SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Retail threat intelligence report — 4–8 May 2026

The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…

  • Reference: TI-2026-0508-004 (public edition)
  • Sector: Retail
  • Reporting period: 4–8 May 2026
  • Issued: 8 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m — and the M&S / Co-op timeline remains the operational reference case for UK retail incident-response planning. The reporting period continues to surface helpdesk social-engineering tradecraft against UK retail support operations and sustained Qilin / TheGentlemen / DragonForce leak-site activity. The single most operationally-significant development inside the reporting window is NCSC's 4 May 2026 blog on the AI-accelerated patch wave, which is materially relevant to retailers with extensive Citrix, Ivanti and PAN-OS exposure.

Key Judgements

The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that the Scattered Spider / DragonForce affiliate cluster will continue to target UK retail support operations through helpdesk social engineering and identity-provider compromise over the next reporting cycle. The April 2026 leak-site picture (DragonForce 63 victims, third place globally) confirms sustained operational tempo. (HIGH confidence)
  2. It is likely that retail point-of-sale and e-commerce platforms operating shared payment / loyalty SaaS will continue to be attractive Cl0p / ShinyHunters data-extortion targets, with the MOVEit Automation CVE-2026-4670 active-exploitation reporting realigning the operator signature with the vertical's trust-platform exposure. (MEDIUM-HIGH confidence)
  3. It is likely that the operational and regulatory cost of the M&S / Co-op campaign (£270m–£440m, ICO engagement) will continue to drive significant retail-sector defensive investment over the next 12 months, particularly in identity controls and helpdesk procedure. (HIGH confidence)
  4. It is likely that the AI-accelerated patch-wave dynamic flagged by NCSC on 4 May 2026 will produce at least one nationally-significant retail exploitation event within the next two reporting cycles, with Citrix NetScaler, Ivanti EPMM and PAN-OS User-ID portal exposure the highest-leverage gating factors. (MEDIUM confidence)
  5. There is a realistic possibility that follow-on attacks against North-American grocery and convenience retailers (UNFI carry-forward) will continue to provide template tradecraft for adjacent UK affiliates throughout 2026. (MEDIUM confidence)

2. Sector threat landscape

Retail remains a structurally attractive target class. The combination of high-volume payment-card flow, dispersed point-of-sale estates, complex outsourced helpdesk dependencies, and intense seasonal trading windows that disincentivise patch-wave responses continues to elevate the sector's exposure. The M&S, Co-op and Harrods incidents of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates between £270m and £440m — remain the operational reference case for UK retail incident response.

The April 2026 leak-site picture (Breachsense, ransomware.live) — 772 victims claimed across 70 groups — continues to track the retail subset closely. Qilin (103 April postings, 445 year-to-date) is the leading single operator; TheGentlemen (82) has displaced Akira (69) into second place; DragonForce (63) holds third. The Scattered Spider / DragonForce affiliate cluster continues to be the dominant tradecraft-template for UK retail attacks, with helpdesk social-engineering, MFA fatigue, and identity-provider compromise (Okta / Azure AD) the canonical access pattern.

Edge-appliance and identity-provider exposure are the two dominant gating factors for the vertical. The Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055, CVE-2026-4368), the Ivanti EPMM CVE-2026-6973 (KEV-listed 1 May 2026, FCEB deadline 10 May) and the Palo Alto PAN-OS User-ID portal CVE-2026-0300 (KEV-listed 6 May 2026, FCEB deadline 27 May) are immediately operationally relevant; the MOVEit Automation CVE-2026-4670 active-exploitation reporting matters for any retailer running automated payment / loyalty / supplier file transfer.

Geopolitical pressure is sub-dominant in retail compared with criminal activity, but ScarCruft's gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the wider pattern of state-aligned actors using third-party software supply chains as a delivery vector — a pattern of acute concern in retail, where loyalty-platform and payment-orchestration software are tightly concentrated across a small number of vendors.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.

