Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…
- Reference: TI-2026-0508-004 (public edition)
- Sector: Retail
- Reporting period: 4–8 May 2026
- Issued: 8 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m — and the M&S / Co-op timeline remains the operational reference case for UK retail incident-response planning. The reporting period continues to surface helpdesk social-engineering tradecraft against UK retail support operations and sustained Qilin / TheGentlemen / DragonForce leak-site activity. The single most operationally-significant development inside the reporting window is NCSC's 4 May 2026 blog on the AI-accelerated patch wave, which is materially relevant to retailers with extensive Citrix, Ivanti and PAN-OS exposure.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the Scattered Spider / DragonForce affiliate cluster will continue to target UK retail support operations through helpdesk social engineering and identity-provider compromise over the next reporting cycle. The April 2026 leak-site picture (DragonForce 63 victims, third place globally) confirms sustained operational tempo. (HIGH confidence)
- It is likely that retail point-of-sale and e-commerce platforms operating shared payment / loyalty SaaS will continue to be attractive Cl0p / ShinyHunters data-extortion targets, with the MOVEit Automation CVE-2026-4670 active-exploitation reporting realigning the operator signature with the vertical's trust-platform exposure. (MEDIUM-HIGH confidence)
- It is likely that the operational and regulatory cost of the M&S / Co-op campaign (£270m–£440m, ICO engagement) will continue to drive significant retail-sector defensive investment over the next 12 months, particularly in identity controls and helpdesk procedure. (HIGH confidence)
- It is likely that the AI-accelerated patch-wave dynamic flagged by NCSC on 4 May 2026 will produce at least one nationally-significant retail exploitation event within the next two reporting cycles, with Citrix NetScaler, Ivanti EPMM and PAN-OS User-ID portal exposure the highest-leverage gating factors. (MEDIUM confidence)
- There is a realistic possibility that follow-on attacks against North-American grocery and convenience retailers (UNFI carry-forward) will continue to provide template tradecraft for adjacent UK affiliates throughout 2026. (MEDIUM confidence)
2. Sector threat landscape
Retail remains a structurally attractive target class. The combination of high-volume payment-card flow, dispersed point-of-sale estates, complex outsourced helpdesk dependencies, and intense seasonal trading windows that disincentivise patch-wave responses continues to elevate the sector's exposure. The M&S, Co-op and Harrods incidents of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates between £270m and £440m — remain the operational reference case for UK retail incident response.
The April 2026 leak-site picture (Breachsense, ransomware.live) — 772 victims claimed across 70 groups — continues to track the retail subset closely. Qilin (103 April postings, 445 year-to-date) is the leading single operator; TheGentlemen (82) has displaced Akira (69) into second place; DragonForce (63) holds third. The Scattered Spider / DragonForce affiliate cluster continues to be the dominant tradecraft-template for UK retail attacks, with helpdesk social-engineering, MFA fatigue, and identity-provider compromise (Okta / Azure AD) the canonical access pattern.
Edge-appliance and identity-provider exposure are the two dominant gating factors for the vertical. The Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055, CVE-2026-4368), the Ivanti EPMM CVE-2026-6973 (KEV-listed 1 May 2026, FCEB deadline 10 May) and the Palo Alto PAN-OS User-ID portal CVE-2026-0300 (KEV-listed 6 May 2026, FCEB deadline 27 May) are immediately operationally relevant; the MOVEit Automation CVE-2026-4670 active-exploitation reporting matters for any retailer running automated payment / loyalty / supplier file transfer.
