SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Financial services threat intelligence report — 16–22 May 2026

The week's collection picture has been dominated by continued exploitation of edge-appliance vulnerabilities (Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973), the Akira and Qilin ransomware crews reaching new weekly leak-site cadence highs…

  • Reference: TI-2026-0522-001 (public edition)
  • Sector: Financial services, banking, fintech and insurance
  • Reporting period: 16–22 May 2026
  • Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Financial Services, Banking, Fintech and Insurance vertical during the period 16 May 2026 to 22 May 2026. The week's collection picture has been dominated by continued exploitation of edge-appliance vulnerabilities (Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973), the Akira and Qilin ransomware crews reaching new weekly leak-site cadence highs, and the consolidation of the Scattered Spider / DragonForce / LockBit operational alliance into a coherent extortion cartel actively targeting banking BPO and fintech outsourced helpdesks. Sources are graded throughout against the Admiralty system, and analytic judgements are accompanied by an explicit confidence rating.

Key Judgements

The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  • It is highly likely that ransomware and pure data-extortion crews — Qilin, TheGentlemen, Akira, DragonForce, Cl0p and the Lynx / ShinyHunters cluster — will continue to drive the majority of the materially-disruptive activity affecting UK and European financial-services entities over the next reporting cycle, with the Scattered Spider IAB front-end continuing to focus on outsourced helpdesks and BPO vendors. (HIGH confidence)
  • It is likely that CVE-2026-20182 (Cisco Catalyst SD-WAN, CVSS 10.0) will produce at least one publicly-disclosed UK financial-services exploitation event within the next two reporting cycles. CISA, NCSC-UK, NSA and partners have published joint guidance citing active in-the-wild exploitation by UAT-8616, with post-exploitation activity including SSH key addition, NETCONF manipulation and privilege escalation to root. (MEDIUM confidence)
  • It is likely that the Ivanti EPMM CVE-2026-6973 chain (CVSS 7.2, in CISA KEV from 7 May 2026) will continue to be exploited against EPMM tenants whose admin credentials were harvested by the earlier CVE-2026-1340 wave in January 2026. UK FS organisations operating on-prem EPMM should treat any admin credential issued prior to 1 February 2026 as untrusted until rotated. (MEDIUM confidence)
  • It is highly likely that AI-driven KYC bypass — real-time deepfake voice and video, synthetic identity generation, automated spear-phish targeting of C-suite — will continue to grow as a fraud-adjacent risk for retail banking and insurance carriers, per FS-ISAC's 2026 AI hardening advisory. (HIGH confidence)

2. Sector threat landscape

The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets. Check Point Research's Q1 2026 retrospective places Qilin as the most active ransomware operation for the third consecutive quarter, with 338 disclosed victims; TheGentlemen reached 424 named victims on its leak site by 18 May; Akira passed 1,488 cumulative leak-site victims with its most recent disclosure on 20 May. The four most active groups — Qilin, Akira, TheGentlemen and LockBit — together accounted for 41% of all named victims in Q1, a notable consolidation from prior quarters and consistent with the formal LockBit / Qilin / DragonForce alliance reporting first surfaced in spring 2026.

Edge-appliance and identity-provider exposure remains the single most operationally consequential collection theme for financial services this week. CVE-2026-20182 against the Cisco Catalyst SD-WAN Controller and Manager has been added to CISA's Known Exploited Vulnerabilities catalogue under Emergency Directive 26-03 and is the subject of a joint advisory from CISA, NSA, NCSC-UK, ASD's ACSC, CCCS and NCSC-NZ. Cisco Talos has confirmed in-the-wild exploitation by activity cluster UAT-8616, with post-exploitation tradecraft centred on SSH key addition, NETCONF manipulation across the SD-WAN fabric, and escalation to root. Any UK FS organisation operating Catalyst SD-WAN Controller or Manager should treat this as the highest-priority patch action of the reporting cycle.

The Scattered Spider / DragonForce campaign that materially disrupted M&S, Co-op and Harrods in April–May 2025 has continued to shape the threat picture, but the operational pivot in 2026 is towards banking BPO, outsourced helpdesk and the customer-service supply chain of regulated FS firms. The IAB front-end is now well-resourced enough to operate against helpdesk estates outside its traditional English-language target set. UK retail-banking clients should assume their inbound helpdesk channel is a credible attack surface and exercise their voice-authentication, callback and ID-verification controls against an explicit scenario before the next quarter close.

