Financial services threat intelligence report — 16–22 May 2026
The week's collection picture has been dominated by continued exploitation of edge-appliance vulnerabilities (Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973), the Akira and Qilin ransomware crews reaching new weekly leak-site cadence highs…
- Reference: TI-2026-0522-001 (public edition)
- Sector: Financial services, banking, fintech and insurance
- Reporting period: 16–22 May 2026
- Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance vertical during the period 16 May 2026 to 22 May 2026. The week's collection picture has been dominated by continued exploitation of edge-appliance vulnerabilities (Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973), the Akira and Qilin ransomware crews reaching new weekly leak-site cadence highs, and the consolidation of the Scattered Spider / DragonForce / LockBit operational alliance into a coherent extortion cartel actively targeting banking BPO and fintech outsourced helpdesks. Sources are graded throughout against the Admiralty system, and analytic judgements are accompanied by an explicit confidence rating.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and pure data-extortion crews — Qilin, TheGentlemen, Akira, DragonForce, Cl0p and the Lynx / ShinyHunters cluster — will continue to drive the majority of the materially-disruptive activity affecting UK and European financial-services entities over the next reporting cycle, with the Scattered Spider IAB front-end continuing to focus on outsourced helpdesks and BPO vendors. (HIGH confidence)
- It is likely that CVE-2026-20182 (Cisco Catalyst SD-WAN, CVSS 10.0) will produce at least one publicly-disclosed UK financial-services exploitation event within the next two reporting cycles. CISA, NCSC-UK, NSA and partners have published joint guidance citing active in-the-wild exploitation by UAT-8616, with post-exploitation activity including SSH key addition, NETCONF manipulation and privilege escalation to root. (MEDIUM confidence)
- It is likely that the Ivanti EPMM CVE-2026-6973 chain (CVSS 7.2, in CISA KEV from 7 May 2026) will continue to be exploited against EPMM tenants whose admin credentials were harvested by the earlier CVE-2026-1340 wave in January 2026. UK FS organisations operating on-prem EPMM should treat any admin credential issued prior to 1 February 2026 as untrusted until rotated. (MEDIUM confidence)
- It is highly likely that AI-driven KYC bypass — real-time deepfake voice and video, synthetic identity generation, automated spear-phish targeting of C-suite — will continue to grow as a fraud-adjacent risk for retail banking and insurance carriers, per FS-ISAC's 2026 AI hardening advisory. (HIGH confidence)
2. Sector threat landscape
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. Check Point Research's Q1 2026 retrospective places Qilin as the most active ransomware operation for the third consecutive quarter, with 338 disclosed victims; TheGentlemen reached 424 named victims on its leak site by 18 May; Akira passed 1,488 cumulative leak-site victims with its most recent disclosure on 20 May. The four most active groups — Qilin, Akira, TheGentlemen and LockBit — together accounted for 41% of all named victims in Q1, a notable consolidation from prior quarters and consistent with the formal LockBit / Qilin / DragonForce alliance reporting first surfaced in spring 2026.
Edge-appliance and identity-provider exposure remains the single most operationally consequential collection theme for financial services this week. CVE-2026-20182 against the Cisco Catalyst SD-WAN Controller and Manager has been added to CISA's Known Exploited Vulnerabilities catalogue under Emergency Directive 26-03 and is the subject of a joint advisory from CISA, NSA, NCSC-UK, ASD's ACSC, CCCS and NCSC-NZ. Cisco Talos has confirmed in-the-wild exploitation by activity cluster UAT-8616, with post-exploitation tradecraft centred on SSH key addition, NETCONF manipulation across the SD-WAN fabric, and escalation to root. Any UK FS organisation operating Catalyst SD-WAN Controller or Manager should treat this as the highest-priority patch action of the reporting cycle.
The Scattered Spider / DragonForce campaign that materially disrupted M&S, Co-op and Harrods in April–May 2025 has continued to shape the threat picture, but the operational pivot in 2026 is towards banking BPO, outsourced helpdesk and the customer-service supply chain of regulated FS firms. The IAB front-end is now well-resourced enough to operate against helpdesk estates outside its traditional English-language target set. UK retail-banking clients should assume their inbound helpdesk channel is a credible attack surface and exercise their voice-authentication, callback and ID-verification controls against an explicit scenario before the next quarter close.
