Legal services threat intelligence report — 27 June – 3 July 2026
Coverage this period is dominated by the SharePoint deserialisation KEV entry (CVE-2026-45659) - operationally significant for the legal sector given the near-ubiquity of SharePoint and iManage for matter files, trust-account documentation…
- Reference: TI-2026-0703-003 (public edition)
- Sector: Legal services — solicitors, barristers and legal service providers
- Reporting period: 27 June – 3 July 2026
- Issued: 3 July 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Legal sector - solicitors, barristers, chambers, legal support services and adjacent - during the period 27 Jun 2026 - 03 Jul 2026. It is intended to support operational defenders and risk owners in law firms and legal services organisations and is graded TLP:CLEAR. Coverage this period is dominated by the SharePoint deserialisation KEV entry (CVE-2026-45659) - operationally significant for the legal sector given the near-ubiquity of SharePoint and iManage for matter files, trust-account documentation, and client due-diligence packs - and by continued ransomware and data-extortion activity of the shape that has driven the 77% year-on-year increase in successful attacks on UK law firms reported by the SRA / Law Gazette.
The perimeter tail is dominated by IP Insights critical-scored Tor exits and bulletproof hosting. Two peer notifications received this period via the Solicitors Regulation Authority informal information-sharing channel concern conveyancing-fraud precursor activity; details TLP:CLEAR-restricted.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that CVE-2026-45659 will be exploited against unpatched SharePoint estates in law firms and legal services organisations within the next 14 days, given the CISA KEV three-day BOD timeline and the near-ubiquity of SharePoint / iManage / Microsoft 365 collaboration in the vertical (HIGH confidence).
- It is highly likely that data-extortion attacks (encryption-optional, exfiltration-mandatory) will continue to grow at the pace suggested by Arctic Wolf's 11x YoY figure through Q3 2026, disproportionately affecting law firms because of the sensitivity and monetisable nature of client matter data (HIGH confidence).
- It is likely that Qilin, Akira and DragonForce will continue to target mid-market law firms as opportunistic ransomware targets, consistent with the SRA 2024 Risk Outlook and sector-adjacent leak-site activity (MEDIUM-HIGH confidence).
- It is a realistic possibility that a state-sponsored actor (particularly Chinese or Iranian) will conduct a targeted intrusion against a UK law firm handling sanctions, dual-use export licensing, or international arbitration matters during Q3 2026 (MEDIUM confidence).
2. Sector threat landscape
The legal sector remains one of the most targeted verticals in the UK, driven by the combination of high-value data (client matter files, board packs, transaction data, material non-public information), a payments environment (client trust accounts) that closely resembles financial services in fraud terms, and, historically, uneven cyber-maturity across the mid-market. NCSC's UK legal sector threat report, the SRA 2024 Risk Outlook and the Law Gazette's report of a 77% YoY increase in successful attacks on UK law firms all point to the same operational reality this period.
CVE-2026-45659 is operationally significant for the legal sector. SharePoint (and iManage which frequently sits alongside it) is the dominant document-management platform in mid-market and large law firms, and is the store of record for matter files, client onboarding documentation, KYC / AML packs, board packs, opinion drafts, and trust-account correspondence. The Site Member auth pre-requisite is a low bar in typical law-firm deployments where all fee earners and support staff carry at least Site Member on the matter intranet.
