SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Legal services threat intelligence report — 23–29 May 2026

The vertical remains under sustained pressure from organised criminal cyber actors, with the SRA 2024 Risk Outlook continuing to identify phishing, conveyancing fraud and ransomware as the three highest-impact risks to UK firms…

  • Reference: TI-2026-0529-003 (public edition)
  • Sector: Legal services — solicitors, barristers and legal service providers
  • Reporting period: 23–29 May 2026
  • Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Legal, Solicitors, Barristers and Legal Services vertical during the period 23 May 2026 to 29 May 2026. The vertical remains under sustained pressure from organised criminal cyber actors, with the SRA 2024 Risk Outlook continuing to identify phishing, conveyancing fraud and ransomware as the three highest-impact risks to UK firms — a position the post-Legal Aid Agency 2025 environment has not improved. ICO and Chaucer disclosures place 226 UK law firms suffering data breaches in the prior twelve months, with cyber-attacks against UK law firms up 77% year on year and nearly three-quarters of the UK's top 100 firms impacted at some point. The collection picture this week is dominated by continued edge-appliance exploitation pressure — Cisco Catalyst SD-WAN, Ivanti EPMM, Microsoft Exchange OWA, Trend Micro Apex One and Citrix NetScaler — and by ransomware leak-site cadence from Qilin, TheGentlemen, Akira and DragonForce against legal-services adjacent professional-services victims. Sources are graded against the Admiralty System.

Phishing-derived alerting was within envelope across all in-scope tenants. No client-confidential or matter-related data was identified in transit on any flagged exfiltration-pattern alert across the reporting period.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that conveyancing-fraud and Friday-afternoon push-payment attacks will continue to dominate the criminal threat picture against UK solicitor firms across the next reporting cycle, with email account compromise via OAuth consent-phishing the most consequential entry vector. (HIGH confidence)
  2. It is highly likely that ransomware operators — Qilin, TheGentlemen, Akira and DragonForce — will continue to target mid-market UK law firms over the next reporting cycle, given the documented Q1 2026 cadence and the affiliate-onboarding dynamics in the major RaaS programmes. (HIGH confidence)
  3. It is likely that the Microsoft Exchange Server OWA zero-day (CVE-2026-42897) will be weaponised against mid-market UK firms still operating on-prem Exchange or hybrid topologies. Outlook Web Access is a common residual access vector for matter-related correspondence in firms that have not fully cloud-migrated. (MEDIUM-HIGH confidence)
  4. It is likely that nation-state intelligence interest in UK legal firms representing sanctioned persons, asset-recovery counter-parties or strategic-disputes clients will continue, with China- and Russia-nexus collection focus most active. (MEDIUM confidence)
  5. There is a realistic possibility that the Legal Aid Agency 2025 disruption will be referenced in any future TLP:CLEAR NCSC advisory as a case study for sustained ransomware impact on legal-sector systems; firms should expect renewed regulator focus on operational resilience. (MEDIUM confidence)

2. Sector threat landscape

The UK legal sector continues to occupy a distinctive position in the threat landscape: the concentration of high-value client data, the size of individual transactions, and the time-sensitive nature of conveyancing and settlement work make law firms a particularly attractive target for organised criminal cyber operators. The SRA's 2024 Risk Outlook identifies phishing, conveyancing fraud and ransomware as the three highest-impact risks, and that taxonomy continues to map closely against observed activity in 2026. Chaucer Group reporting places 226 UK law firms as having suffered data breaches in the prior twelve months, with attacks against UK law firms up 77% year on year. The NCSC's 2025 cyber-threat-to-the-UK-legal-sector report continues to be cited as the authoritative public anchor for the vertical.

Ransomware leak-site activity remains the dominant single category of disruption. Q1 2026 leak-site postings grew 22% year-on-year to 2,638 across the whole population, and the legal-and-professional-services slice is consistently large enough to register on every major operator's Q1 retrospective. Qilin remains the highest-volume operator for the third consecutive quarter (338 disclosed Q1 victims); TheGentlemen has expanded rapidly from 35 victims in Q4 2025 to 182 in Q1 2026; Akira posted 197 victims in Q1 (down from 226 in Q4 2025); and the LockBit / Qilin / DragonForce alliance continues to operate as a coherent cartel. Mid-market firms with limited in-house cyber capability remain disproportionately exposed.