Geopolitical pressure on the vertical has not eased. NCSC-UK's Middle East cyber posture guidance remains live for any UK FS entity with regional exposure, and the long-standing Russian state-aligned hacktivist posture against UK FS firms with sanctions-regime exposure or visible support for Ukraine remains a credible source of disruption-grade DDoS and brand-damage activity. The FS-ISAC operational resilience advisory and the ICO's breach disclosure trend data continue to point to ransomware and pure data-extortion as the dominant resilience test cases through 2026.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.
| THREAT ACTOR PROFILE — Qilin (a.k.a. Agenda, Qilin.B) | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russia |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial — extortion / data theft |
| Sector Focus | Financial services, professional services, healthcare, manufacturing |
| Tooling | Qilin.B encryptor (Rust/Go), SystemBC proxy, AnyDesk, Cobalt Strike, mimikatz, rclone for staging exfiltration |
| TTP Highlights | Initial access via VPN credentials purchased from IABs; rapid privilege escalation via DCSync; ESXi-aware encryption variant; double-extortion with leak-site countdown timer |
| Reporting Cycle Activity | 338 named victims in Q1 2026 (Check Point Research); leak-site posting cadence sustained through the reporting period; FS-sector subset reaffirmed as a priority target by H-ISAC / FS-ISAC cross-sector exchange |
| Confidence | HIGH — well-corroborated across vendor reporting and partner exchange |
| Admiralty | B2 |
| Reference | Refs 1, 4, 5 |
| THREAT ACTOR PROFILE — Scattered Spider / DragonForce affiliate cluster | |
|---|---|
| Aliases | UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine |
| Suspected Origin | UK / US / English-speaking community |
| Suspected Sponsor | Criminal (IAB front-end into DragonForce / LockBit / Qilin cartel) |
| Primary Motivation | Financial — extortion via partner ransomware |
| Sector Focus | Retail, hospitality, banking BPO, telecommunications, insurance |
| Tooling | Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue / push bombing, OAuth consent-phishing, AnyDesk / TeamViewer / ScreenConnect for hands-on-keyboard |
| TTP Highlights | Helpdesk social engineering with pre-built identity-verification scripts; targeting of identity-provider admin accounts; rapid pivot to ESXi for mass-encryption; DragonForce or partner-affiliated encryptor for the final disruption stage |
| Reporting Cycle Activity | Continued helpdesk-targeted voice-phishing campaign across UK BPO partners — Sophos and CrowdStrike attribute fresh activity during the reporting period; no confirmed UK FS victim yet publicly disclosed for the week |
| Confidence | HIGH — multiply-sourced including NCSC, Sophos X-Ops, CrowdStrike, Mandiant |
| Admiralty | A2 |
| Reference | Refs 3, 7, 11 |
| THREAT ACTOR PROFILE — Cl0p | |
|---|---|
| Aliases | TA505 affiliate, FIN11-adjacent |
| Suspected Origin | Russia / CIS |
| Suspected Sponsor | Criminal |
| Primary Motivation | Financial — pure data extortion |
| Sector Focus | Cross-sector with marked FS / fintech / professional-services emphasis |
| Tooling | Custom Cl0p data-extortion toolkit; preference for zero-day in managed file transfer products (MOVEit, GoAnywhere, Cleo); leak-site for staged disclosure |
| TTP Highlights | Mass-exploitation of MFT zero-day; selective post-exploitation against high-value tenants; data theft without encryption since 2023; staged public extortion |
| Reporting Cycle Activity | No fresh major MFT exploitation campaign in the reporting period, but residual victim disclosures from earlier 2026 activity continue to appear on the leak site |
| Confidence | MEDIUM |
| Admiralty | B2 |
| Reference | Ref 5 |
| THREAT ACTOR PROFILE — TheGentlemen | |
|---|---|
| Aliases | — |
| Suspected Origin | Unattributed (likely Russian-speaking criminal milieu) |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial — extortion |
| Sector Focus | Cross-sector with sustained FS / professional-services targeting |
| Tooling | Go-based encryptor for Windows, Linux, BSD and NAS targets; SystemBC C2 observed in compromised infrastructure |
| TTP Highlights | Rapid affiliate onboarding; multi-platform encryptor; aggressive leak-site cadence; large affiliate pool driving the headline victim numbers |
| Reporting Cycle Activity | 424 named victims on leak-site by 18 May 2026 (Hacker News, Ransomware.live); compromised C2 server discovery revealed 1,570+ historical victims, suggesting iceberg dynamics |
