Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
- Reference: TI-2026-0504-004 (public edition)
- Sector: Retail
- Reporting period: 27 April – 3 May 2026
- Issued: 4 May 2026 · Lead analyst: P. Bassill (SOC Lead) · Reviewed by: SOC Reviewing Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m. The Scattered Spider / DragonForce affiliate cluster is the proximate threat-actor cluster of greatest concern. The reporting period continues to surface helpdesk social-engineering tradecraft against UK retail support operations and sustained Qilin / Akira / DragonForce leak-site activity.
Key Judgements
1. It is highly likely that the Scattered Spider / DragonForce affiliate cluster will continue to target UK retail support operations through helpdesk social engineering and identity-provider compromise over the next reporting cycle. (HIGH confidence)
2. It is likely that retail point-of-sale and e-commerce platforms operating shared payment / loyalty SaaS will continue to be attractive Cl0p / ShinyHunters data-extortion targets. (MEDIUM-HIGH confidence)
3. It is likely that the operational and regulatory cost of the M&S / Co-op campaign (£270m–£440m, ICO engagement) will drive significant retail-sector defensive investment over the next 12 months, particularly in identity controls and helpdesk procedure. (HIGH confidence)
4. There is a realistic possibility that Citrix NetScaler CVE-2026-3055 / 4368 exploitation will affect retail-sector edge appliances within the next two reporting cycles. (MEDIUM confidence)
2. Sector threat landscape
The economic dimension of the spring-2025 wave has been substantial. Combined direct, recovery, and lost-trading costs across the M&S, Co-op and Harrods incidents are estimated in the £270m–£440m range, with the events classed as a Category 2 cyber-event by UK industry experts. M&S customer personal data (names, addresses, order histories) was exfiltrated; Co-op confirmed access to current and past members' data with the actor claim of 20 million records reaching the press, although Co-op did not confirm that figure. Payment data and passwords were not accessed in the M&S incident on the company's public timeline.
Beyond the named retailers, ransomware leak-site activity against the wider retail and hospitality vertical continued at sustained tempo through April 2026. Qilin (103 postings) led globally, Akira (48) and LockBit (39) maintained strong tempo, and DragonForce continued to move up the leaderboard. ShinyHunters and WorldLeaks pure-data-extortion postings continued to surface retail e-commerce victims operating shared loyalty / payment SaaS platforms.
The geopolitical dimension is secondary in the vertical: hacktivist DDoS against UK retail public-facing storefronts continues at low operational tempo and is meaningfully less material than organised-criminal ransomware and helpdesk social engineering. The UK Cyber Security Breaches Survey 2025/2026 confirms phishing as the most common (38%) and most disruptive incident type across UK businesses generally.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
| THREAT ACTOR PROFILE — Scattered Spider / DragonForce affiliate cluster | |
|---|---|
| Aliases | UNC3944, Octo Tempest, Muddled Libra |
| Suspected Origin | Western (UK / US, English-speaking) |
| Suspected Sponsor | Organised criminal — affiliate of multiple RaaS |
| Primary Motivation | Financial — ransomware, data theft, extortion |
| Sector Targeting | Retail, hospitality, financial services, telecoms, BPO |
| Geographic Focus | Global; high-tempo UK and North American operations |
| Signature TTPs | SIM-swap and helpdesk social engineering; MFA fatigue; abuse of identity providers; rapid pivot to cloud admin planes; commercial-RMM abuse |
| Tooling / Malware Families | Living-off-the-land; ScreenConnect; AnyDesk; DragonForce ransomware payload |
| Recent Activity | Spring-2025 M&S / Co-op / Harrods campaign — Category 2 cyber-event, £270m–£440m combined cost; tradecraft has become the reference template for follow-on actors targeting UK retail support |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — Qilin | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal — RaaS |
| Primary Motivation | Financial — ransomware and data extortion |
| Sector Targeting | Retail, healthcare, financial services, manufacturing |
| Geographic Focus | Global |
| Signature TTPs | Stolen / brute-forced credentials; exposed RDP / VPN; rapid double extortion |
| Tooling / Malware Families | Qilin / Agenda encryptors; AnyDesk, RustDesk |
| Recent Activity | 103 leak-site postings in April 2026; retail subset includes regional and specialty retailers |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — ShinyHunters / WorldLeaks | |
|---|---|
| Aliases | Various — pure-data-extortion brand |
| Suspected Origin | Mixed |
| Suspected Sponsor | Organised criminal |
| Primary Motivation | Financial — pure data extortion |
| Sector Targeting | Retail, e-commerce, hospitality, financial services |
| Geographic Focus | Global |
| Signature TTPs | API / SaaS exploitation; loyalty / payment-platform breach; coordinated leak-site posting; brand-pressure leveraging |