Edge-appliance exploitation pressure is shaping the initial-access landscape across the vertical. Cisco Catalyst SD-WAN CVE-2026-20182 (CVSS 10.0, KEV, confirmed UAT-8616 in-the-wild activity) carries critical risk for any firm operating the affected controller / manager configuration. Ivanti EPMM CVE-2026-6973 chain pressure continues against firms whose admin credentials were harvested in the January 2026 CVE-2026-1340 wave. Microsoft Exchange Server CVE-2026-42897 is particularly relevant because legal firms have historically been slow to migrate fully to Exchange Online and frequently retain OWA exposure for partner and barrister chambers access. Trend Micro Apex One CVE-2026-34926 (KEV 21 May 2026) carries EDR-control-plane risk against firms with Apex One deployed, and the Citrix NetScaler ADC and Gateway advisories (CVE-2026-3055 and CVE-2026-4368, flagged by NCSC this week) are critical for firms using NetScaler for remote-access or load-balancing.

Conveyancing-fraud and Friday-afternoon push-payment attacks continue to drive the highest-frequency, highest-impact category of incident against the vertical. The operational pattern is consistent: M365 account compromise via OAuth consent-phishing or AiTM phishing, mailbox-rule manipulation to suppress the legitimate party's reply traffic, and substitution of bank details immediately before the funds-transfer instruction. Firms with weak M365 administrative control over OAuth consent grants, lacking conditional-access policies, or with insufficient client-funds reconciliation checks remain the most exposed. The SRA's continuing emphasis on this risk category in client-handling material is well-founded.

Nation-state intelligence collection against the vertical is harder to characterise precisely but persists. UK firms representing parties in commercial disputes with sanctioned persons, asset-recovery work touching state-aligned counter-parties, or strategic litigation involving China-, Russia-, Iran- or DPRK-aligned interests, have all been documented as targeted in vendor reporting. ESET's APT activity report for October 2025 to March 2026 — released 28 May — reflects sustained Russian, Chinese, North Korean and Iranian APT pressure across legal-adjacent professional services, and ESET specifically notes oil-shipment and drone-maker campaigns whose downstream legal counsel are within reasonable expectation of being targeted.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (a.k.a. Agenda, Qilin.B)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russia
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion / data theft
  • Sector Targeting: Cross-sector with sustained Legal, Solicitors, Barristers and Legal Services relevance.
  • Geographic Focus: Global; UK, EU, US, ANZ
  • Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
  • Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)

Akira

  • Aliases:
  • Suspected Origin: Russia-aligned criminal milieu
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — encryption + extortion
  • Sector Targeting: Cross-sector with sustained Legal, Solicitors, Barristers and Legal Services relevance.
  • Geographic Focus: Global; SMB and mid-market heavy
  • Signature TTPs: Cisco VPN account abuse without MFA; rapid AD reconnaissance; ESXi targeting; brand-pressure leak-site
  • Tooling / Malware Families: Akira encryptor (Rust); RustDesk; AnyDesk; rclone; PCHunter; Mimikatz
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: HIGH

TheGentlemen

  • Aliases:
  • Suspected Origin: Unattributed (likely Russian-speaking criminal milieu)
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial — extortion
  • Sector Targeting: Cross-sector with sustained Legal, Solicitors, Barristers and Legal Services relevance.
  • Geographic Focus: Cross-sector, global
  • Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows/Linux/BSD/NAS); SystemBC C2
  • Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
  • Analytic Confidence: MEDIUM-HIGH