Scattered Spider / DragonForce affiliate cluster

  • Aliases: UNC3944, Octo Tempest, Muddled Libra
  • Suspected Origin: Western (UK / US, English-speaking)
  • Suspected Sponsor: Organised criminal — affiliate of multiple RaaS
  • Primary Motivation: Financial — ransomware, data theft, extortion
  • Sector Targeting: Retail, hospitality, financial services, telecoms, BPO
  • Geographic Focus: Global; high-tempo UK and North American operations
  • Signature TTPs: SIM-swap and helpdesk social engineering; MFA fatigue; abuse of identity providers (Okta, Azure AD); rapid pivot to cloud admin planes; DragonForce ransomware payload
  • Tooling / Malware Families: Living-off-the-land; commercial RMM tooling; DragonForce ransomware payload
  • Recent Activity: 63 leak-site postings in April 2026 — third-place global ranking; cluster tradecraft from M&S / Co-op continues to template UK retail attacks
  • Assessed Threat to Vertical: HIGH — helpdesk social-engineering vector remains poorly mitigated in many UK retail support operations
  • Analytic Confidence: HIGH

Qilin

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal — RaaS
  • Primary Motivation: Financial — ransomware and data extortion
  • Sector Targeting: Retail, healthcare, financial services, professional services
  • Geographic Focus: Global; sustained UK activity
  • Signature TTPs: Stolen / brute-forced credential access; double extortion; fast time-to-encrypt
  • Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptors
  • Recent Activity: 103 April 2026 leak-site postings — fourth consecutive month leading
  • Assessed Threat to Vertical: HIGH
  • Analytic Confidence: HIGH

TheGentlemen

  • Aliases:
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal — RaaS
  • Primary Motivation: Financial — ransomware
  • Sector Targeting: Retail, manufacturing, professional services
  • Geographic Focus: Global; growing UK and EU activity
  • Signature TTPs: Edge-appliance and stolen-credential initial access; rapid lateral movement; double-extortion
  • Tooling / Malware Families: Custom encryptor; LOLBins
  • Recent Activity: 82 leak-site postings in April 2026 — second-place global ranking
  • Assessed Threat to Vertical: HIGH — rising tempo and confirmed retail-aligned victimology
  • Analytic Confidence: MEDIUM-HIGH

Cl0p / ShinyHunters / WorldLeaks cluster

  • Aliases: TA505 (Cl0p)
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal
  • Primary Motivation: Financial — pure data extortion
  • Sector Targeting: Retail, financial services, healthcare — file-transfer and SaaS-platform-dependent verticals
  • Geographic Focus: Global
  • Signature TTPs: Mass-exploitation of file-transfer / SaaS platform CVEs; pure data extortion without encryption; coordinated leak-site posting
  • Tooling / Malware Families: Custom web shells; Truebot loader
  • Recent Activity: MOVEit Automation CVE-2026-4670 active-exploitation reporting realigns operator signature with retail trust platforms
  • Assessed Threat to Vertical: MEDIUM-HIGH — disproportionate impact-per-campaign for retailers with shared payment / loyalty SaaS
  • Analytic Confidence: MEDIUM-HIGH

