Financial services threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
- Reference: TI-2026-0517-001 (public edition)
- Sector: Financial services, banking, fintech and insurance
- Reporting period: 11–17 May 2026
- Issued: 17 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics. Check Point Research published its Q1 2026 retrospective during the week confirming a record 2,122 leak-site victims across 91 active data-leak sites, with Qilin alone claiming 338 victims in the quarter and Qilin / Akira / TheGentlemen / LockBit together responsible for 41 percent of all postings. The sector-relevant operational shift this week was the publication of CISA Emergency Directive 26-03 on 14 May 2026 covering Cisco Catalyst SD-WAN Controller authentication-bypass (CVE-2026-20182), and the addition of CVE-2026-20182 to the KEV catalogue the same day. The Ivanti EPMM CVE-2026-6973 FCEB deadline (10 May) has now passed without UK-FS exploitation publicly attributed but with active exploitation continuing globally. FS-ISAC publicly continued to emphasise the operational resilience pressure across the sector from triple-extortion ransomware blending data theft, encryption and DDoS.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and pure data-extortion crews — Qilin, TheGentlemen, Akira, DragonForce, Cl0p and the Lynx / ShinyHunters cluster — will continue to drive the majority of the material risk to the vertical over the next reporting cycle. The Q1 2026 leak-site numbers (2,122 victims, 91 active DLS, Qilin 338) confirm continued consolidation around fewer, more capable operations rather than easing of tempo (HIGH confidence).
- It is likely that CISA Emergency Directive 26-03 (Cisco Catalyst SD-WAN, CVE-2026-20182) will produce at least one publicly-disclosed UK financial-services exploitation event within the next two reporting cycles. UK FS estates running Cisco Catalyst SD-WAN at branch or perimeter are immediately exposed; the hunt-and-hardening guidance in the CISA supplemental direction is the operational template for next week (HIGH confidence).
- It is likely that Scattered-Spider / DragonForce-style social-engineering of IT helpdesks and outsourced banking BPO operations will continue at the tempo set by the M&S / Co-op campaign that the UK Cyber Monitoring Centre rated a Category 2 cyber hurricane (combined cost estimate £270m–£440m). The English-speaking affiliate cluster remains the most operationally consequential threat to UK FS helpdesk operations (HIGH confidence).
2. Sector threat landscape
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. Check Point Research's Q1 2026 retrospective published during the reporting period attributes 2,122 leak-site victims across the quarter to seventy-plus active data-leak sites, with Qilin leading at 338 postings for the third consecutive quarter. Akira posted significant volume and was singled out for sector selection deliberately optimised for ransom-pressure response — the financial-services sub-sector remains inside that targeting window. FS-ISAC public reporting during the period continues to emphasise the operational resilience burden from triple-extortion ransomware combining data theft, encryption and DDoS, and to highlight rising fraud and supply-chain risks alongside generative-AI-enabled scams.
Edge-appliance and identity-provider exposure remains the single most operationally consequential collection theme for financial services this week. The 14 May addition of CVE-2026-20182 (Cisco Catalyst SD-WAN Controller authentication bypass) to the CISA KEV catalogue, combined with CISA Emergency Directive 26-03 and its supplemental hunt-and-hardening direction, represents a step-change in operational priority — branch-network SD-WAN controllers are now an attested active-exploitation surface. The Ivanti EPMM CVE-2026-6973 FCEB deadline of 10 May has passed; UK FS organisations with EPMM in production should treat unmitigated exposure as a hunt trigger rather than a patch-cycle item. The Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055 and CVE-2026-4368) carried into the reporting period from late April remain on the same active-exploitation footing, as does Palo Alto PAN-OS User-ID portal CVE-2026-0300. Progress MOVEit Automation CVE-2026-4670 (pre-auth RCE, low complexity) remains under active exploitation by Cl0p-style operators with a pure-data-extortion model that has historically disproportionately affected financial services with file-transfer platform dependencies. NCSC's standing F5 BIG-IP Access Policy Manager unauthenticated RCE advisory remains on the UK feed and applies to FS organisations operating F5 in the identity-broker role.
Geopolitical pressure has not eased. NCSC's Middle East cyber posture guidance, refreshed in light of evolving events, remains live for any UK FS entity with regional exposure. NCSC's standing position on Russian state-aligned hacktivism remains live; UK financial-services entities with sanctions-regime exposure or visible support for Ukraine continue to carry an elevated DDoS and disruption risk.
