Legal services threat intelligence report — 20–26 June 2026
The dominant collection theme this period is the convergence of edge-appliance exposure (Ubiquiti UniFi OS chain added to CISA KEV on 23 June) with sustained ransomware and pure data-extortion targeting of UK law firms which continues to attract NCSC, SRA and Law Society attention.
- Reference: TI-2026-0626-003 (public edition)
- Sector: Legal services — solicitors, barristers and legal service providers
- Reporting period: 20–26 June 2026
- Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Legal, Solicitors, Barristers and Legal Services sector during the period 20 Jun 2026 - 26 Jun 2026. It is intended to support law-firm IT functions, the Senior Information Risk Owner, the COLP and managing partners with operational risk responsibility, and is graded TLP:CLEAR. The dominant collection theme this period is the convergence of edge-appliance exposure (Ubiquiti UniFi OS chain added to CISA KEV on 23 June) with sustained ransomware and pure data-extortion targeting of UK law firms which continues to attract NCSC, SRA and Law Society attention.
The Chaucer Group's recent finding that 226 UK law firms suffered data breaches in the past year remains the dominant statistical context, and the historical Jones Day cyber attack (confirmed April 2026) and the CTS managed-services-provider compromise that touched 80-200 UK firms continue to define the sector risk profile.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and pure data-extortion crews - Akira, Qilin, LockBit 5.0 and the DragonForce cluster - will continue to drive the majority of materially-disruptive incidents against UK law firms during the next two reporting cycles, consistent with leak-site activity in this period and prior periods (HIGH confidence).
- It is highly likely that the three Ubiquiti UniFi OS defects added to KEV on 23 June will be exploited against unpatched chambers and law-firm branch-office UniFi deployments within the next 14 days, given the public Bishop Fox PoC and the prevalence of UniFi hardware in mid-tier UK legal estates (HIGH confidence).
- It is highly likely that conveyancing fraud, BEC against client-account departments and impersonation of partners in cross-border transactions will continue at current or elevated volumes through Q3 2026, consistent with NCSC Legal Sector Cyber Threat Report findings and SRA enforcement trend (HIGH confidence).
- It is likely that managed-services-provider compromise (CTS-style) will recur as a delivery vector for ransomware against UK legal services within the next two reporting cycles, given the continued concentration of practice-management hosting amongst a small number of providers (MEDIUM-HIGH confidence).
- It is a realistic possibility that state-aligned actors (Salt Typhoon, Mustang Panda, APT28) will conduct targeted intrusions against UK law firms involved in geopolitically sensitive matters - sanctions enforcement, state-investor disputes, ICC representation - within the next two reporting cycles (MEDIUM confidence).
2. Sector threat landscape
The UK legal services vertical is unusually exposed to cyber risk because it concentrates high-value, time-sensitive and confidentially-held information in firms whose IT maturity varies widely across the magic-circle / silver-circle / mid-tier / boutique / chambers spectrum. The collection picture for this period is dominated by the edge-appliance exposure carried forward from the prior period and amplified by the 23 June Ubiquiti UniFi OS KEV addition, and by sustained ransomware activity affecting firms across all tiers.
The Ubiquiti UniFi OS chain is operationally significant for the legal vertical because UniFi hardware is extensively deployed in mid-tier firm head-office and branch networks, in chambers, and in expert-witness / forensic-services suppliers. The CVE-2026-34908 / -34909 / -34910 chain to unauthenticated root RCE and the CISA BOD 26-04 deadline of 26 June present a remediation challenge for firms whose IT is partly or wholly outsourced to MSPs.
Ransomware activity against UK and international law firms continued at elevated levels. Akira, Qilin, LockBit 5.0 and the DragonForce / Scattered Spider cluster all remain operationally relevant. The historical Jones Day breach (April 2026) and the CTS managed-services-provider compromise (which affected an estimated 80-200 UK firms) continue to define the sector's near-term risk profile. Conveyancing fraud and BEC against client-account departments remained at sustained volume, consistent with NCSC Legal Sector Cyber Threat Report findings.
