Threat to Vertical | MEDIUM — material as the access supplier to Qilin / Akira |
| Analytic Confidence | MEDIUM |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1566.002 | Spearphishing Link | Email thread-hijacking with ZIP/HTA droppers observed against UK finance professional inboxes; consistent with Pikabot / Latrodectus delivery. | M |
| Initial Access | T1133 | External Remote Services | CISA KEV expansions on Cisco SD-WAN Manager and Citrix NetScaler create an immediate exposure for finance-sector edge appliances. | H |
| Initial Access | T1199 | Trusted Relationship | Cl0p and ShinyHunters cluster continue to favour single-point trust-platform exploitation (MOVEit-pattern) for mass victimology. | H |
| Impact | T1486 | Data Encrypted for Impact | Qilin, Akira, LockBit, DragonForce affiliates continue to deploy encryptors against the vertical at scale. | H |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Apr 2026 | UK retailers (M&S, Co-op, Harrods) — adjacent | Scattered Spider / DragonForce | Continued reputational and supply-chain spillover; vendor-diligence questionnaires recirculating across UK FS | Public reporting; ICO |
| Apr 2026 | Multiple FS leak-site listings (global) | Qilin, Akira, Cl0p, ShinyHunters | 772 victims claimed across 70 groups in April; financial-services subset includes regional banks, brokerages and insurance brokers | Ransomware leak-site tracking |
| Apr 2026 | UK FS-sector law firm | Play (suspected) | Sensitive client data exposure risk; ICO engagement | Public reporting |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-31431 | Linux Kernel (resource transfer) | 7.8 | Yes | Yes | Apply distro patches; prioritise Internet-facing & multi-tenant hosts |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys; review for known-exploit IOCs |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-41940 | WebPros cPanel / WP Squared / WHM | 9.8 | No | Suspected | Patch; audit panel admin auth events |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager | 8.8 | Yes | Yes | Patch immediately; restrict admin plane to mgmt VLAN |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Rotate SD-WAN passwords; patch |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Patch; review information disclosure logs |
| CVE-2025-2749 | Kentico Xperience | 9.0 | Yes | Yes | Patch; audit upload paths |
| CVE-2025-32975 | Quest KACE SMA | 8.8 | Yes | Suspected | Patch; restrict KACE management UI |
| CVE-2025-48700 | Synacor Zimbra Collaboration | 6.1 | Yes | Yes | Patch; restrict webmail to authenticated users |
| CVE-2024-27199 | JetBrains TeamCity | 7.3 | Yes | Yes | Patch; rotate CI secrets |
7. Indicators of compromise
Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. IP Insights reputation feed currently lists 812,641 distinct IPv4 addresses across active blocklists (snapshot 04 May 2026 08:15 UTC). AS200651 (FlokiNET) currently lists 110 of 131 known IPs as blacklisted (risk score 100/critical); the AS continues to host bulletproof-style infrastructure observed in the reporting period across phishing, RAT C2, and brute-force activity.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force; IP Insights threat 100/critical, 6 active blacklists (Spamhaus, AbuseIPDB-30d, Blocklist.de, ipsum, ShadowWhisperer); Reliance Jio IN |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd (GB) — IP Insights threat 100/critical, 6 blacklists; observed in cross-tenant scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical, 7 blacklists |
| ASN | AS200651 | 04 May 2026 | H | FlokiNET — 110/131 known IPs blacklisted; risk 100/critical; bulletproof-style hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via initial-access broker (Qilin / Akira / DragonForce) | H | H | CRITICAL |
| Mass data-extortion via trusted file-transfer / SaaS exploitation (Cl0p pattern) | M | H | HIGH |
| Helpdesk social engineering / MFA fatigue (Scattered Spider pattern) leading to identity-provider compromise | M | H | HIGH |
| Edge-appliance compromise via Citrix NetScaler CVE-2026-3055 / 4368 | M | H | HIGH |
| Business email compromise targeting finance / treasury function | H | M | HIGH |
| Hacktivist DDoS aligned with geopolitical events | M | L | MEDIUM |
| Supply-chain compromise via shared SaaS / managed-service provider | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Patching priorities for the vertical are dominated by Citrix NetScaler ADC / Gateway (CVE-2026-3055, CVE-2026-4368) and the Linux kernel local-privilege-escalation CVE-2026-31431; both should be treated as emergency patch cycles where present. The CISA KEV April additions — Cisco Catalyst SD-WAN Manager (three CVEs), Kentico, Quest KACE, Synacor Zimbra, JetBrains TeamCity and PaperCut — should be patched on the published federal-deadline schedule (4 May 2026) at the latest. Identity-controls hardening to mitigate Scattered-Spider-style helpdesk social engineering remains the highest-impact defensive investment for retail-banking and insurance-broker support operations, with specific reference to NIST 800-63B identity-proofing and number-matching MFA. ISO/IEC 27001 Annex A controls A.5.13 (information-security policy for supplier relationships) and A.8.10 (information deletion) are direct levers against the Cl0p and ShinyHunters exfiltration patterns.