| Tooling / Malware Families | Custom web shells and API-abuse scripts; leak portal |
| Recent Activity | Sustained pure-data-extortion postings during the reporting period; retail e-commerce subset features prominently |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | MEDIUM |
| THREAT ACTOR PROFILE — Cl0p | |
|---|---|
| Aliases | TA505 affiliate, FIN11-adjacent |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal |
| Primary Motivation | Financial — data extortion |
| Sector Targeting | Retail, financial services, healthcare, public sector |
| Geographic Focus | Global |
| Signature TTPs | Mass-exploitation of trusted file-transfer / SaaS platforms (MOVEit-pattern); pure data extortion |
| Tooling / Malware Families | Custom web shells; Truebot; Cl0p leak portal |
| Recent Activity | Sustained leak-site activity during the reporting period; retail / e-commerce subset includes shared-platform victims |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1566 | Phishing | Retail-themed (loyalty, returns, supplier-onboarding) lures continue to drive credential-theft volumes against the vertical. | H |
| Initial Access | T1199 | Trusted Relationship | Helpdesk / Partner-PA social engineering of outsourced retail support is the M&S / Co-op pattern. | H |
| Initial Access | T1078.004 | Cloud Accounts | Identity-provider compromise (Okta, Azure AD) following helpdesk-driven password reset and MFA enrolment changes. | H |
| Persistence | T1136.003 | Create Cloud Account | Scattered-Spider-style federated-identity persistence; new-account / new-app-registration in the cloud control plane. | H |
| Defence Evasion | T1556.006 | Multi-Factor Authentication | MFA-fatigue and number-matching bypass; SIM-swap of registered phone factors. | H |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / Mega.io / direct cloud-object-storage egress is the routine pattern across Akira and DragonForce data-theft phases. | H |
| Impact | T1486 | Data Encrypted for Impact | DragonForce, Qilin, Akira encryptors deploying against UK retail and hospitality at sustained tempo. | H |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Spring 2025 — carry-forward | Marks & Spencer (UK) | Scattered Spider / DragonForce | Customer PII (names, addresses, order histories) exfiltrated; payment data not accessed; multi-month operational impact | Public reporting |
| Spring 2025 — carry-forward | Co-op (UK) | Scattered Spider / DragonForce | Member data accessed; actor claim 20 million records (unconfirmed); ICO engagement | Public reporting |
| Spring 2025 — carry-forward | Harrods (UK) | Scattered Spider / DragonForce | Cyber incident confirmed; sector-wide diligence cycle resulted | Public reporting |
| Apr 2026 | Multiple retail leak-site listings (global) | Qilin, Akira, DragonForce, ShinyHunters | 772 victims claimed across 70 groups in April; retail subset includes regional and specialty retailers | Ransomware leak-site tracking |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-31431 | Linux Kernel (resource transfer) | 7.8 | Yes | Yes | Apply distro patches; prioritise Internet-facing & multi-tenant hosts |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys; review for known-exploit IOCs |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-41940 | WebPros cPanel / WP Squared / WHM | 9.8 | No | Suspected | Patch; audit panel admin auth events |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager | 8.8 | Yes | Yes | Patch immediately; restrict admin plane to mgmt VLAN |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Rotate SD-WAN passwords; patch |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Patch; review information disclosure logs |
| CVE-2025-2749 | Kentico Xperience | 9.0 | Yes | Yes | Patch; audit upload paths |
| CVE-2025-32975 | Quest KACE SMA | 8.8 | Yes | Suspected | Patch; restrict KACE management UI |
| CVE-2025-48700 | Synacor Zimbra Collaboration | 6.1 | Yes | Yes | Patch; restrict webmail to authenticated users |
| CVE-2024-27199 | JetBrains TeamCity | 7.3 | Yes | Yes | Patch; rotate CI secrets |
7. Indicators of compromise
Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. IP Insights reputation feed currently lists 812,641 distinct IPv4 addresses across active blocklists (snapshot 04 May 2026 08:15 UTC). AS200651 (FlokiNET) currently lists 110 of 131 known IPs as blacklisted (risk score 100/critical); the AS continues to host bulletproof-style infrastructure observed in the reporting period across phishing, RAT C2, and brute-force activity.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force; IP Insights threat 100/critical, 6 active blacklists; Reliance Jio IN |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd (GB) — IP Insights threat 100/critical, 6 blacklists |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit — IP Insights threat 100/critical, 7 blacklists |
| ASN | AS200651 | 04 May 2026 | H | FlokiNET — 110/131 known IPs blacklisted; bulletproof-style hosting |
| Pattern | Helpdesk / Partner-PA password-reset or MFA-enrolment-change events outside baseline | 27 Apr 2026 | H | Scattered-Spider tradecraft; hunt against IdP audit logs (Okta / Azure AD) |