State-aligned activity warrants monitoring for firms whose practice areas touch sanctions enforcement, state-investor disputes, ICC representation or geopolitically sensitive M&A. Salt Typhoon (PRC), Mustang Panda (PRC) and APT28 (GRU) have all been observed targeting professional services firms with adjacent practice profiles, and where a client is conducting work likely to attract state-actor interest the threat model should be elevated.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Akira
- Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, professional services, manufacturing, education, legal, retail
- Geographic Focus: Global; consistent UK / EU presence
- Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; ChaCha20 ransomware encryption
- Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
- Recent Activity: 22 Jun NTD Apparel posted to leak site; continued mid-week activity against professional-services sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services, retail
- Geographic Focus: Global; sustained EU and UK targeting through 2026
- Signature TTPs: Initial access via phishing and exposed VPN / RDP; abuse of valid accounts; rapid AD escalation; data exfiltration via Rclone to Mega / Backblaze prior to encryption
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
- Recent Activity: 22 Jun leak-site posting of Central Bank of Libya; sustained volume leadership across the reporting period (Insikt / ransomware.live)
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
DragonForce / Scattered Spider cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
- Suspected Origin: Western (UK / US) English-speaking criminal cluster + DragonForce RaaS infrastructure
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - extortion via encryption and data leak
- Sector Targeting: Retail, financial services, hospitality, telecoms, BPO / outsourced helpdesk providers, education
- Geographic Focus: UK and US primary; spreading EMEA
- Signature TTPs: IT-service-desk social engineering for MFA reset; Okta / Entra session hijack; rapid AD compromise; data theft via Rclone; deployment of DragonForce affiliate ransomware
- Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
- Recent Activity: 22 Jun leak-site posts of BITS Pilani and mihana-v.com (estimated attack 20 Jun); sustained UK retail / hospitality activity through the period
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
LockBit 5.0
- Aliases: LockBit, LockBit Black, LockBit Green, LockBit 5.0 (Aug 2025 relaunch)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, healthcare, manufacturing, government contractors, legal services
- Geographic Focus: Global; consistent UK / EU / NA volume
- Signature TTPs: Initial access via exposed RDP, public-facing exploits, valid accounts; ESXi-specific encryptor build; double-extortion via leak site
- Tooling / Malware Families: LockBit 5.0 encryptor (Win/Linux/ESXi variants), StealBit exfiltrator, Cobalt Strike, Mimikatz
- Recent Activity: Continuing 2026 leak-site activity post-relaunch; selective targeting of FS, legal and contractor sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: MEDIUM-HIGH
Mustang Panda (PRC)
- Aliases: Mustang Panda, Bronze President, RedDelta, TA416, HoneyMyte
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation-state (MSS-aligned)
- Primary Motivation: Espionage, influence collection on diaspora and NGO targets
- Sector Targeting: Government, NGOs, think-tanks, trade bodies, defence contractors, R&D
- Geographic Focus: Global, with sustained EU and SEA operations
- Signature TTPs: Spear-phishing with weaponised LNK / ISO containers; PlugX deployment; long-dwell-time operations against policy-influence targets
- Tooling / Malware Families: PlugX, ToneShell, Korplug, ClaimLoader
- Recent Activity: Sustained 2026 operations against trade bodies and NGOs documented in vendor reporting
- Assessed Threat to Vertical: HIGH for trade bodies and R&D
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Anticipated mass-exploitation of Ubiquiti UniFi OS chain at chambers and law-firm branch edge; continued exposure of legacy Citrix NetScaler perimeters | HIGH |
| Initial Access | T1566.002 | Spearphishing Link | Conveyancing fraud and impersonation of partners in cross-border transactions; sustained BEC against client-account departments | HIGH |
| Initial Access | T1078 | Valid Accounts | DragonForce / Scattered Spider helpdesk social-engineering for MFA reset; reuse of credentials harvested from CTS-style MSP compromises | HIGH |
| Execution | T1204.002 | User Execution: Malicious File | Macro-enabled documents in instruction-themed lures to fee-earners and trainees | MEDIUM |
| Persistence | T1098.001 | Account Manipulation: Additional Cloud Credentials | Attacker-controlled federation in Entra ID / Okta tenants of compromised firms | MEDIUM |
| Defense Evasion | T1562.001 | Disable or Modify Tools | EDR tampering observed in Akira and LockBit 5.0 case-work against legal-sector victims | MEDIUM |
| Credential Access | T1003.001 | OS Credential Dumping: LSASS Memory | Standard Mimikatz / sekurlsa post-domain-admin pattern across Akira and Qilin intrusions | HIGH |