Disrupt
Disruption priorities are: (a) sustained sharing of the IP Insights blocklist (currently 812,641 entries) and the FS-ISAC member feed into customer perimeter-block lists; (b) coordinated takedown of the FlokiNET-hosted infrastructure observed during the reporting period via the AS200651 abuse channel and CERT-UK; (c) tabletop exercise against the Scattered-Spider helpdesk-compromise scenario for any customer with outsourced retail-banking support; (d) rehearsal of the ransomware-and-double-extortion playbook with a specific time-to-encrypt of under four hours, consistent with current Qilin and Akira affiliate operating tempo.
10. Forward outlook
It is highly likely that ransomware will remain the dominant material-risk vector in the vertical over the next reporting cycle, with Qilin retaining its leading position in absolute leak-site volume. (HIGH confidence; 30-day horizon)
It is likely that Citrix NetScaler CVE-2026-3055 and CVE-2026-4368 will see sustained mass-exploitation against unpatched UK financial-services edge appliances over the next two reporting cycles. (MEDIUM-HIGH confidence; 60-day horizon)
There is a realistic possibility that a UK retail-banking or insurance-broker helpdesk operation will suffer a Scattered-Spider-style identity-provider compromise within the next six reporting cycles. (MEDIUM confidence; 180-day horizon)
There is a realistic possibility that Russian state-aligned hacktivist activity against UK FS will spike in line with geopolitical events, but the operational impact will remain materially below that of organised-crime ransomware. (MEDIUM confidence)
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC — Threat reports | NCSC.GOV.UK | A1 |
| 2 | NCSC alert: Russian state-aligned hacktivist groups, 19 Jan 2026 | NCSC.GOV.UK | A1 |
| 3 | CISA KEV: 8 CVEs added 20 Apr 2026 (Cisco SD-WAN, Kentico, KACE, Zimbra, TeamCity, PaperCut) | CISA | A1 |
| 4 | CISA KEV: CVE-2026-31431 (Linux kernel) added 1 May 2026 | CISA | A1 |
| 5 | FS-ISAC — Heightened cyber threats and operational resilience reporting | FS-ISAC | A2 |
| 6 | UK Cyber Security Breaches Survey 2025/2026 | GOV.UK / DSIT | A1 |
| 7 | April 2026 Ransomware Report — 772 victims, 70 groups | BreachSense | B2 |
| 8 | Akira & Cl0p as most active ransomware groups | Dark Reading | B2 |
| 9 | Marks & Spencer / Co-op — Category 2 cyber-event reporting | Computer Weekly / SecurityAffairs | B2 |
| 10 | IP Insights — IP/ASN/CIDR threat intelligence API (UK Cyber Defence Ltd) | ipinsights.io | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Financial services threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
Financial services threat intelligence report — 16–22 May 2026
The week's collection picture has been dominated by continued exploitation of edge-appliance vulnerabilities (Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973), the Akira and Qilin ransomware crews reaching new weekly leak-site cadence highs…
Financial services threat intelligence report — 4–8 May 2026
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…