| Pattern | Cloud admin-plane new-app-registration / new-federation-domain | 27 Apr 2026 | H | Scattered-Spider persistence; hunt against Azure AD / Okta admin event logs |
| Pattern | rclone / Mega.io egress from corporate file-shares | 27 Apr 2026 | H | DragonForce / Akira data-theft hallmark |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Helpdesk / Partner-PA social engineering leading to identity-provider compromise (Scattered Spider pattern) | H | H | CRITICAL |
| Ransomware deployment via initial-access broker (Qilin / Akira / DragonForce) | H | H | CRITICAL |
| Pure data extortion via shared loyalty / payment SaaS exploitation (Cl0p / ShinyHunters pattern) | M | H | HIGH |
| Edge-appliance compromise via Citrix NetScaler / Cisco SD-WAN CVEs | M | H | HIGH |
| Hacktivist DDoS against e-commerce storefront | H | L | MEDIUM |
| Magecart / web-skimming compromise of e-commerce checkout | M | M | MEDIUM |
| Insider exfiltration of loyalty / customer data | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities are: identity-provider audit-log hunting for password-reset / MFA-enrolment-change events outside the customer-specific baseline (Scattered Spider tradecraft); cloud admin-plane hunting for new-app-registration / new-federation-domain events; rclone / Mega.io / direct-cloud-object-storage egress from corporate file-shares; PowerShell -ExecutionPolicy Bypass parented by non-baseline processes; and Citrix NetScaler / Cisco SD-WAN exploitation indicators as soon as Sigma rules are released. Where customers operate Magento / Shopify / similar e-commerce platforms, hunting for Magecart-pattern script injection in checkout-page resources is warranted.
Defend
Patching priorities are dominated by Citrix NetScaler ADC / Gateway and the Linux kernel CVE-2026-31431. The single highest-impact defensive investment for the vertical is identity-controls hardening to mitigate Scattered-Spider-style helpdesk social engineering: number-matching MFA, helpdesk procedure requiring out-of-band verification for password reset and MFA enrolment changes, and conditional-access rules requiring a known-device or known-network token for high-privilege accounts. ISO/IEC 27001 Annex A controls A.5.16 (identity management) and A.5.17 (authentication information) are direct levers. PCI-DSS v4.0 controls remain the operating standard for cardholder-data environments.
Disrupt
Disruption priorities are tabletop exercise against the helpdesk-compromise scenario for any customer with outsourced retail support; coordination with the Retail and Hospitality ISAC where customers are members; sustained sharing of the IP Insights blocklist into customer perimeter-block lists; and rehearsal of the customer-PII-extortion-without-encryption scenario for any customer holding material loyalty / membership data.
10. Forward outlook
It is highly likely that Scattered-Spider-style helpdesk social engineering will remain the principal helpdesk-and-identity material-risk scenario for the vertical over the next reporting cycle. (HIGH confidence; 30-day horizon)
It is likely that ransomware leak-site activity against UK retail will continue at sustained tempo, with DragonForce, Qilin and Akira the most operationally-relevant operators. (HIGH confidence; 30-day horizon)
It is likely that Citrix NetScaler exploitation will affect at least one UK retail edge appliance within the next two reporting cycles. (MEDIUM-HIGH confidence; 60-day horizon)
There is a realistic possibility that a UK retailer will suffer a Cl0p-pattern shared-SaaS data-extortion event within the next six reporting cycles. (MEDIUM confidence; 180-day horizon)
Trigger conditions that would prompt revision of this forecast: a confirmed Scattered-Spider intrusion into a UK retailer's identity provider; in-the-wild exploitation of a previously-quiet retail SaaS platform along the Cl0p pattern; observed Magecart-pattern script injection on a customer e-commerce checkout.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC — Threat reports | NCSC.GOV.UK | A1 |
| 2 | CISA KEV — April / May 2026 additions | CISA | A1 |
| 3 | Computer Weekly — M&S, Co-op attacks a Category 2 cyber hurricane | Computer Weekly | B2 |
| 4 | SecurityAffairs — Financial impact of M&S and Co-op cyberattacks could reach £440M | SecurityAffairs | B2 |
| 5 | Eye Security — Retail Giants Breached: M&S, Harrods, UNFI | Eye Security | B2 |
| 6 | April 2026 Ransomware Report — 772 victims, 70 groups | BreachSense | B2 |
| 7 | Heimdal Security — Retail cybersecurity statistics for 2026 | Heimdal Security | C2 |
| 8 | UK Cyber Security Breaches Survey 2025/2026 | GOV.UK / DSIT | A1 |
| 9 | IP Insights — IP / ASN / CIDR threat intelligence API | ipinsights.io | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…
Retail threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the retail threat picture continued to be defined by the aftermath and direct lineage of the M&S and Co-op cyber attacks attributable to the Scattered Spider / DragonForce affiliate cluster.