| Collection | T1213 | Data from Information Repositories | Bulk export of practice-management system content (iManage, NetDocuments, SharePoint) prior to encryption | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi prior to encryption; consistent with Akira and Qilin tradecraft | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of Akira, Qilin and DragonForce; CTS-style MSP compromise blast-radius remains relevant | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 23 Jun 2026 | Ubiquiti UniFi OS Server (vendor) | Unattributed | Three CVEs added to CISA KEV; chambers, mid-tier firms and branch offices with UniFi hardware in scope | CISA KEV / Bishop Fox PoC |
| 22 Jun 2026 | Law-firm-adjacent professional services (multiple) | Multiple commodity actors | Sustained leak-site activity from Akira, Qilin and DragonForce against professional-services victims; supply-chain exposure into legal sector via shared MSPs | ransomware.live |
| Continuing | Jones Day (April 2026 disclosure) | Unattributed file-transfer ransomware cluster | Confirmed cyber attack with client-file access; reference for sector risk profile | Legal Cheek |
| Continuing | CTS (legal MSP) compromise blast-radius | Unattributed | Estimated 80-200 UK firms affected by historical MSP compromise; ongoing relevance for MSP-hosted practice-management estates | Computing / Law Gazette |
| Continuing | Mustang Panda / APT28 / Salt Typhoon | PRC / GRU state actors | Sustained targeting of legal sector adjacent to state-investor, sanctions and geopolitical matters per vendor reporting | Microsoft / Mandiant / CrowdStrike |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure |
| CVE-2026-34909 | Ubiquiti UniFi OS Server < 5.0.8 - path traversal | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies |
| CVE-2026-34910 | Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE) | 10.0 | Yes | Yes | Patch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE |
| CVE-2025-67038 | Lantronix EDS5000 Device Server - HTTP RPC command injection (root) | 9.8 | Yes | Yes | Apply Lantronix firmware update; remove internet exposure; segregate serial-to-IP devices to OT zone |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command injection | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately per NCSC; rotate gateway service accounts; force session reset for all interactive users |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read / write | 8.8 | Yes | Yes | Force Chrome / Edge update across workstation estate via Intune / SCCM; verify against KEV due-date |
| CVE-2025-48595 | Android Framework - integer overflow leading to local privilege escalation | 7.8 | Yes | Yes | Push June 2026 Android security patch via MDM; require minimum patch level on BYOD enrolments |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per LiteSpeed; confirm with hosting providers; relevant under outsourced-ICT regulatory regimes |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period |
| IP | 92[.]118[.]39[.]95 | 23 Jun 2026 | HIGH | UNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail |
| IP | 80[.]94[.]95[.]115 | 24 Jun 2026 | HIGH | SS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints |
| IP | 134[.]122[.]114[.]42 | 23 Jun 2026 | MEDIUM | DigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic |
| IP | 198[.]235[.]24[.]31 | 20 Jun 2026 | MEDIUM | Google Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals |
| IP | 162[.]142[.]125[.]34 | 25 Jun 2026 | LOW | Censys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise |
| IP | 64[.]227[.]107[.]117 | 24 Jun 2026 | MEDIUM | DigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI |
| IP | 152[.]32[.]143[.]49 | 22 Jun 2026 | MEDIUM | UCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail |
| IP | 146[.]70[.]180[.]13 | 21 Jun 2026 | MEDIUM | M247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via Ubiquiti UniFi OS chain at chambers / branch edge | H | H | CRITICAL |
| CTS-style MSP compromise as a delivery vector for ransomware against MSP-hosted practice-management estate | M | H | HIGH |
| Conveyancing fraud / BEC against client-account department with completion-monies misdirection | H | H | CRITICAL |
| Helpdesk social-engineering enabling Scattered Spider-style Okta / Entra session hijack | H | H | CRITICAL |
| State-aligned credentialed intrusion against firm with geopolitically sensitive practice | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the Ubiquiti UniFi OS chain as the principal hunting hypothesis for this period. For the legal-vertical-specific BEC and conveyancing-fraud risk, ensure M365 mailbox-rule-creation alerting is active across all monitored tenants, and prioritise alerts on rules that auto-delete or auto-forward messages containing 'completion', 'monies', 'wire', 'transfer' or solicitor-firm name strings. Hunt for bulk-export activity against iManage, NetDocuments and SharePoint document repositories. Tune existing SOC rules to suppress Censys / Shodan scanner traffic (162.142.125.34) whilst retaining it in IP Insights enrichment.