Geopolitical pressure has not eased. NCSC's standing position on Russian state-aligned hacktivism remains live; UK financial services entities with sanctions-regime exposure or visible support for Ukraine continue to carry an elevated DDoS and disruptive-activity risk, although the operational impact remains substantially below organised-crime ransomware. ScarCruft's gaming-platform supply-chain compromise reported by ESET on 5 May 2026 illustrates the continued willingness of DPRK-aligned actors to use third-party software-supply chains as a delivery channel, a pattern that financial-services organisations should track because of their substantial third-party software dependency exposure.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Threat Actor Profile — Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Financial services, healthcare, professional services, manufacturing
- Geographic Focus: Global; sustained UK, EU and North American activity
- Signature TTPs: Initial access via stolen / brute-forced credentials, exposed RDP / VPN and edge-appliance exploitation; abuse of legitimate remote-management tooling; double-extortion model; rapid affiliate iteration
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptor variants; living-off-the-land; AnyDesk, RustDesk and ScreenConnect for hands-on-keyboard
- Recent Activity: 338 leak-site postings in Q1 2026 (Check Point Research) — third consecutive quarter as global leader; continued UK and EU FS-sub-sector victimology in May 2026
- Assessed Threat to Vertical: HIGH — vertical-aligned victimology, mature TTPs, sustained operational tempo
- Analytic Confidence: HIGH
Threat Actor Profile — Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra
- Suspected Origin: Western (UK / US, English-speaking)
- Suspected Sponsor: Organised criminal — affiliate of multiple RaaS
- Primary Motivation: Financial — ransomware, data theft, extortion
- Sector Targeting: Retail, hospitality, financial services, telecoms, BPO
- Geographic Focus: Global; high-tempo UK and North American operations
- Signature TTPs: SIM-swap and helpdesk social engineering; MFA fatigue; abuse of identity providers (Okta, Entra ID); rapid pivot to cloud and SaaS; living-off-the-land; commercial RMM abuse
- Tooling / Malware Families: Living-off-the-land; commercial RMM tooling; DragonForce ransomware payload
- Recent Activity: M&S / Co-op campaign rated Category 2 cyber hurricane by UK Cyber Monitoring Centre, combined cost £270m–£440m; affiliate tradecraft continues to be replicated against UK BPO operations
- Assessed Threat to Vertical: HIGH — the helpdesk social-engineering vector is poorly mitigated in many UK FS support operations
- Analytic Confidence: HIGH
Threat Actor Profile — Cl0p
- Aliases: TA505 affiliate, FIN11-adjacent
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal
- Primary Motivation: Financial — pure data extortion
- Sector Targeting: Financial services, healthcare, public sector — any vertical with exposed managed file-transfer or SaaS platforms
- Geographic Focus: Global
- Signature TTPs: Mass-exploitation of zero-day / n-day vulnerabilities in trusted file-transfer products (MOVEit-style); pure data extortion without on-disk encryption; mass leak-site campaigns
- Tooling / Malware Families: Custom web shells; Truebot loader; Cl0p leak portal
- Recent Activity: Sustained leak-site activity through May 2026; Progress MOVEit Automation CVE-2026-4670 continues to feed operator targeting
- Assessed Threat to Vertical: HIGH — disproportionate impact-per-campaign for finance and insurance with file-transfer dependencies
- Analytic Confidence: HIGH
Threat Actor Profile — TheGentlemen
- Aliases: —
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware
- Sector Targeting: Financial services, professional services, manufacturing
- Geographic Focus: Global; growing UK and EU activity
- Signature TTPs: Initial access via stolen credentials and edge-appliance exploitation; rapid lateral movement; double-extortion model
- Tooling / Malware Families: Custom encryptor; commodity LOLBins; abuse of native admin tooling
- Recent Activity: Sustained top-five leak-site presence across Q1 2026 (Check Point Research) — among the four operations (with Qilin, Akira, LockBit) responsible for 41 percent of all Q1 postings
- Assessed Threat to Vertical: HIGH — rising tempo and confirmed UK FS victimology
- Analytic Confidence: MEDIUM-HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Cisco Catalyst SD-WAN Controller CVE-2026-20182 (added to KEV 14 May, CISA ED 26-03) and Ivanti EPMM CVE-2026-6973 (active exploitation, FCEB deadline 10 May passed) place authentication-bypass and pre-auth RCE on UK FS edge surfaces. Progress MOVEit Automation CVE-2026-4670 continues to feed Cl0p-style operator targeting. | H |
| Initial Access | T1133 | External Remote Services | Citrix NetScaler ADC / Gateway, Palo Alto PAN-OS User-ID portal and F5 BIG-IP APM expose remote-access infrastructure to authentication and configuration-plane abuse. | H |
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts | Scattered Spider / DragonForce affiliate cluster continues to compromise Okta and Entra ID admin roles via helpdesk social-engineering — M&S / Co-op pattern. | H |