| Confidence | MEDIUM-HIGH |
| Admiralty | B2 |
| Reference | Refs 12, 13 |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1566.002 | Spear-phishing Link | Helpdesk social-engineering with pre-built identity-verification scripts; voice-phishing of Tier-1 outsourced support staff; OAuth consent-phishing against M365 tenants. | HIGH |
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Cisco Catalyst SD-WAN Controller (CVE-2026-20182) and Ivanti EPMM (CVE-2026-6973) against unpatched internet-facing instances. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud | Reuse of IAB-purchased VPN credentials and harvested EPMM admin credentials originating from the CVE-2026-1340 wave in January 2026. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded PowerShell loaders invoking SystemBC and Cobalt Strike Beacon in Qilin and TheGentlemen operations. | MEDIUM |
| Persistence | T1136.002 | Create Account: Domain | Creation of attacker-controlled domain admin and break-glass accounts as a precursor to encryption / extortion. | MEDIUM |
| Defence Evasion | T1562.001 | Impair Defences: Disable Security Tools | Targeting of EDR control planes via stolen admin credentials; Trend Micro Apex One directory-traversal CVE-2026-34926 added to CISA KEV during the reporting period heightens this risk. | MEDIUM |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Use of rclone, MEGAcmd and AzCopy to push data to attacker-controlled cloud storage prior to encryption stage. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware Qilin.B and DragonForce encryptors; mass-encryption of hypervisor estates. | HIGH |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 18 May 2026 | Vodafone (telecoms; FS supplier) | Lapsus$ | Source-code leak via third-party development tooling; customer data and core network unaffected; demonstrates continued residual Lapsus$ activity against FS supplier base. | Ref 15 |
| 19 May 2026 | THORChain (cryptocurrency) | Unattributed | USD 10.7 million stolen following compromise of one of six vaults; trading halted; reaffirms DeFi platform exposure for fintech clients with crypto-adjacent exposure. | Ref 16 |
| 20 May 2026 | Multiple FS-adjacent victims (TheGentlemen leak) | TheGentlemen RaaS | Leak-site victim count crossed 424; multiple professional-services and FS-adjacent victims disclosed during the reporting period. | Ref 12 |
| 20 May 2026 | Multiple FS-adjacent victims (Akira leak) | Akira RaaS | 30+ victims disclosed in a single day on leak site; cumulative leak-site total surpassed 1,488 named victims since 2023. | Ref 13 |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager | 10.0 | Yes | Active ITW (UAT-8616) | Apply Cisco fixed release immediately; review for SSH key addition, NETCONF anomalies; rotate any privileged credentials on the SD-WAN fabric. |
| CVE-2026-6973 | Ivanti EPMM (on-prem) | 7.2 | Yes | Active ITW | Patch to 12.6.1.1 / 12.7.0.1 / 12.8.0.1; assume any admin credential issued before 1 Feb 2026 is compromised — rotate; review for credential reuse from the CVE-2026-1340 wave. |
| CVE-2026-34926 | Trend Micro Apex One (on-prem) | 8.7 | Yes | Active ITW | Apply Trend Micro patch immediately; review Apex One management console exposure; rotate service-account credentials. |
| CVE-2025-34291 | Langflow (AI workflow platform) | 8.2 | Yes | Active ITW | Patch or remove internet exposure; review for credential exposure via overly-permissive CORS configuration; relevant to FS firms running LangChain-adjacent AI tooling. |
| CVE-2026-3055 / CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 9.3 / 8.6 | Yes | Active ITW (NCSC advisory) | Apply Citrix-supplied builds; force-rotate session keys; review NetScaler authentication and session-persistence telemetry for indicators of post-exploitation. |
| CVE-2026-41091 | Microsoft Defender — Elevation of Privilege | 7.8 | Yes | Confirmed exploitation | Apply May 2026 Patch Tuesday roll-up across the FS Windows estate; verify Defender update channel is current. |
| CVE-2026-45498 | Microsoft Defender — Denial of Service | 6.5 | Yes | Confirmed exploitation | Apply May 2026 Patch Tuesday roll-up; this complements the EoP fix above. |
| CVE-2026-31431 | Linux Kernel — Incorrect Resource Transfer | 7.0 | Yes | Active ITW | Apply distribution-supplied kernel; relevant to Linux-hosted core-banking adjacent estates and to FS-adjacent SaaS platforms running on Linux. |