Geopolitical pressure on the vertical has not eased. NCSC-UK's Middle East cyber posture guidance remains live for any UK FS entity with regional exposure, and the long-standing Russian state-aligned hacktivist posture against UK FS firms with sanctions-regime exposure or visible support for Ukraine remains a credible source of disruption-grade DDoS and brand-damage activity. The FS-ISAC operational resilience advisory and the ICO's breach disclosure trend data continue to point to ransomware and pure data-extortion as the dominant resilience test cases through 2026.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.

THREAT ACTOR PROFILE — Qilin (a.k.a. Agenda, Qilin.B)
AliasesAgenda, Qilin.B
Suspected OriginRussia
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial — extortion / data theft
Sector FocusFinancial services, professional services, healthcare, manufacturing
ToolingQilin.B encryptor (Rust/Go), SystemBC proxy, AnyDesk, Cobalt Strike, mimikatz, rclone for staging exfiltration
TTP HighlightsInitial access via VPN credentials purchased from IABs; rapid privilege escalation via DCSync; ESXi-aware encryption variant; double-extortion with leak-site countdown timer
Reporting Cycle Activity338 named victims in Q1 2026 (Check Point Research); leak-site posting cadence sustained through the reporting period; FS-sector subset reaffirmed as a priority target by H-ISAC / FS-ISAC cross-sector exchange
ConfidenceHIGH — well-corroborated across vendor reporting and partner exchange
AdmiraltyB2
ReferenceRefs 1, 4, 5
THREAT ACTOR PROFILE — Scattered Spider / DragonForce affiliate cluster
AliasesUNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
Suspected OriginUK / US / English-speaking community
Suspected SponsorCriminal (IAB front-end into DragonForce / LockBit / Qilin cartel)
Primary MotivationFinancial — extortion via partner ransomware
Sector FocusRetail, hospitality, banking BPO, telecommunications, insurance
ToolingVoice-phishing of IT helpdesks, SIM-swap, MFA fatigue / push bombing, OAuth consent-phishing, AnyDesk / TeamViewer / ScreenConnect for hands-on-keyboard
TTP HighlightsHelpdesk social engineering with pre-built identity-verification scripts; targeting of identity-provider admin accounts; rapid pivot to ESXi for mass-encryption; DragonForce or partner-affiliated encryptor for the final disruption stage
Reporting Cycle ActivityContinued helpdesk-targeted voice-phishing campaign across UK BPO partners — Sophos and CrowdStrike attribute fresh activity during the reporting period; no confirmed UK FS victim yet publicly disclosed for the week
ConfidenceHIGH — multiply-sourced including NCSC, Sophos X-Ops, CrowdStrike, Mandiant
AdmiraltyA2
ReferenceRefs 3, 7, 11
THREAT ACTOR PROFILE — Cl0p
AliasesTA505 affiliate, FIN11-adjacent
Suspected OriginRussia / CIS
Suspected SponsorCriminal
Primary MotivationFinancial — pure data extortion
Sector FocusCross-sector with marked FS / fintech / professional-services emphasis
ToolingCustom Cl0p data-extortion toolkit; preference for zero-day in managed file transfer products (MOVEit, GoAnywhere, Cleo); leak-site for staged disclosure
TTP HighlightsMass-exploitation of MFT zero-day; selective post-exploitation against high-value tenants; data theft without encryption since 2023; staged public extortion
Reporting Cycle ActivityNo fresh major MFT exploitation campaign in the reporting period, but residual victim disclosures from earlier 2026 activity continue to appear on the leak site
ConfidenceMEDIUM
AdmiraltyB2
ReferenceRef 5
THREAT ACTOR PROFILE — TheGentlemen
Aliases
Suspected OriginUnattributed (likely Russian-speaking criminal milieu)
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial — extortion
Sector FocusCross-sector with sustained FS / professional-services targeting
ToolingGo-based encryptor for Windows, Linux, BSD and NAS targets; SystemBC C2 observed in compromised infrastructure
TTP HighlightsRapid affiliate onboarding; multi-platform encryptor; aggressive leak-site cadence; large affiliate pool driving the headline victim numbers
Reporting Cycle Activity424 named victims on leak-site by 18 May 2026 (Hacker News, Ransomware.live); compromised C2 server discovery revealed 1,570+ historical victims, suggesting iceberg dynamics
ConfidenceMEDIUM-HIGH
AdmiraltyB2
ReferenceRefs 12, 13

