Legal services threat intelligence report — 6–12 June 2026
The legal-sector collection picture this week sits against an unusually material regulatory backdrop: the Solicitors Regulation Authority's April 2026 consultation on compliance demonstration remains open…
- Reference: TI-2026-0612-003 (public edition)
- Sector: Legal services — solicitors, barristers and legal service providers
- Reporting period: 6–12 June 2026
- Issued: 12 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Legal, Solicitors, Barristers and Legal Services sector during the period 06 Jun 2026 - 12 Jun 2026. It is intended to support security leadership and operational defenders within the vertical and is issued under TLP:CLEAR.
The legal-sector collection picture this week sits against an unusually material regulatory backdrop: the Solicitors Regulation Authority's April 2026 consultation on compliance demonstration remains open, and the Legal Aid Agency cyber-attack continues to impose downstream financial-security strain on UK firms. The week's principal new exposures align around credential-phishing of solicitor and barrister identity providers (NCSC NetScaler advisories CVE-2026-3055 / -4368) and ransomware targeting of firm document-management estates, with Cisco SD-WAN Manager (CVE-2026-20245, no patch) and Arista EOS (CVE-2026-7473, no patch) elevating the perimeter-edge risk for firms running these vendors.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware crews - Qilin, TheGentlemen, Akira and DragonForce - will continue to treat UK and EU law firms as a high-value target subset, with the financial and reputational consequences of leak-site posting driving disproportionate extortion-payment pressure. (HIGH confidence)
- It is highly likely that AI-augmented spear-phishing will materially raise the success rate of conveyancing-fraud, beneficial-owner-impersonation and friday-afternoon-fraud campaigns against UK firms over the next reporting cycle, consistent with the 2026 SRA / Law Society guidance on AI-enabled fraud. (HIGH confidence)
- It is likely that legal-sector supply-chain providers - case-management vendors, e-disclosure platforms, and outsourced IT providers similar to the 2023 CTS pattern - will be targeted again over the period; the LAA pattern continues to inform this judgement. (MEDIUM confidence)
- It is a realistic possibility that the SRA will issue further enforcement decisions against firms that breach incident-reporting obligations during the reporting period, given the April 2026 consultation focus and prior precedent (DPP Law Ltd, GBP 60,000, 2025). (MEDIUM confidence)
2. Sector threat landscape
The legal vertical continues to face an asymmetric ransomware and data-extortion threat picture. Chaucer Group's industry-wide statistics for the trailing year record 226 UK law firms suffering data breaches; nearly three-quarters of the UK's top 100 firms have been affected by cyber attacks. The SRA's April 2026 consultation on compliance demonstration, together with the LAA cyber-attack's continuing operational fall-out, has raised the regulatory and commercial salience of cyber risk across the sector.
Edge-appliance exposure dominates the new-this-week picture. The Cisco Catalyst SD-WAN Manager defect CVE-2026-20245 (no patch) and the Arista EOS tunnel-decap defect CVE-2026-7473 (no patch planned) are both directly relevant to mid-market and large-firm data-centre fabrics. The NCSC Citrix NetScaler advisories (CVE-2026-3055 / -4368) compound the picture: NetScaler is a commonly deployed VPN concentrator in multi-office practices and is heavily used by chambers IT providers to reach barrister estate equipment. The Microsoft Defender BlueHammer disclosure (CVE-2026-33825) is acutely relevant to small and mid-market firms that depend on Defender as their primary EDR.
Conveyancing-fraud and CEO-impersonation remain the highest-volume threat for the sector. The 2024 SRA risk update specifically identified phishing, conveyancing fraud and ransomware as the top three risks; AI-augmented voice and text generation has now materially lowered the cost and raised the success rate of these campaigns. The Law Society and SRA have published 2026 guidance emphasising client-account verification controls.
Outsourced legal IT providers continue to represent a high-leverage supply-chain compromise vector: the 2023 CTS incident remains the canonical UK example, and the LAA cyber-attack continues to demonstrate the sector-wide impact of upstream compromise. The reporting period saw no public disclosure of a comparable provider-level incident, although several mid-market case-management platforms experienced unscheduled maintenance windows that warrant tracking.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia (Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Legal-sector relevance; documented UK law-firm targeting via leak-site postings.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
- Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
- Recent Activity: 97-101 victims posted in May 2026 - fifth consecutive month at top of leak-site postings (BreachSense / Check Point).