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1566.004Spearphishing VoiceSustained helpdesk social-engineering tradecraft templated on the M&S / Co-op campaign — primary access vector for the Scattered Spider / DragonForce cluster.H
Initial AccessT1133External Remote ServicesCitrix NetScaler / Ivanti EPMM / PAN-OS additions to KEV expose retail edge appliances; extensive head-office and store-network remote-access surface.H
Initial AccessT1190Exploit Public-Facing ApplicationMOVEit Automation CVE-2026-4670 and Weaver E-Cology CVE-2026-22679 add unauthenticated RCE surfaces to retail trust platforms and supplier portals.H
Initial AccessT1199Trusted RelationshipCl0p / ShinyHunters cluster continues to favour shared SaaS / loyalty platform exploitation for mass-victim impact.H
Privilege EscalationT1098Account ManipulationIdentity-provider compromise (Okta, Azure AD) following helpdesk social-engineering — the canonical post-access pattern for the cluster.H
Lateral MovementT1021.007Remote Services: Cloud ServicesIdentity-provider abuse pivots to cloud-admin plane — sector-typical for the Scattered Spider cluster.M
ImpactT1486Data Encrypted for ImpactDragonForce, Qilin, TheGentlemen affiliates continue to deploy encryptors against retail at scale.H
ImpactT1565.002Data Manipulation: Transmitted DataPoS estate / payment-orchestration manipulation as a secondary impact vector — relevant for retailers with bespoke checkout integrations.M

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
May 2026Multiple retail leak-site listings (global)Qilin, TheGentlemen, DragonForce, Cl0pRetail subset of the 772 April leak-site victims; sustained Q1–Q2 2026 baselineRansomware.live; Breachsense
May 2026Vulnerability patch wave (sector-wide)MultipleNCSC 4 May 2026 blog warns AI-accelerated vulnerability discovery is shrinking time-to-weaponisationNCSC; CISA
Apr 2026UK retailers (M&S, Co-op, Harrods) — adjacent reportingScattered Spider / DragonForceContinued reputational and supply-chain spillover; vendor-diligence questionnaires recirculating across UK retail; £270m–£440m reference cost band standsComputer Weekly; ICO
RecentUnited Natural Foods Inc. (UNFI, US)Affiliate-cluster (carry-forward)Confirmed cyber incident in the M&S / Co-op follow-on wave; relevant template tradecraft for UK grocery operatorsPublic reporting

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM)8.8Yes (1 May)YesPatch immediately; FCEB deadline 10 May; rotate admin sessions
CVE-2026-0300Palo Alto Networks PAN-OS User-ID Portal9.8Yes (6 May)YesPatch immediately; FCEB deadline 27 May; restrict portal exposure
CVE-2026-3055Citrix NetScaler ADC / Gateway9.3YesYesPatch immediately; rotate session keys
CVE-2026-4368Citrix NetScaler ADC / Gateway8.8YesYesPatch; audit Gateway session logs
CVE-2026-4670Progress MOVEit Automation9.8PendingYesPatch; audit MFT operator authentication on retail supplier / loyalty estates
CVE-2026-22679Weaver E-Cology9.8YesPatch; restrict OA platform to internal networks
CVE-2026-41940WebPros cPanel / WP Squared / WHM9.8YesPatch; audit panel admin auth events on hosted-website and brand-microsite estates

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.

TypeIndicatorFirst SeenConf.Notes
IPv487[.]103[.]126[.]5430 Apr 2026HSSH brute-force — Vodafone PT (AS12353); IP Insights threat 100/critical, 6 active blacklists
IPv4136[.]232[.]11[.]1020 Apr 2026HSSH brute-force — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 6 active blacklists
IPv487[.]236[.]176[.]4502 May 2026MConstantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298); cross-tenant scanning
IPv4185[.]220[.]101[.]3003 May 2026MTor exit (for-privacy.net); 7 active blacklists
ASNAS200651OngoingHFlokiNET — 110/132 known IPs blacklisted; bulletproof-style hosting consistently observed in retail-themed phishing
PatternHelpdesk voice social-engineering against outsourced retail support BPOOngoingHTemplated on M&S / Co-op campaign; community-shared indicator sets via RH-ISAC