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1566.002Spear-phishing LinkHelpdesk social-engineering with pre-built identity-verification scripts; voice-phishing of Tier-1 outsourced support staff; OAuth consent-phishing against M365 tenants.HIGH
Initial AccessT1190Exploit Public-Facing ApplicationMass exploitation of Cisco Catalyst SD-WAN Controller (CVE-2026-20182) and Ivanti EPMM (CVE-2026-6973) against unpatched internet-facing instances.HIGH
Initial AccessT1078.004Valid Accounts: CloudReuse of IAB-purchased VPN credentials and harvested EPMM admin credentials originating from the CVE-2026-1340 wave in January 2026.HIGH
ExecutionT1059.001Command and Scripting: PowerShellEncoded PowerShell loaders invoking SystemBC and Cobalt Strike Beacon in Qilin and TheGentlemen operations.MEDIUM
PersistenceT1136.002Create Account: DomainCreation of attacker-controlled domain admin and break-glass accounts as a precursor to encryption / extortion.MEDIUM
Defence EvasionT1562.001Impair Defences: Disable Security ToolsTargeting of EDR control planes via stolen admin credentials; Trend Micro Apex One directory-traversal CVE-2026-34926 added to CISA KEV during the reporting period heightens this risk.MEDIUM
ExfiltrationT1567.002Exfiltration to Cloud StorageUse of rclone, MEGAcmd and AzCopy to push data to attacker-controlled cloud storage prior to encryption stage.HIGH
ImpactT1486Data Encrypted for ImpactESXi-aware Qilin.B and DragonForce encryptors; mass-encryption of hypervisor estates.HIGH

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
18 May 2026Vodafone (telecoms; FS supplier)Lapsus$Source-code leak via third-party development tooling; customer data and core network unaffected; demonstrates continued residual Lapsus$ activity against FS supplier base.Ref 15
19 May 2026THORChain (cryptocurrency)UnattributedUSD 10.7 million stolen following compromise of one of six vaults; trading halted; reaffirms DeFi platform exposure for fintech clients with crypto-adjacent exposure.Ref 16
20 May 2026Multiple FS-adjacent victims (TheGentlemen leak)TheGentlemen RaaSLeak-site victim count crossed 424; multiple professional-services and FS-adjacent victims disclosed during the reporting period.Ref 12
20 May 2026Multiple FS-adjacent victims (Akira leak)Akira RaaS30+ victims disclosed in a single day on leak site; cumulative leak-site total surpassed 1,488 named victims since 2023.Ref 13

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN Controller / Manager10.0YesActive ITW (UAT-8616)Apply Cisco fixed release immediately; review for SSH key addition, NETCONF anomalies; rotate any privileged credentials on the SD-WAN fabric.
CVE-2026-6973Ivanti EPMM (on-prem)7.2YesActive ITWPatch to 12.6.1.1 / 12.7.0.1 / 12.8.0.1; assume any admin credential issued before 1 Feb 2026 is compromised — rotate; review for credential reuse from the CVE-2026-1340 wave.
CVE-2026-34926Trend Micro Apex One (on-prem)8.7YesActive ITWApply Trend Micro patch immediately; review Apex One management console exposure; rotate service-account credentials.
CVE-2025-34291Langflow (AI workflow platform)8.2YesActive ITWPatch or remove internet exposure; review for credential exposure via overly-permissive CORS configuration; relevant to FS firms running LangChain-adjacent AI tooling.
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC / Gateway9.3 / 8.6YesActive ITW (NCSC advisory)Apply Citrix-supplied builds; force-rotate session keys; review NetScaler authentication and session-persistence telemetry for indicators of post-exploitation.
CVE-2026-41091Microsoft Defender — Elevation of Privilege7.8YesConfirmed exploitationApply May 2026 Patch Tuesday roll-up across the FS Windows estate; verify Defender update channel is current.
CVE-2026-45498Microsoft Defender — Denial of Service6.5YesConfirmed exploitationApply May 2026 Patch Tuesday roll-up; this complements the EoP fix above.
CVE-2026-31431Linux Kernel — Incorrect Resource Transfer7.0YesActive ITWApply distribution-supplied kernel; relevant to Linux-hosted core-banking adjacent estates and to FS-adjacent SaaS platforms running on Linux.
CVE-2026-1340Ivanti EPMM (on-prem) — earlier wave9.1YesActive ITW (Jan 2026)If not previously patched, the EPMM tenant must be treated as compromised; admin credentials in use at time of exposure should be rotated.
CVE-2008-4250 / CVE-2009-1537 / CVE-2009-3459 / CVE-2010-0249 / CVE-2010-0806Legacy Microsoft / AdobevariousYesActive ITW (CISA KEV 20 May 2026)Audit the FS estate for any legacy Windows / Adobe Reader builds that remain in service — isolate, virtualise or decommission immediately.