| CVE-2026-1340 | Ivanti EPMM (on-prem) — earlier wave | 9.1 | Yes | Active ITW (Jan 2026) | If not previously patched, the EPMM tenant must be treated as compromised; admin credentials in use at time of exposure should be rotated. |
| CVE-2008-4250 / CVE-2009-1537 / CVE-2009-3459 / CVE-2010-0249 / CVE-2010-0806 | Legacy Microsoft / Adobe | various | Yes | Active ITW (CISA KEV 20 May 2026) | Audit the FS estate for any legacy Windows / Adobe Reader builds that remain in service — isolate, virtualise or decommission immediately. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IP | 185.243.78.42 | Reporting period | MEDIUM | Bamboozle Web Services MEA FZ-LLC (Dubai); business-hosting; IP Insights flagged 'block'; candidate egress-deny indicator for FS estates with no UAE business need. |
| Domain | support-helpdesk-portal[.]com | Reporting period | MEDIUM | Scattered Spider-style helpdesk-phishing domain pattern; recipient should add to URL-filtering blocklist and alert on internal DNS resolution. |
| Domain | auth0-secure-login[.]net | Reporting period | MEDIUM | Identity-provider impersonation pattern; supports MFA-bypass tradecraft. |
| Hash (SHA-256) | 8e4f...(Qilin.B loader, redacted) | Reporting period | MEDIUM | Recent Qilin.B encryptor loader observed by Sophos / Mandiant; deploy as YARA-based detection alongside the existing Qilin family ruleset. |
| User-Agent | Mozilla/5.0 (compatible; agent/scanner) | Reporting period | LOW | Generic scanner pattern observed against internet-facing FS Java application surfaces; treat as low-fidelity unless paired with brute-force burst or exploit attempt. |
| Tactic | OAuth consent-phishing against M365 tenants | Reporting period | MEDIUM | Continued use of fake 'helpdesk' OAuth applications to obtain M365 token grants; review consented-application inventory monthly and tighten the consent-grant policy. |
| TTP | Voice-phishing of outsourced helpdesk | Reporting period | HIGH | Scattered Spider / DragonForce IAB tradecraft; instrument helpdesk callback authentication; consider voice-biometric or callback-via-trusted-channel for admin password resets. |
| Infrastructure | Self-signed JARM / Cobalt Strike profile | Reporting period | MEDIUM | Continued use of Cobalt Strike Beacon in Qilin / TheGentlemen post-exploitation; pair with Suricata JA3/JARM hunts. |
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Ransomware compromise via outsourced helpdesk social engineering | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation (Cisco SD-WAN / Citrix / Ivanti EPMM) leading to lateral movement | HIGH | HIGH | CRITICAL |
| Pure data extortion (Cl0p-style MFT) against finance / treasury platforms | MEDIUM | HIGH | HIGH |
| AI-driven KYC fraud / synthetic-identity attacks against retail banking | HIGH | MEDIUM | HIGH |
| Geopolitically-motivated DDoS against UK FS firms with sanctions-regime exposure | MEDIUM | MEDIUM | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.
Detect
- Ivanti EPMM admin-action logging: alert on any admin-level configuration change, any new MDM-bound profile and any sudden Apex-API call burst originating from an EPMM admin account that has not rotated since 1 February 2026.
- M365 helpdesk-impersonation patterns: alert on any new OAuth consent grant from a user whose role does not warrant admin-consent applications, and on any new device-code authentication originating outside the documented per-tenant baseline.
- EDR / Apex One / Defender management-console activity: detect unexpected service stops, exclusion-list additions, and console-side configuration changes; correlate with the new CVE-2026-34926 and CVE-2026-41091 indicators.
Defend
- Apply Cisco fixed release for CVE-2026-20182, Ivanti EPMM patches for CVE-2026-6973, Trend Micro Apex One fix for CVE-2026-34926, Citrix NetScaler builds for CVE-2026-3055 / 4368, and the May 2026 Microsoft Patch Tuesday roll-up across the FS Windows estate.
- Force-rotate all EPMM admin credentials in use prior to 1 February 2026 and treat them as untrusted; same logic for any SD-WAN admin credentials in use prior to the Cisco fix.
- Enforce phishing-resistant MFA (FIDO2 / certificate-bound) for all admin accounts on M365, identity providers, EDR consoles, and any privileged-access management tool. Disable SMS and voice-call MFA on admin accounts.
- Tighten the outsourced-helpdesk control package: callback-via-trusted-channel for password resets, voice-biometric or shared-secret challenge for admin actions, and tabletop exercise the helpdesk against an explicit Scattered Spider scenario before quarter close.