| Initial Access | T1199 | Trusted Relationship | Cl0p and Lynx clusters continue to favour single-point trust-platform exploitation (MOVEit-pattern) for mass victimology. | H |
| Impact | T1486 | Data Encrypted for Impact | Qilin, TheGentlemen, Akira, DragonForce affiliates continue to deploy encryptors against UK FS at scale; Q1 2026 leak-site total 2,122 victims (Check Point Research). | H |
| Impact | T1657 | Financial Theft | Sustained credential-harvesting and BEC tradecraft against UK SME-banking customers, with measurable AI-assisted phishing tooling growth. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| May 2026 | Multiple FS leak-site listings (global) | Qilin, TheGentlemen, Akira, DragonForce | 2,122 Q1 2026 victims claimed across 91 active DLS (Check Point Research) — FS subset includes regional banks, brokerages and insurance carriers across UK, EU and North America | Check Point Research; Ransomware.live |
| 14 May 2026 | Cisco Catalyst SD-WAN exploitation surface (sector-wide) | Multiple — CISA ED 26-03 | CVE-2026-20182 authentication-bypass added to KEV 14 May; CISA Emergency Directive 26-03 and supplemental hunt-and-hardening guidance issued; UK FS estates running SD-WAN at branch / perimeter immediately exposed | CISA; NCSC |
| Ongoing | M&S / Co-op cyber attack cost envelope | Scattered Spider / DragonForce affiliate cluster | UK Cyber Monitoring Centre Category 2 cyber hurricane rating (combined £270m–£440m); replicable affiliate playbook against UK retail-banking BPO operations | UK Cyber Monitoring Centre; Computer Weekly |
| May 2026 | Cl0p / MOVEit Automation continued exploitation | Cl0p (suspected) | Pre-auth RCE in Progress MOVEit Automation prior to 2025.1.5 / 2025.0.9 / 2024.1.8 — operator selection cycle continues; pure-data-extortion model | Progress advisory; vendor reporting |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller (authentication bypass) | 9.8 | Yes (14 May) | Yes | Patch immediately; align with CISA ED 26-03 / Supplemental Direction; hunt for compromise; FCEB hardening guidance applies |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline now passed (10 May); rotate admin sessions; review MDM admin auth logs |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch; rotate session keys; hunt for indicators |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation (< 2025.1.5 / 2025.0.9 / 2024.1.8) | 9.8 | Yes | Yes (low-complexity) | Patch; audit MFT operator and admin authentication |
| CVE-2026-8043 | Ivanti Xtraction (external control of file name, RCE) | 9.6 | — | Pending | Patch; restrict reporting console exposure |
| CVE-2026-44277 | Fortinet FortiAuthenticator (improper access control) | 9.1 | — | Pending | Patch; restrict management plane exposure |
| CVE-2026-26083 | Fortinet FortiSandbox (missing authorisation, RCE) | 9.1 | — | Pending | Patch; restrict sandbox API exposure |
| CVE-2026-34260 | SAP S/4HANA Enterprise Search for ABAP | 9.6 | — | Pending | Patch; restrict access to enterprise search endpoints |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force pattern — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 7 active blacklists; carry-forward IOC |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298) — IP Insights threat 100/critical; mass scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical |
| ASN | AS200651 | Ongoing | H | FlokiNET — 112/134 known IPs blacklisted; risk 100/critical; risk breakdown low 19 / med 3 / high 31 / critical 81; bulletproof hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Edge-appliance / SD-WAN exploitation chain (Cisco SD-WAN ED 26-03, Citrix, Ivanti EPMM, PA User-ID) leading to ransomware deployment | H | H | CRITICAL |
| Helpdesk social-engineering of outsourced banking BPO operations leading to MFA-bypass and identity-provider compromise | H | H | CRITICAL |
| Pure data extortion via trusted file-transfer / SaaS platform compromise (MOVEit pattern) | M | H | HIGH |
| AI-assisted phishing of corporate-banking and insurance-broker inboxes leading to BEC and wire fraud | H | M | HIGH |
| DDoS / disruptive activity from Russian state-aligned hacktivist clusters against sanctions-exposed FS entities | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on three concurrent threads. First, Cisco Catalyst SD-WAN Controller telemetry: ensure that vManage, vSmart and vBond control-plane authentication, configuration changes, and template-push events are being centrally ingested, and apply the hunt-and-hardening hypotheses set out in CISA Supplemental Direction ED 26-03 to the past sixty days of telemetry. Second, edge-appliance exploitation telemetry across Citrix NetScaler, Ivanti EPMM and Palo Alto PAN-OS — sustain the admin-plane and User-ID portal coverage from prior cycles. Third, identity-provider helpdesk social-engineering: detect MFA fatigue, SIM-swap precursors and risky-sign-in patterns against Okta and Entra ID — Scattered Spider / DragonForce affiliate tradecraft remains the dominant social-engineering threat to UK FS helpdesk operations.