Data-extortion continues to dominate the operational threat picture. Arctic Wolf's 11x YoY growth figure for data-extortion incidents captures the operational reality that many actors have shifted away from encryption toward pure exfiltration-and-leak monetisation. The sensitivity of legal client data amplifies both the extortion leverage and the regulatory / reputational exposure of successful attacks. Conveyancing-fraud campaigns targeting property-transaction teams remain the leading fraud-adjacent vector, with the SRA continuing to name it in the top three impacts against firms.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking (unattributed)
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion)
- Sector Targeting: Legal, healthcare, financial services, professional services
- Geographic Focus: Global
- Signature TTPs: IAB-brokered credentials, RMM abuse, RDP; Rust payload; ESXi Linux variant
- Tooling / Malware Families: Qilin.B, Cobalt Strike, Rclone-to-Mega, Mimikatz
- Recent Activity: Sustained cadence into July 2026 per ransomware.live
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Akira
- Aliases: Akira, Storm-1567
- Suspected Origin: Russian-speaking (unattributed)
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion)
- Sector Targeting: Legal, manufacturing, professional services
- Geographic Focus: North America and Europe
- Signature TTPs: Cisco VPN unpatched initial access, IAB credentials, RDP lateral movement, ESXi targeting
- Tooling / Malware Families: Akira ransomware, Megazord ESXi variant, Rclone, AnyDesk
- Recent Activity: Cumulative $244m proceeds; sustained cadence into July
- Assessed Threat to Vertical: HIGH - direct threat to mid-market law firm ESXi back-office estates
- Analytic Confidence: HIGH
DragonForce / Scattered Spider cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra
- Suspected Origin: Anglophone (UK/US); four arrests 30 Jun 2026
- Suspected Sponsor: Organised criminal alliance
- Primary Motivation: Financial (ransomware + extortion)
- Sector Targeting: Retail, telecoms, professional services, technology; sector adjacency for legal
- Geographic Focus: Anglophone western targets
- Signature TTPs: Voice-phishing IT service desk to reset MFA, help-desk social engineering, EDR bypass via RMM, aggressive cloud-tenant pivot
- Tooling / Malware Families: DragonForce ransomware, AnyDesk, SplashTop, Ngrok, Impacket
- Recent Activity: NCA arrests 30 Jun 2026 reduce but do not eliminate operational threat under alliance-affiliate model
- Assessed Threat to Vertical: MEDIUM-HIGH - social-engineering methodology transfers to law-firm help desks
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1566.001 | Spearphishing Attachment | Malicious ISO / IMG / OneNote attachments delivering IcedID, Latrodectus and DarkGate loaders continued to dominate the phishing tail this period; volume steady week-on-week per Proofpoint and Sophos | HIGH |
| Initial Access | T1078.004 | Cloud Accounts | OAuth token replay and refresh-token abuse against Microsoft 365 tenants; credential-stuffing tail from Tor exits and bulletproof ranges | MEDIUM |
| Persistence | T1053.005 | Scheduled Task/Job | Post-exploitation scheduled-task creation observed in Akira intrusions, particularly on domain controllers immediately following DCSync activity | MEDIUM |
| Discovery | T1046 | Network Service Discovery | Automated port sweeps from datacentre-hosted infrastructure - IP Insights flagged multiple AS135771 and AS14061 sources in the perimeter tail | MEDIUM |
| Command and Control | T1071.001 | Web Protocols | Cobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives from FS-ISAC and H-ISAC partners this period; JARM / JA3 fingerprint hunts remain the primary detection | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone-to-Mega and rclone-to-MEGAsync exfiltration patterns dominant in Qilin double-extortion intrusions; Akira favours MEGA and Backblaze B2 | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin, Akira and DragonForce ransomware deployment observed against sector-adjacent peers this period per ransomware.live and FS-ISAC / H-ISAC reporting | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 01 Jul 2026 | Microsoft SharePoint Server (vendor) | Unattributed | CVE-2026-45659 KEV entry; direct impact on law-firm SharePoint / iManage document management | CISA KEV / Microsoft advisory |
| Continuing impact | Legal Aid Agency (UK) | N/A - historical breach | May 2026 LAA disruption continues to affect the market; MoJ confirmed during the period that solicitors affected will not be given a separate compensation route | Law Gazette 30 Jun 2026 update |
| Ongoing | Chaucer Group breach data (industry-wide) | N/A - statistical baseline | 226 UK law firms suffered data breaches in the past year per Chaucer Group release; statistical context for board-level risk framing | Chaucer Group press release |
| 30 Jun 2026 | Four UK nationals arrested | DragonForce / Scattered Spider cluster | NCA arrests reduce but do not eliminate operational threat to sector | National Crime Agency press release |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-45659 | Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE | 8.8 | Yes | Yes | Patch immediately per CISA KEV entry 01 Jul 2026, remediation deadline 04 Jul 2026; audit Site Member permissions; restrict inbound SharePoint /_layouts and /_vti_bin paths at the WAF; hunt w3wp.exe child processes |