Disrupt
- Share confirmed indicators with FS-ISAC and CiSP; use the ipinsights.io TAXII 2.1 endpoint or the equivalent MISP feed to push the indicators in Section 7 into client preventive controls without manual reformatting.
- Confirm BCDR plan covers a ransomware scenario that includes outsourced-helpdesk compromise as the initial-access vector, and validate the offline / immutable backup tier against a tabletop within the next reporting cycle.
- Disable legacy authentication paths on M365 / identity providers; remove IMAP / SMTP-AUTH from tenants where it is not strictly required; require modern-auth on all OAuth grants.
10. Forward outlook
It is highly likely that ransomware-cartel leak-site cadence will continue at or above the weekly tempo observed in May 2026, with Qilin, Akira and TheGentlemen sustaining the largest share of UK FS-adjacent victims. (HIGH confidence)
It is likely that the AI-driven patch-wave dynamic will continue to dominate the operational picture for the next reporting cycle, with at least one further major edge-appliance or identity-provider CVE entering CISA KEV before mid-June 2026. (MEDIUM confidence)
Trigger conditions warranting a forecast revision: confirmed exploitation of CVE-2026-20182 against a UK FS entity (raises vertical risk to CRITICAL); identification of a new ransomware affiliate cluster targeting UK retail banking BPO; or a publicly-disclosed UK FS regulator-led intervention citing AI-driven KYC fraud as the primary loss driver.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.
| Source | Reliability | Information | Credibility |
|---|---|---|---|
| A — Completely reliable | Demonstrated repeated reliability | 1 — Confirmed | Corroborated by independent sources |
| B — Usually reliable | Reliable on most occasions | 2 — Probably true | Logical, consistent, partially corroborated |
| C — Fairly reliable | Sometimes reliable | 3 — Possibly true | Reasonably logical, agrees with some information |
| D — Not usually reliable | Limited prior accuracy | 4 — Doubtful | Possible but lacks logic or corroboration |
| E — Unreliable | History of inaccuracy | 5 — Improbable | Contradicts other reporting |
| F — Cannot be judged | No basis for evaluation | 6 — Cannot be judged | Cannot be assessed |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | Q1 2026 Ransomware Retrospective | Check Point Research | B2 |
| 2 | Ransomware sector reconsolidating — Qilin, LockBit, The Gentlemen expand | Industrial Cyber | B2 |
| 3 | DragonForce / Scattered Spider alliance briefings | Sophos X-Ops; Acronis TRU; BlackFog | A2 |
| 4 | Health-ISAC 2026 Annual Threat Report (FS cross-reference) | Health-ISAC | A2 |
| 5 | Ransomware Q1 2026: Fewer Groups, Bigger Hits, Pre-Staged Access | Cybersecurity Insiders | B2 |
| 6 | FS-ISAC AI hardening advisory; sector risk advisory | FS-ISAC / ABA Banking Journal | A2 |
| 7 | Inside DragonForce — M&S, Co-op, Harrods analysis | Infosecurity Magazine; Sophos | A2 |
| 8 | CISA / NCSC-UK joint advisory on CVE-2026-20182 (Cisco SD-WAN) | CISA; NCSC-UK; NSA; ACSC; CCCS | A1 |
| 9 | Ivanti May 2026 Security Update (CVE-2026-6973) | Ivanti; Help Net Security; SocRadar | A2 |
| 10 | Trend Micro Apex One Critical Bulletin (CVE-2026-34926) | Trend Micro; SecurityWeek; CISA KEV | A2 |
| 11 | Scattered Spider / DragonForce target UK retail in new attacks | SecurityBrief UK | B2 |
| 12 | SystemBC C2 reveals 1,570+ TheGentlemen victims | The Hacker News; ransomware.live | B2 |
| 13 | Akira drops 30 victims in one day | SecurityWeek; The Record | A2 |
| 14 | GitHub Nx Console / TanStack supply-chain compromise | BleepingComputer; Hendry Adrian Daily Recap | B2 |
| 15 | Vodafone source-code leak (Lapsus$) | SecurityWeek; Hendry Adrian Daily Recap | B2 |
| 16 | THORChain USD 10.7m loss | Cybernews; SecurityWeek | B3 |
| 17 | ipinsights.io enrichment & blocklist (87.103.126.54 et al.) | ipinsights.io | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Financial services threat intelligence report — 4–8 May 2026
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…
Financial services threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
Financial services threat intelligence report — 27 April – 3 May 2026
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.