Scattered Spider / DragonForce affiliate cluster

  • Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
  • Suspected Origin: UK / US / English-speaking community
  • Suspected Sponsor: Criminal (IAB into DragonForce / LockBit / Qilin cartel)
  • Primary Motivation: Financial — extortion via partner ransomware
  • Sector Targeting: Cross-sector with sustained Legal, Solicitors, Barristers and Legal Services relevance.
  • Geographic Focus: UK, US, increasing reach into EU and outsourced helpdesks abroad
  • Signature TTPs: Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue, OAuth consent-phishing, RMM (AnyDesk / TeamViewer / ScreenConnect)
  • Tooling / Malware Families: DragonForce / LockBit / Qilin partner encryptors; ESXi-targeted mass-encryption
  • Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — NCSC, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
  • Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A2.
  • Analytic Confidence: HIGH — NCSC, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1566.001Spear-phishing AttachmentConveyancing- and matter-themed phishing with weaponised PDF / DOCX attachments targeting fee-earner mailboxes.HIGH
Initial AccessT1566.002Spear-phishing LinkAiTM phishing pages mimicking M365 sign-in, OAuth consent-phishing against fee-earner mailboxes.HIGH
Initial AccessT1190Exploit Public-Facing ApplicationCisco SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Exchange OWA CVE-2026-42897, Apex One CVE-2026-34926, Citrix NetScaler CVE-2026-3055/4368 against unpatched internet-facing tiers.HIGH
Initial AccessT1078.004Valid Accounts: CloudIAB-purchased M365 credentials and session tokens harvested from AiTM phishing.HIGH
PersistenceT1098.002Account Manipulation: Additional Email Delegate PermissionsGranting attacker-controlled mailbox-delegate permissions and inbox-rule writes to suppress legitimate counter-party reply traffic during conveyancing-fraud.HIGH
Defence EvasionT1564.008Hide Artifacts: Email Hiding RulesServer-side inbox rules to delete or relocate fraud-detection emails before fee-earner review.HIGH
Credential AccessT1539Steal Web Session CookieSession-token theft from AiTM phishing; reuse against M365 / SharePoint / OneDrive.HIGH
CollectionT1114.002Email Collection: Remote Email CollectionBulk-download of matter-related correspondence via Graph API following session-token theft.MEDIUM
ExfiltrationT1567.002Exfiltration to Cloud Storagerclone / MEGA / AzCopy egress of matter and HR data prior to ransomware stage.HIGH
ImpactT1486Data Encrypted for ImpactQilin.B / Akira / DragonForce encryption of fee-earner laptops, file-servers and DMS estates.HIGH
ImpactT1657Financial TheftConveyancing push-payment substitution; client-funds redirect at completion.HIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
24 May 2026Global Retool Group (Business Services, professional-services adjacent)QilinPosted to Qilin leak-site 24 May; data-extortion ongoing.Ransomware.live
Q1 2026226 UK law firms — twelve-month data-breach disclosure aggregateMultiple — criminal and unattributedChaucer Group / ICO breach-reporting aggregate; 77% year-on-year increase in attacks against UK law firms.Chaucer Group / ICO
Continued through May 2026Legal Aid Agency (LAA) — April 2025 disruption follow-onUnattributedLAA systems remained partially offline for nine months following the April 2025 attack; continuing case study for sustained ransomware impact in the sector.Law Gazette / NCSC
15 May 2026Microsoft Exchange Server tenants (on-prem) — legal-sector exposureMultipleCVE-2026-42897 OWA XSS confirmed in active exploitation; legal firms with on-prem Exchange are materially exposed.Microsoft / Help Net Security
Earlier 2026Mid-tier UK law firm — anonymised peer disclosureAkira-attributed (leak-site reporting)Conveyancing-matter exposure; ICO MROS-listed; client-funds incident contained at the firm's managed agent.Anonymised peer exchange / Law Gazette

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild)10.0YesYesPatch immediately; rotate SSH keys; review NETCONF logs
CVE-2026-6973Ivanti EPMM (post-CVE-2026-1340 credential reuse chain)7.2YesYesPatch and rotate any admin credential issued before 1 Feb 2026
CVE-2026-34926Trend Micro Apex One (On-Premise) — directory traversal9.4YesYesPatch to build ≥17079; treat as EDR-control-plane exposure until verified
CVE-2026-42897Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email8.1YesYesApply 14 May 2026 OOB update; disable OWA externally pending patch
CVE-2025-34291Langflow — origin validation error (added KEV 21 May 2026)9.1YesSuspectedPatch and restrict admin endpoints to trusted networks
CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May)8.0–8.8YesYesAudit developer endpoints; remove compromised package versions
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May)9.0 / 7.5NoSuspectedApply Citrix advisory updates; review session tokens

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]5ongoingMTOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block
IP193[.]32[.]162[.]157ongoingMBrute-force / malware family — listed on 6 blacklists per IP Insights
Domainglobal-retool-leaks[.]onion24 May 2026MQilin leak-site post — Global Retool Group disclosure