Defend
Preventive priorities for the legal vertical follow Section 6 directly. Ubiquiti UniFi OS 5.0.8 patch must be applied by 26 June to meet CISA BOD 26-04 across head-office, branch and chambers estates. Where IT is outsourced to MSPs, written confirmation of patch status must be obtained and recorded for COLP audit. For conveyancing fraud and BEC, enforce out-of-band verbal verification of all completion-monies destinations regardless of email confirmation, in line with Law Society and SRA guidance. Enforce number-matching MFA on all M365 / Okta tenants. Block legacy authentication. Audit federation trust relationships for unrecognised cloud directories. Ensure backup procedures meet SRA outcome-focused regulatory expectations and that practice-management system backups are immutable and held off-premises. For state-aligned threat exposure, firms with practice areas touching sanctions, ICC or geopolitically sensitive matters should adopt elevated identity hardening per NCSC's high-threat individual guidance.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the Legal Sector Information Sharing and Analysis Centre (LS-ISAO via SRA / Law Society liaison) and the NCSC CiSP legal community, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) coordination with the SRA on patch-status confirmation across the MSP supplier chain; (iii) takedown coordination via NCSC ACD for impersonation domains used in conveyancing-fraud lures; (iv) firm-name-themed domain monitoring via Domaintools / urlscan and proactive registration of likely typosquats; (v) submission of observed BEC sender infrastructure to ipinsights.io for community blocklisting.
10. Forward outlook
*Looking forward to the next reporting period (27 Jun - 03 Jul 2026), it is likely that at least one UK law firm will publicly disclose a ransomware or data-extortion incident traceable to one of the Ubiquiti UniFi OS chain, Cisco SD-WAN Manager, Citrix NetScaler or MSP-compromise vectors in Section 6, given the volume of unpatched edge exposure in the sector.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026) | CISA | A1 |
| 4 | CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026) | CISA | A1 |
| 5 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 6 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 7 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 8 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 9 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 10 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 11 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 12 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 13 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 14 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 15 | IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feed | UK Cyber Defence Ltd | A1 |
| 17 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 18 | NCSC Cyber Threat Report: UK Legal Sector (2024 update, current) | National Cyber Security Centre | A1 |
| 19 | Solicitors Regulation Authority Risk Outlook 2025-26 update | Solicitors Regulation Authority | A1 |
| 20 | Chaucer Group: 226 UK law firms suffered data breaches in past year | Chaucer Group plc | C2 |
| 21 | Law Society and SRA conveyancing-fraud guidance (current) | Law Society of England and Wales / SRA | A2 |
| 22 | Computing / Law Gazette CTS compromise reporting (historical, ongoing relevance) | Computing / Law Gazette | C2 |
| 23 | Microsoft Threat Intelligence Salt Typhoon and Mustang Panda updates (2026) | Microsoft Corporation | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Legal Threat Intelligence Briefing
May 2025 Legal Sector Threat Analysis
Legal services threat intelligence report — 27 April – 3 May 2026
The legal-services threat picture for the reporting period continues to reflect a sharp upward trajectory in attacks on UK law firms — the Law Gazette reports a 77 per cent year-on-year rise in successful attacks (538 to 954)…
Legal services threat intelligence report — 4–8 May 2026
The legal-services threat picture for the reporting period continues to reflect the sharp upward trajectory in attacks on UK law firms — the Law Gazette has reported a 77 per cent year-on-year rise in successful attacks (538 to 954)…