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.

TypeIndicatorFirst SeenConf.Notes
IP185.243.78.42Reporting periodMEDIUMBamboozle Web Services MEA FZ-LLC (Dubai); business-hosting; IP Insights flagged 'block'; candidate egress-deny indicator for FS estates with no UAE business need.
Domainsupport-helpdesk-portal[.]comReporting periodMEDIUMScattered Spider-style helpdesk-phishing domain pattern; recipient should add to URL-filtering blocklist and alert on internal DNS resolution.
Domainauth0-secure-login[.]netReporting periodMEDIUMIdentity-provider impersonation pattern; supports MFA-bypass tradecraft.
Hash (SHA-256)8e4f...(Qilin.B loader, redacted)Reporting periodMEDIUMRecent Qilin.B encryptor loader observed by Sophos / Mandiant; deploy as YARA-based detection alongside the existing Qilin family ruleset.
User-AgentMozilla/5.0 (compatible; agent/scanner)Reporting periodLOWGeneric scanner pattern observed against internet-facing FS Java application surfaces; treat as low-fidelity unless paired with brute-force burst or exploit attempt.
TacticOAuth consent-phishing against M365 tenantsReporting periodMEDIUMContinued use of fake 'helpdesk' OAuth applications to obtain M365 token grants; review consented-application inventory monthly and tighten the consent-grant policy.
TTPVoice-phishing of outsourced helpdeskReporting periodHIGHScattered Spider / DragonForce IAB tradecraft; instrument helpdesk callback authentication; consider voice-biometric or callback-via-trusted-channel for admin password resets.
InfrastructureSelf-signed JARM / Cobalt Strike profileReporting periodMEDIUMContinued use of Cobalt Strike Beacon in Qilin / TheGentlemen post-exploitation; pair with Suricata JA3/JARM hunts.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.

Threat ScenarioLikelihoodImpactComposite
Ransomware compromise via outsourced helpdesk social engineeringHIGHHIGHCRITICAL
Edge-appliance exploitation (Cisco SD-WAN / Citrix / Ivanti EPMM) leading to lateral movementHIGHHIGHCRITICAL
Pure data extortion (Cl0p-style MFT) against finance / treasury platformsMEDIUMHIGHHIGH
AI-driven KYC fraud / synthetic-identity attacks against retail bankingHIGHMEDIUMHIGH
Geopolitically-motivated DDoS against UK FS firms with sanctions-regime exposureMEDIUMMEDIUMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.

Detect

  • Ivanti EPMM admin-action logging: alert on any admin-level configuration change, any new MDM-bound profile and any sudden Apex-API call burst originating from an EPMM admin account that has not rotated since 1 February 2026.
  • M365 helpdesk-impersonation patterns: alert on any new OAuth consent grant from a user whose role does not warrant admin-consent applications, and on any new device-code authentication originating outside the documented per-tenant baseline.
  • EDR / Apex One / Defender management-console activity: detect unexpected service stops, exclusion-list additions, and console-side configuration changes; correlate with the new CVE-2026-34926 and CVE-2026-41091 indicators.

Defend

  • Apply Cisco fixed release for CVE-2026-20182, Ivanti EPMM patches for CVE-2026-6973, Trend Micro Apex One fix for CVE-2026-34926, Citrix NetScaler builds for CVE-2026-3055 / 4368, and the May 2026 Microsoft Patch Tuesday roll-up across the FS Windows estate.
  • Force-rotate all EPMM admin credentials in use prior to 1 February 2026 and treat them as untrusted; same logic for any SD-WAN admin credentials in use prior to the Cisco fix.
  • Enforce phishing-resistant MFA (FIDO2 / certificate-bound) for all admin accounts on M365, identity providers, EDR consoles, and any privileged-access management tool. Disable SMS and voice-call MFA on admin accounts.
  • Tighten the outsourced-helpdesk control package: callback-via-trusted-channel for password resets, voice-biometric or shared-secret challenge for admin actions, and tabletop exercise the helpdesk against an explicit Scattered Spider scenario before quarter close.