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; BOD 26-04 deadline 26 Jun 2026 has passed; restrict management plane to dedicated VLAN |
| CVE-2026-34909 | Ubiquiti UniFi OS Server - path traversal | 9.8 | Yes | Yes | As per -34908; component of the Bishop Fox unauthenticated root RCE chain |
| CVE-2026-34910 | Ubiquiti UniFi OS Server - improper input validation | 9.8 | Yes | Yes | As per -34908; component of the Bishop Fox unauthenticated root RCE chain |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3) | 9.3 | Yes | Yes | Fixed builds 14.1-66.59, 13.1-62.23, 13.1-37.262 FIPS/NDcPP; must run 'kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all' post-patch |
| CVE-2026-4368 | Citrix NetScaler Gateway / AAA vserver - race condition | 7.7 | Yes | Yes | Applied by the same patches as -3055; session mix-up risk against Gateway and AAA virtual servers |
| CVE-2025-67038 | Lantronix EDS5000 serial-to-IP bridge - command injection | 9.6 | Yes | Suspected | Vendor patch pending; segment device management to dedicated OT VLAN |
| CVE-2026-50751 | Check Point Security Gateway - improper authentication | 9.8 | Yes | Yes | Apply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - authenticated RCE | 8.4 | Yes | Suspected | Cisco fixed release train; disable public-facing vManage where feasible |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]101[.]34 | 28 Jun 2026 | HIGH | for-privacy.net Tor exit; IP Insights score 100 / critical; 8 blacklists; observed in credential-spray tail against Entra ID sign-in endpoints |
| IP | 194[.]180[.]48[.]18 | 30 Jun 2026 | HIGH | serverion (NL); IP Insights score 85 / critical; 2 active + 3 degraded blacklists; observed in SSH brute-force tail against perimeter jump hosts |
| IP | 141[.]98[.]11[.]90 | 02 Jul 2026 | MEDIUM | UAB Host Baltic AS209605 (LT); IP Insights score 10 / low but datacentre-flagged; source of scripted OAuth token replay against Microsoft 365 |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| SharePoint (CVE-2026-45659) mass-exploitation at document-management estate | H | H | CRITICAL |
| Data-extortion of matter files / client MNPI / trust-account documentation | H | H | CRITICAL |
| Conveyancing fraud via mailbox-rule creation on partner / conveyancer mailbox | H | H | CRITICAL |
| Ransomware deployment via CitrixBleed 3 session-token theft | M | H | HIGH |
| Help-desk social engineering (DragonForce-style) to reset MFA on privileged accounts | M | H | HIGH |
| State-sponsored targeting of sanctions / dual-use / arbitration teams | L | H | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat CVE-2026-45659 as the principal hunting hypothesis for the next reporting cycle. Rules around w3wp.exe spawning cmd or PowerShell under the SharePoint app-pool identity, ULS log deserialisation exceptions, and Site Member-permission accounts accessing upload endpoints must be deployed. Deploy conveyancing-fraud-specific detections against partner / conveyancer mailboxes: New-InboxRule with keyword filters matching common purchase / completion / undertaking terminology, mailbox-forwarding rule creation, delegated-access grants outside expected sessions. Retain Qilin / Akira initial-access hunt playbook. Deploy help-desk social-engineering hunts: MFA reset events shortly followed by first-time sign-in from a non-corporate device or IP, particularly if the target is a partner-level or IT-admin account.
Defend
Preventive priorities follow Section 6 directly. SharePoint / iManage patching must be prioritised as CVE-2026-45659 remediation, with the CISA KEV 04 Jul deadline as the operational anchor. Complete NetScaler patching and session-invalidation. Deploy phishing-resistant MFA (FIDO2, Windows Hello for Business) to all partner-level and conveyancer accounts, and to any IT-admin / service-desk account with MFA-reset authority. Deploy Conditional Access rules blocking non-managed devices from initiating mailbox-rule creation and mailbox-forwarding actions. Where iManage or NetDocuments is the primary DMS, review third-party integration attack surface and disable unused connectors. Baseline data loss prevention on matter files and MNPI-tagged documents.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the SRA cyber-security peer group and the informal law-firm information-sharing channel, with this week's IP Insights critical / block tail contributed; (ii) NCSC CiSP membership for law-firm technical staff to enable indicator exchange under the professional services vertical; (iii) coordinated take-down requests to bulletproof providers for conveyancing-fraud infrastructure, submitted through the NCSC Takedown Service; (iv) participation in SRA / Law Society tabletop exercises for large-firm incident response, including data-extortion negotiation and regulatory notification workflows.
10. Forward outlook
Looking forward to the next reporting period (04 Jul - 10 Jul 2026), it is likely that at least one UK law firm will publicly disclose a SharePoint-borne incident attributable to CVE-2026-45659. It is likely that data-extortion attacks against mid-market law firms will continue at elevated volumes. Conveyancing-fraud attempts against partner mailboxes are expected to remain steady week-on-week. Ransomware leak-site cadence from Qilin and Akira is expected to remain steady, with a moderate probability of a directly-attributed UK law-firm victim posting during the period.