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH - multiply sourced (Check Point Research, BreachSense, Ransomware.live)
TheGentlemen
- Aliases: -
- Suspected Origin: Unattributed (likely Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion
- Sector Targeting: Cross-sector with documented mid-market law-firm and chambers targeting.
- Geographic Focus: Cross-sector, global
- Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows / Linux / BSD / NAS); SystemBC C2
- Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
- Recent Activity: 70 victims posted in May 2026 - second only to Qilin (BreachSense).
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: MEDIUM-HIGH
Akira
- Aliases: Akira / Megazord
- Suspected Origin: Russia-linked
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Legal-sector targeting via Cisco VPN credential abuse.
- Geographic Focus: Global
- Signature TTPs: Cisco VPN credential abuse (no-MFA accounts); Rust / C++ encryptor; ESXi targeting; data-extortion sites
- Tooling / Malware Families: Akira encryptor; LOLBin chain; AnyDesk; rclone
- Recent Activity: 64 victims posted in May 2026 - third in the leak-site ranking (BreachSense).
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
- Suspected Origin: UK / US / English-speaking community
- Suspected Sponsor: Criminal (IAB into DragonForce / LockBit / Qilin)
- Primary Motivation: Financial - extortion via partner ransomware
- Sector Targeting: Cross-sector with Legal-sector relevance through outsourced IT and chambers IT helpdesk targeting.
- Geographic Focus: UK, US, increasing EU and outsourced helpdesks abroad
- Signature TTPs: Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue, OAuth consent-phish, RMM abuse (AnyDesk / ScreenConnect)
- Tooling / Malware Families: DragonForce / LockBit / Qilin partner encryptors; ESXi mass-encryption
- Recent Activity: DragonForce 32 victims in May 2026 (down from 41 in April per BreachSense); BPO / outsourced-helpdesk pattern continues.
- Assessed Threat to Vertical: HIGH - Admiralty A2.
- Analytic Confidence: HIGH - NCSC-UK, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Arista EOS (CVE-2026-7473), Fortinet FortiClient EMS (CVE-2026-35616) and Citrix NetScaler (CVE-2026-3055 / -4368) against firm perimeters. | HIGH |
| Initial Access | T1566.001 | Spear-phishing Attachment | AI-augmented conveyancing fraud and CEO-impersonation campaigns; Microsoft 365 OAuth consent-phishing. | HIGH |
| Initial Access | T1078 | Valid Accounts | Credential reuse via dark-market sales against legal-sector M365 tenants. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded PowerShell loaders staging SystemBC and Cobalt Strike Beacon. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Cisco SD-WAN Manager CLI command-injection and Microsoft Defender BlueHammer chain. | HIGH |
| Defence Evasion | T1562.001 | Impair Defences: Disable Security Tools | BlueHammer LPE used to disable Defender on small / mid-market firm endpoints. | HIGH |
| Collection | T1213 | Data from Information Repositories | Bulk staging from SharePoint, NetDocuments, iManage and equivalent matter-management platforms prior to exfiltration. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd / AzCopy push of client-confidential matter data prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware encryptors mass-encrypt hypervisor estates underpinning matter-management and document-management systems. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to CISA KEV; ITW exploitation; no patch. | CISA / Cisco PSIRT |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to KEV; no patch planned. | CISA / Arista |
| 09 Jun 2026 | Google Chromium V8 | Unattributed | CVE-2026-11645 KEV listing; browser-side RCE. | CISA / Google |
| 02 Jun 2026 | Fortinet FortiClient EMS | Unattributed | CVE-2026-35616 ITW; carry. | watchTowr Labs |
| Ongoing | Qilin / TheGentlemen / Akira / DragonForce leak sites | Multiple | UK law firms continue to appear in leak-site postings; May 2026 volumes record-comparable. | BreachSense / Ransomware.live |
| Ongoing | Legal Aid Agency post-incident impact | Unattributed (April 2026 attack) | Continues to impose financial-security strain on firms drawing legal-aid revenue. | Law Society / Law Gazette |
| 22 Apr 2026 | SRA consultation on compliance demonstration | n/a (regulatory) | Open consultation on how firms demonstrate compliance with cyber and operational controls. | SRA |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command-injection (authenticated, netadmin) | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; ACL Manager to management VLAN; monitor for crafted file uploads. No vendor patch at issue. |