Disrupt

  • Share confirmed indicators with FS-ISAC and CiSP; use the ipinsights.io TAXII 2.1 endpoint or the equivalent MISP feed to push the indicators in Section 7 into client preventive controls without manual reformatting.
  • Confirm BCDR plan covers a ransomware scenario that includes outsourced-helpdesk compromise as the initial-access vector, and validate the offline / immutable backup tier against a tabletop within the next reporting cycle.
  • Disable legacy authentication paths on M365 / identity providers; remove IMAP / SMTP-AUTH from tenants where it is not strictly required; require modern-auth on all OAuth grants.

10. Forward outlook

It is highly likely that ransomware-cartel leak-site cadence will continue at or above the weekly tempo observed in May 2026, with Qilin, Akira and TheGentlemen sustaining the largest share of UK FS-adjacent victims. (HIGH confidence)

It is likely that the AI-driven patch-wave dynamic will continue to dominate the operational picture for the next reporting cycle, with at least one further major edge-appliance or identity-provider CVE entering CISA KEV before mid-June 2026. (MEDIUM confidence)

Trigger conditions warranting a forecast revision: confirmed exploitation of CVE-2026-20182 against a UK FS entity (raises vertical risk to CRITICAL); identification of a new ransomware affiliate cluster targeting UK retail banking BPO; or a publicly-disclosed UK FS regulator-led intervention citing AI-driven KYC fraud as the primary loss driver.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.

SourceReliabilityInformationCredibility
A — Completely reliableDemonstrated repeated reliability1 — ConfirmedCorroborated by independent sources
B — Usually reliableReliable on most occasions2 — Probably trueLogical, consistent, partially corroborated
C — Fairly reliableSometimes reliable3 — Possibly trueReasonably logical, agrees with some information
D — Not usually reliableLimited prior accuracy4 — DoubtfulPossible but lacks logic or corroboration
E — UnreliableHistory of inaccuracy5 — ImprobableContradicts other reporting
F — Cannot be judgedNo basis for evaluation6 — Cannot be judgedCannot be assessed

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).

Source / TitlePublisherAdmiralty
1Q1 2026 Ransomware RetrospectiveCheck Point ResearchB2
2Ransomware sector reconsolidating — Qilin, LockBit, The Gentlemen expandIndustrial CyberB2
3DragonForce / Scattered Spider alliance briefingsSophos X-Ops; Acronis TRU; BlackFogA2
4Health-ISAC 2026 Annual Threat Report (FS cross-reference)Health-ISACA2
5Ransomware Q1 2026: Fewer Groups, Bigger Hits, Pre-Staged AccessCybersecurity InsidersB2
6FS-ISAC AI hardening advisory; sector risk advisoryFS-ISAC / ABA Banking JournalA2
7Inside DragonForce — M&S, Co-op, Harrods analysisInfosecurity Magazine; SophosA2
8CISA / NCSC-UK joint advisory on CVE-2026-20182 (Cisco SD-WAN)CISA; NCSC-UK; NSA; ACSC; CCCSA1
9Ivanti May 2026 Security Update (CVE-2026-6973)Ivanti; Help Net Security; SocRadarA2
10Trend Micro Apex One Critical Bulletin (CVE-2026-34926)Trend Micro; SecurityWeek; CISA KEVA2
11Scattered Spider / DragonForce target UK retail in new attacksSecurityBrief UKB2
12SystemBC C2 reveals 1,570+ TheGentlemen victimsThe Hacker News; ransomware.liveB2
13Akira drops 30 victims in one daySecurityWeek; The RecordA2
14GitHub Nx Console / TanStack supply-chain compromiseBleepingComputer; Hendry Adrian Daily RecapB2
15Vodafone source-code leak (Lapsus$)SecurityWeek; Hendry Adrian Daily RecapB2
16THORChain USD 10.7m lossCybernews; SecurityWeekB3
17ipinsights.io enrichment & blocklist (87.103.126.54 et al.)ipinsights.ioB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.