Trigger conditions that would prompt revision of this outlook include: (a) any publicly-disclosed UK law-firm SharePoint / iManage incident attributable to CVE-2026-45659; (b) any confirmed state-sponsored intrusion against a UK law firm handling sanctions or dual-use export licensing, which would warrant immediate out-of-cycle reporting; (c) any material change in the operational tempo of the DragonForce / Scattered Spider cluster following the NCA arrests.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities catalogue (daily updates) | CISA | A1 |
| 3 | CISA KEV addition of CVE-2026-45659 SharePoint deserialisation RCE, 01 Jul 2026 | CISA | A1 |
| 4 | CISA KEV addition of CVE-2026-34908, -34909, -34910 Ubiquiti UniFi OS chain, 23 Jun 2026 | CISA | A1 |
| 5 | Citrix Security Bulletin CTX696300 for CVE-2026-3055 and CVE-2026-4368 | Citrix / Cloud Software Group | A2 |
| 6 | Microsoft Security Update Guide entry for CVE-2026-45659 | Microsoft | A2 |
| 7 | SharePoint RCE CVE-2026-45659 added to CISA KEV after active exploitation | The Hacker News | B2 |
| 8 | CISA warns of actively exploited Microsoft SharePoint vulnerability | SecurityWeek | B2 |
| 9 | Rapid7 vulnerability database: Microsoft SharePoint CVE-2026-45659 | Rapid7 | B1 |
| 10 | NHS England Digital cyber alert CC-4759 - Citrix critical security updates | NHS Digital | A1 |
| 11 | ransomware.live daily leak-site tracker | ransomware.live | B2 |
| 12 | The State of Ransomware - Q1 2026 | Check Point Research | A2 |
| 13 | Global ransomware activity for May 2026 | Industrial Cyber | B2 |
| 14 | FS-ISAC daily indicator exchange (member portal - TLP:CLEAR) | FS-ISAC | A1 |
| 15 | H-ISAC daily bulletin (member portal - TLP:CLEAR) | H-ISAC | A1 |
| 16 | MTS-ISAC daily bulletin and Cyware indicator exchange (TLP:CLEAR) | MTS-ISAC | A1 |
| 17 | Retail and Hospitality ISAC member exchange (TLP:CLEAR) | RH-ISAC | A1 |
| 18 | NCA arrests four for attacks on M&S, Co-op and Harrods (30 Jun 2026) | National Crime Agency | A1 |
| 19 | AA25-239A: Countering Chinese State-Sponsored Actors | CISA / NSA / NCSC / partners | A1 |
| 20 | July rundown - Salt Typhoon and SharePoint scares | IT Pro | B2 |
| 21 | NHS South East London / Synnovis long-tail update | Recorded Future News | B2 |
| 22 | NHS pathology reports backlog update (Q1 2026) | Digital Health | B2 |
| 23 | NCSC Cyber Threat Report: UK Legal Sector | National Cyber Security Centre | A1 |
| 24 | Cyber attacks on law firms jump by 77% (Jun 2026) | Law Society Gazette | B2 |
| 25 | 226 UK law firms suffered data breaches in the past year | Chaucer Group | C3 |
| 26 | SRA 2024 Risk Outlook (ongoing reference) | Solicitors Regulation Authority | A2 |
| 27 | M&S, Co-op & Harrods cyber-attacks - lessons for retailers | Brabners | B2 |
| 28 | Cyber-attacks on M&S, Co-op, Harrods post-incident summary | Air IT Group | C2 |
| 29 | NCSC Cyber Threat Report: UK Charity Sector | National Cyber Security Centre | A1 |
| 30 | GOV.UK: protect your charity from cyber crime | Cabinet Office / DCMS | A1 |
| 31 | IP Insights REST API enrichment (multiple lookups during the reporting period) | IP Insights / UK Cyber Defence Ltd | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Legal Threat Intelligence Briefing
May 2025 Legal Sector Threat Analysis
Legal services threat intelligence report — 27 April – 3 May 2026
The legal-services threat picture for the reporting period continues to reflect a sharp upward trajectory in attacks on UK law firms — the Law Gazette reports a 77 per cent year-on-year rise in successful attacks (538 to 954)…
Legal services threat intelligence report — 4–8 May 2026
The legal-services threat picture for the reporting period continues to reflect the sharp upward trajectory in attacks on UK law firms — the Law Gazette has reported a 77 per cent year-on-year rise in successful attacks (538 to 954)…