Defend
Patch posture is the single most operationally consequential defensive action for the next reporting cycle. The combination of CVE-2026-20182 (Cisco SD-WAN, ED 26-03), CVE-2026-6973 (Ivanti EPMM, FCEB deadline passed), CVE-2026-0300 (PAN-OS, FCEB deadline 27 May), CVE-2026-3055 / CVE-2026-4368 (NetScaler), CVE-2026-4670 (MOVEit Automation) and the Ivanti Xtraction CVE-2026-8043, Fortinet FortiAuthenticator CVE-2026-44277, Fortinet FortiSandbox CVE-2026-26083 and SAP S/4HANA CVE-2026-34260 additions from the May 2026 Patch Tuesday cycle is the prioritised patching set for the vertical. Identity controls deserve a particular focus on outsourced helpdesk operations: enforce risk-based MFA on privileged accounts, prohibit voice-channel password resets, and audit Okta / Entra ID admin-role assignments. Where F5 BIG-IP APM is operated in the identity-broker role, the NCSC unauthenticated RCE advisory mitigation should be in place. Segment file-transfer platforms (MOVEit, GoAnywhere, Globalscape) from general corporate networks.
Disrupt
Disruption priorities for the next reporting cycle are concentrated in two areas. First, takedown coordination on phishing infrastructure spoofing UK FS brands: continue using APWG and the NCSC takedown channel as the primary path. Second, FS-ISAC and CiSP intelligence exchange on Scattered Spider / DragonForce affiliate TTP signatures observed against UK retail-banking BPO operations — the M&S / Co-op campaign cost envelope (£270m–£440m, Category 2 cyber hurricane rating) is the reference precedent the sector is now planning against.
10. Forward outlook
It is highly likely that the AI-driven patch-wave dynamic will continue to dominate the operational picture for the next reporting cycle, with at least one further major edge-appliance or identity-provider CVE expected to enter active exploitation within the cycle. Cisco Catalyst SD-WAN (ED 26-03) is the active reference case. It is likely that Qilin, TheGentlemen, Akira and DragonForce will continue to lead UK FS leak-site exposure, with the Lynx and ShinyHunters / WorldLeaks clusters continuing to grow tempo. It is likely that pure-data-extortion via trusted file-transfer or SaaS-platform compromise will produce at least one publicly-disclosed UK FS or insurance-broker incident within the cycle (MOVEit pattern). There is a realistic possibility of a nationally-significant DDoS incident against UK FS entities visibly supporting Ukraine or enforcing sanctions, particularly during high-profile geopolitical developments.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Reports & Advisories (rolling) | NCSC | A1 |
| 2 | NCSC – Cisco Catalyst SD-WAN advisory and ED 26-03 alignment (May 2026) | NCSC / CISA | A1 |
| 3 | NCSC – Citrix NetScaler ADC / Gateway CVE-2026-3055 / CVE-2026-4368 | NCSC | A1 |
| 4 | NCSC – F5 BIG-IP Access Policy Manager unauthenticated RCE advisory | NCSC | A1 |
| 5 | NCSC – Middle East cyber posture review guidance | NCSC | A1 |
| 6 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 7 | CISA Alert – CVE-2026-20182 Cisco Catalyst SD-WAN Controller added to KEV (14 May 2026) | CISA | A1 |
| 8 | CISA Emergency Directive 26-03 – Mitigate Cisco SD-WAN Vulnerabilities | CISA | A1 |
| 9 | CISA Alert – Ivanti EPMM CVE-2026-6973 active exploitation | CISA | A1 |
| 10 | Check Point Research – State of Ransomware Q1 2026 | Check Point Research | B2 |
| 11 | Breachsense – April / Q1 2026 ransomware tracking | Breachsense | B2 |
| 12 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 13 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Financial services threat intelligence report — 4–8 May 2026
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…
Financial services threat intelligence report — 16–22 May 2026
The week's collection picture has been dominated by continued exploitation of edge-appliance vulnerabilities (Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973), the Akira and Qilin ransomware crews reaching new weekly leak-site cadence highs…
Financial services threat intelligence report — 27 April – 3 May 2026
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.