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite
Helpdesk social-engineering against outsourced retail support BPO leading to MFA-bypass and identity-provider compromiseHHCRITICAL
Ransomware deployment via DragonForce / Qilin against ESXi or PoS estateMHHIGH
Pure data extortion via shared payment / loyalty SaaS platform compromiseMHHIGH
AI-assisted phishing of head-office and procurement inboxes leading to BEC and supplier-payment fraudMMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection priorities for the next reporting cycle should focus on two concurrent themes. First, identity-provider abuse — phishing-resistant MFA bypass, MFA-fatigue, and Okta / Azure AD configuration-drift telemetry, with explicit alerting on first-seen IP geolocation for privileged accounts and on helpdesk-mediated credential resets. Second, edge-appliance exploitation telemetry: Citrix NetScaler, Ivanti EPMM and PAN-OS User-ID portal access correlated against published indicator-of-compromise sets. The Retail and Hospitality ISAC remains the single highest-value source for retail-specific helpdesk-tradecraft indicators.

Defend

Patch posture and helpdesk procedure are the two highest-leverage defensive priorities. The Ivanti EPMM, PAN-OS, NetScaler, MOVEit Automation, Weaver E-Cology and cPanel patch-wave should be circulated to all retail clients with edge-appliance or hosted-platform exposure. Helpdesk procedure should be reviewed against the M&S / Co-op operational lessons: voice authentication should never permit credential reset on its own, callback-to-known-number protocols should be standard for any privileged identity change, and identity-provider configuration changes should require multi-person authorisation. ISO/IEC 27001 Annex A 5.16, 5.17 and 8.5 are the relevant references; PCI-DSS 4.0 sections 8 and 12 remain authoritative for any retailer in cardholder-data scope.

Disrupt

Disruption priorities are concentrated in three areas. First, indicator sharing within the Retail and Hospitality ISAC and CiSP, particularly the helpdesk social-engineering tradecraft that templated on the M&S / Co-op campaign. Second, takedown coordination on phishing infrastructure attributable to AS200651 (FlokiNET), particularly retail-themed loyalty-program impersonation kits. Third, tabletop exercise activity covering the helpdesk social-engineering scenario at outsourced support BPO scope.

10. Forward outlook

It is highly likely that the AI-driven patch-wave dynamic will continue to dominate the operational picture for the next reporting cycle, with retail-sector Citrix and Ivanti exposure the highest-leverage gating factor. It is likely that helpdesk social-engineering tradecraft templated on the M&S / Co-op campaign will continue to be replicated against UK retail support operations, particularly during the May-bank-holiday and early-summer trading windows.

Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 against a UK retailer; emergence of a new affiliate cluster with explicit retail-sector victimology distinct from the Scattered Spider / DragonForce template; or a material change in the Cl0p / ShinyHunters operational tempo against retail trust platforms.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC – Preparing for a vulnerability patch wave (4 May 2026 blog)NCSCA2
2NCSC Annual Review 2025 – ransomware and nationally significant incidentsNCSCA1
3UK Cyber Security Breaches Survey 2025/2026 (DSIT)GOV.UKA1
4CISA Known Exploited Vulnerabilities Catalogue (rolling)CISAA1
5CISA Alert – Ivanti EPMM CVE-2026-6973 added to KEV (1 May 2026)CISAA1
6CISA Alert – Palo Alto PAN-OS CVE-2026-0300 added to KEV (6 May 2026)CISAA1
7Breachsense – April 2026 Ransomware Report (772 victims, 70 groups)BreachsenseB2
8Ransomware.live – sector and group leak-site indexRansomware.liveB2
9IP Insights – IP reputation and blocklist enrichment serviceUK Cyber DefenceA1
11Computer Weekly – M&S, Co-op attacks a 'Category 2 cyber hurricane'Computer WeeklyB2
12BlackFog – Marks & Spencer Breach: How a Ransomware Attack Crippled a UK Retail GiantBlackFogC2
13BleepingComputer – Marks & Spencer breach linked to Scattered Spider ransomware attackBleepingComputerC2
14Eye Security – Retail Giants Breached: M&S, Harrods & UNFIEye SecurityC2
15Infosecurity Magazine – How the UK Retail Sector Responded to the Scattered Spider Hack WaveInfosecurity MagazineC2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.