| CVE-2026-7473 | Arista EOS - tunnel-protocol type not validated on decap interface (no patch planned) | 6.9 | Yes | Yes | Apply Arista mitigation: explicit per-protocol decap-group configuration; ACL the tunnel-endpoint IP; consider removal of decap on edge. |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read/write, browser-side RCE | 8.8 | Yes | Yes | Force-update Chrome and Chromium-derived browsers (Edge, Brave) across the fleet; enforce Site Isolation; verify SmartScreen / SafeBrowsing telemetry. |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer for Magento - deserialisation of untrusted data | 9.8 | Yes | Yes | Patch Mirasvit extension to vendor-supplied build; restrict admin/cache endpoints to internal IP space; rotate any captured admin tokens. |
| CVE-2025-48595 | Android Framework - integer overflow, limited targeted exploitation | 7.8 | Yes | Yes | Enforce June 2026 Android security patch level on managed devices via MDM; deprovision devices unable to receive the update. |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - container escape (revived for cloud workloads) | 7.8 | Yes | Yes | Enforce seccomp / AppArmor / SELinux on container hosts; verify kernel >= 5.16.4 or backported patches; restrict unprivileged user namespaces. |
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; watchTowr confirmed ITW exploitation 02 Jun (carry) | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN; hunt for new local accounts and outbound HTTP from EMS hosts. |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (carry) | 8.4 | Yes | Yes | Force MoCAMP rollout to 4.18.26040.1011 or later; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH source IPs. |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - NCSC take-action notice (carry) | 9.1 | No | Suspected | Apply Citrix firmware; rotate NetScaler session tokens; force re-authentication across Gateway tenants; review for AAA-vserver tampering. |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - companion NCSC advisory (carry) | 8.8 | No | Suspected | Apply Citrix firmware bundle; baseline configuration drift; monitor for new admin or read-only accounts. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 24 May 2026 | HIGH | ServeTheWorld AS (NO, AS34989) - perimeter SSH/CMS brute-force; IP Insights threat=critical, 9 blacklists. |
| IP | 79[.]143[.]178[.]79 | 24 May 2026 | HIGH | Contabo (DE) - perimeter brute-force; IP Insights threat=critical, 8 blacklists. |
| IP | 51[.]68[.]226[.]87 | 02 Jun 2026 | HIGH | OVH SAS (FR, AS16276) - datacentre IP; carry-IOC sweep; IP Insights threat=critical, 6 blacklists. |
| IP | 136[.]232[.]11[.]10 | 02 Jun 2026 | HIGH | Reliance Jio (IN, AS55836) - carry-IOC; IP Insights threat=critical, 7 blacklists. |
| IP | 165[.]154[.]105[.]128 | 02 Jun 2026 | HIGH | UCLOUD HK (VN, AS135377) - datacentre; carry-IOC; IP Insights threat=critical, 7 blacklists. |
| ASN | AS135377 (UCLOUD HK) | 12 Jun 2026 | HIGH | IP Insights ASN risk=critical (81); 807/1000 sampled IPs blacklisted; recommend AS-level edge denial for low-business-need ASNs. |
| ASN | AS60729 (TorServers / Stiftung Erneuerbare Freiheit) | 12 Jun 2026 | HIGH | 190/191 sampled IPs blacklisted; treat Tor egress as inherently suspect for client estates. |
| ASN | AS51167 (Contabo) | 12 Jun 2026 | MEDIUM | IP Insights risk=high (52); 553/1000 sampled IPs blacklisted; common scanner / brute-force source. |
| URL | hxxps://lawsoc-portal-reset[.]com | 07 Jun 2026 | MEDIUM | Law Society-themed phish lure. |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment leading to matter-management / e-disclosure platform encryption | H | H | CRITICAL |
| Conveyancing fraud or CEO-impersonation BEC against firm finance teams | H | H | CRITICAL |
| Supply-chain compromise via case-management vendor or outsourced IT (CTS / LAA pattern) | M | H | HIGH |
| SRA enforcement action consequent on incident-reporting failure | M | M | MEDIUM-HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should prioritise (a) Cisco SD-WAN Manager netadmin role activity and configuration-push from non-management VLANs; (b) Arista EOS tunnel-protocol decap conflation; (c) NetScaler AAA-vserver tampering and session-token reuse outside expected geographies; (d) Fortinet FortiClient EMS admin-endpoint anomaly; (e) bulk-download patterns from SharePoint, NetDocuments and iManage matter-management estates; (f) OAuth-consent grants of unusually broad scope on M365 tenants; (g) Defender platform-roll-back events and MoCAMP version mismatch on small / mid-market firm endpoints.