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Conveyancing-fraud / push-payment substitution via M365 account compromiseHIGHHIGHCRITICAL
Ransomware deployment against fee-earner estate or DMS via IAB front-endHIGHHIGHCRITICAL
Exchange OWA exploitation (CVE-2026-42897) against on-prem mailbox estateMEDIUMHIGHHIGH
Edge-appliance exploitation (Cisco SD-WAN / NetScaler / Apex One) against mid-tier firmMEDIUMHIGHHIGH
Nation-state collection against sanctions / asset-recovery / strategic-disputes practiceLOWHIGHMEDIUM
Supply-chain compromise via shared legal-tech SaaS or e-disclosure platformMEDIUMMEDIUMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For legal-services tenants specifically, instrument M365 inbox-rule writes against the conveyancing-fraud baseline — any new server-side rule with subject keywords matching completion / settlement / wire / payment / bank / IBAN should generate a P2 alert. Index fee-earner mailbox OAuth consent grants against the firm-allow-listed enterprise application set; any consent grant outside the allow-list should generate a P2. Hunt for Graph-API bulk-mailbox downloads following session-token theft, and treat any cross-firm OneDrive / SharePoint sharing-grant of matter folders to external tenants as a P1 trigger.

Defend

Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. Legal firms should map controls onto SRA Cybersecurity Code of Conduct and the Lexcel practice-management quality mark, with particular emphasis on the conveyancing client-funds control set. Conditional-access policies should enforce phishing-resistant MFA (FIDO2 / passkeys) for fee-earner and partner mailboxes, and block legacy authentication entirely. Email tenant audit-logging should be retained for at least twelve months to support post-incident matter reconstruction. ICO breach-notification timelines should be exercised against an explicit conveyancing-fraud scenario.

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. The legal vertical lacks a dedicated ISAC, but the Law Society's Cybersecurity for Lawyers programme, Bar Council Cyber Working Group and the SRA's risk-outlook material provide useful peer-exchange. NCSC's CiSP legal trust group offers UK-anchored indicator sharing. International Legal Technology Association (ILTA) members can additionally exchange via the ILTA peer-group structure.

10. Forward outlook

Looking forward to the next reporting period (30 May – 5 June 2026), it is highly likely that conveyancing-fraud will remain the highest-frequency category of incident against the vertical and that Qilin, TheGentlemen, Akira and DragonForce will continue at the current leak-site cadence with at least one professional-services or legal-adjacent victim per week. It is likely that at least one UK mid-tier firm with on-prem Exchange will be identified as exposed to CVE-2026-42897 through CiSP or ICO MROS reporting. There is a realistic possibility that the Scattered Spider IAB front-end will rotate from retail / banking BPO targeting to professional-services BPO over the next two reporting cycles.

*Trigger conditions that would prompt revision of this outlook include: (a) the appearance of a named UK law firm on a Qilin / Akira / TheGentlemen leak-site, which would warrant an immediate client advisory; (b) any SRA or ICO TLP:CLEAR advisory pointing to a sector-wide credential-stuffing or OAuth-consent-phishing campaign; (c) a fresh Microsoft Exchange OWA zero-day affecting hybrid topologies; or (d) novel conveyancing-fraud TTPs reported via the Law Society Cybersecurity for Lawyers programme.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalogCISAA1
2Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZCISA et al.A1
3Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)Cisco TalosB2
4Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026CISA / Trend MicroA1
5Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by MicrosoftMicrosoft / Help Net SecurityB1
6NCSC weekly threat reports and advisory feed (NCSC-UK)NCSCA1
7ESET APT Activity Report — Oct 2025 to Mar 2026ESETB2
8Check Point Research — The State of Ransomware Q1 2026Check Point ResearchB2
9Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026)Ransomware.liveC2
10IP Insights — IP reputation enrichment (https://www.ipinsights.io)UK Cyber Defence LtdB2
11FS-ISAC — sector resilience and AI-fraud advisories (subscription)FS-ISACA2
12NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368NCSCA1
13Chaucer Group — 226 UK law firms data-breach disclosure (twelve-month aggregate)Chaucer GroupB2
14NCSC — The cyber threat to UK legal sector (PDF, ongoing reference)NCSCA1
15Law Society of England and Wales — Cybersecurity for Lawyers programme materialLaw SocietyB2
16Law Gazette — Legal Aid Agency follow-on coverage May 2026Law GazetteB2
17SRA Risk Outlook 2024 (continuing reference)Solicitors Regulation AuthorityA2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.