Defend
Preventive priorities follow Section 6: enforce mitigation-only postures for the two no-patch defects (Cisco SD-WAN Manager and Arista EOS); patch FortiClient EMS to 7.4.2; apply Citrix NetScaler firmware and rotate session tokens; force Defender MoCAMP roll-up to 4.18.26040.1011; force Chromium update for CVE-2026-11645. Verify client-account-verification controls against the 2026 SRA / Law Society guidance and ensure SRA notification pathways are documented and tested. Confirm immutable backup posture for matter-management and document-management hypervisor estates.
Disrupt
Disruption activity within client lawful authority should focus on: (i) coordinated sharing of SRA- and Law-Society-themed phish indicators with peer firm SOCs and the NCSC CiSP legal-sector trust group; (ii) takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations; (iii) deception deployment of conveyancing-themed honeypot domains modelling SRA and Law Society portals; (iv) sector-coordinated takedown requests to registrars and Cloudflare / Microsoft / Google trust-and-safety teams.
10. Forward outlook
Looking forward to the next reporting period (13-19 Jun 2026), it is likely that at least one UK law firm or barristers' chambers will publicly disclose a ransomware or data-extortion incident, with MEDIUM-HIGH confidence based on the persistent leak-site cadence and the ongoing LAA-related strain. AI-augmented conveyancing fraud is highly likely to continue. The SRA is realistically likely to issue further enforcement decisions during the period.
Trigger conditions that would prompt revision of this outlook include: (a) a UK Top 200 firm publicly attributing a breach to NetScaler or FortiClient EMS exploitation; (b) the appearance of a Qilin or Akira leak-site post naming a UK firm or chambers; (c) SRA TLP:CLEAR notification of sector-wide credential-stuffing or token-theft activity through the Law Society cyber-resilience forum; (d) NCSC issuance of a follow-up advisory affecting legal-sector providers. The principal intelligence gap is direct visibility into the SRA / NCSC legal-sector trust group traffic for the 06-12 Jun period.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports & advisories index, https://www.ncsc.gov.uk/section/keep-up-to-date/reports-advisories | A1 | |
| 2 | CISA Known Exploited Vulnerabilities Catalogue, additions of 02 / 03 / 09 Jun 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog | A1 | |
| 3 | CISA Adds Three KEV (Arista EOS, Chromium V8, Cisco SD-WAN Manager), 09 Jun 2026, https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalog | A1 | |
| 4 | 'Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited - No Patch Available', Jun 2026 | The Hacker News | B2 |
| 5 | 'No Patch Planned for Exploited Arista EOS Vulnerability (CVE-2026-7473)', Jun 2026 | SecurityWeek | B2 |
| 6 | Fortinet FortiClient EMS CVE-2026-35616 in-the-wild exploitation confirmation, 02 Jun 2026 | watchTowr Labs | B2 |
| 7 | May 2026 ransomware retrospective (Qilin 97-101, TheGentlemen 70, Akira 64, DragonForce 32; 115 TB stolen) | BreachSense | B2 |
| 8 | 'The State of Ransomware - Q1 2026', https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/ | Check Point Research | B2 |
| 10 | IP Insights threat-assessment lookups (X-API-Key authenticated), https://www.ipinsights.io | A2 | |
| 11 | MITRE ATT&CK Enterprise framework v15, https://attack.mitre.org | A1 | |
| 12 | Cisco Security Advisory cisco-sa-sdwan-privesc-4uxFrdzx, Jun 2026 | A1 | |
| 13 | EOS tunnel decap protocol-type validation | Arista Security Advisory 0137 | A1 |
| 14 | cyber security guidance for solicitors, https://www.lawsociety.org.uk/topics/cybersecurity/cybersecurity-for-solicitors | Law Society | A1 |
| 15 | SRA consultation on compliance demonstration, 22 Apr 2026 | A1 | |
| 16 | DPP Law fine and Legal Aid Agency cyber-attack reporting | Law Gazette | B2 |
| 17 | 226 UK law firms data-breach industry data | Chaucer Group | C2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Legal Threat Intelligence Briefing
May 2025 Legal Sector Threat Analysis
Legal services threat intelligence report — 27 April – 3 May 2026
The legal-services threat picture for the reporting period continues to reflect a sharp upward trajectory in attacks on UK law firms — the Law Gazette reports a 77 per cent year-on-year rise in successful attacks (538 to 954)…
Legal services threat intelligence report — 4–8 May 2026
The legal-services threat picture for the reporting period continues to reflect the sharp upward trajectory in attacks on UK law firms — the Law Gazette has reported a 77 per cent year-on-year rise in successful attacks (538 to 954)…