Geopolitical pressure is sub-dominant in retail compared with criminal activity, but ScarCruft's gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the wider pattern of state-aligned actors using third-party software supply chains as a delivery vector — a pattern of acute concern in retail, where loyalty-platform and payment-orchestration software are tightly concentrated across a small number of vendors.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra
- Suspected Origin: Western (UK / US, English-speaking)
- Suspected Sponsor: Organised criminal — affiliate of multiple RaaS
- Primary Motivation: Financial — ransomware, data theft, extortion
- Sector Targeting: Retail, hospitality, financial services, telecoms, BPO
- Geographic Focus: Global; high-tempo UK and North American operations
- Signature TTPs: SIM-swap and helpdesk social engineering; MFA fatigue; abuse of identity providers (Okta, Azure AD); rapid pivot to cloud admin planes; DragonForce ransomware payload
- Tooling / Malware Families: Living-off-the-land; commercial RMM tooling; DragonForce ransomware payload
- Recent Activity: 63 leak-site postings in April 2026 — third-place global ranking; cluster tradecraft from M&S / Co-op continues to template UK retail attacks
- Assessed Threat to Vertical: HIGH — helpdesk social-engineering vector remains poorly mitigated in many UK retail support operations
- Analytic Confidence: HIGH
Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Retail, healthcare, financial services, professional services
- Geographic Focus: Global; sustained UK activity
- Signature TTPs: Stolen / brute-forced credential access; double extortion; fast time-to-encrypt
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptors
- Recent Activity: 103 April 2026 leak-site postings — fourth consecutive month leading
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
TheGentlemen
- Aliases: —
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware
- Sector Targeting: Retail, manufacturing, professional services
- Geographic Focus: Global; growing UK and EU activity
- Signature TTPs: Edge-appliance and stolen-credential initial access; rapid lateral movement; double-extortion
- Tooling / Malware Families: Custom encryptor; LOLBins
- Recent Activity: 82 leak-site postings in April 2026 — second-place global ranking
- Assessed Threat to Vertical: HIGH — rising tempo and confirmed retail-aligned victimology
- Analytic Confidence: MEDIUM-HIGH
Cl0p / ShinyHunters / WorldLeaks cluster
- Aliases: TA505 (Cl0p)
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal
- Primary Motivation: Financial — pure data extortion
- Sector Targeting: Retail, financial services, healthcare — file-transfer and SaaS-platform-dependent verticals
- Geographic Focus: Global
- Signature TTPs: Mass-exploitation of file-transfer / SaaS platform CVEs; pure data extortion without encryption; coordinated leak-site posting
- Tooling / Malware Families: Custom web shells; Truebot loader
- Recent Activity: MOVEit Automation CVE-2026-4670 active-exploitation reporting realigns operator signature with retail trust platforms
- Assessed Threat to Vertical: MEDIUM-HIGH — disproportionate impact-per-campaign for retailers with shared payment / loyalty SaaS
- Analytic Confidence: MEDIUM-HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1566.004 | Spearphishing Voice | Sustained helpdesk social-engineering tradecraft templated on the M&S / Co-op campaign — primary access vector for the Scattered Spider / DragonForce cluster. | H |
| Initial Access | T1133 | External Remote Services | Citrix NetScaler / Ivanti EPMM / PAN-OS additions to KEV expose retail edge appliances; extensive head-office and store-network remote-access surface. | H |
| Initial Access | T1190 | Exploit Public-Facing Application | MOVEit Automation CVE-2026-4670 and Weaver E-Cology CVE-2026-22679 add unauthenticated RCE surfaces to retail trust platforms and supplier portals. | H |
| Initial Access | T1199 | Trusted Relationship | Cl0p / ShinyHunters cluster continues to favour shared SaaS / loyalty platform exploitation for mass-victim impact. | H |
| Privilege Escalation | T1098 | Account Manipulation | Identity-provider compromise (Okta, Azure AD) following helpdesk social-engineering — the canonical post-access pattern for the cluster. | H |
| Lateral Movement | T1021.007 | Remote Services: Cloud Services | Identity-provider abuse pivots to cloud-admin plane — sector-typical for the Scattered Spider cluster. | M |
| Impact | T1486 | Data Encrypted for Impact | DragonForce, Qilin, TheGentlemen affiliates continue to deploy encryptors against retail at scale. | H |
| Impact | T1565.002 | Data Manipulation: Transmitted Data | PoS estate / payment-orchestration manipulation as a secondary impact vector — relevant for retailers with bespoke checkout integrations. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| May 2026 | Multiple retail leak-site listings (global) | Qilin, TheGentlemen, DragonForce, Cl0p | Retail subset of the 772 April leak-site victims; sustained Q1–Q2 2026 baseline | Ransomware.live; Breachsense |
| May 2026 | Vulnerability patch wave (sector-wide) | Multiple | NCSC 4 May 2026 blog warns AI-accelerated vulnerability discovery is shrinking time-to-weaponisation | NCSC; CISA |
| Apr 2026 | UK retailers (M&S, Co-op, Harrods) — adjacent reporting | Scattered Spider / DragonForce | Continued reputational and supply-chain spillover; vendor-diligence questionnaires recirculating across UK retail; £270m–£440m reference cost band stands | Computer Weekly; ICO |
| Recent | United Natural Foods Inc. (UNFI, US) | Affiliate-cluster (carry-forward) | Confirmed cyber incident in the M&S / Co-op follow-on wave; relevant template tradecraft for UK grocery operators | Public reporting |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline 10 May; rotate admin sessions |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation | 9.8 | Pending | Yes | Patch; audit MFT operator authentication on retail supplier / loyalty estates |
| CVE-2026-22679 | Weaver E-Cology | 9.8 | — | Yes | Patch; restrict OA platform to internal networks |
| CVE-2026-41940 | WebPros cPanel / WP Squared / WHM | 9.8 | — | Yes | Patch; audit panel admin auth events on hosted-website and brand-microsite estates |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 87[.]103[.]126[.]54 | 30 Apr 2026 | H | SSH brute-force — Vodafone PT (AS12353); IP Insights threat 100/critical, 6 active blacklists |
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 6 active blacklists |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298); cross-tenant scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net); 7 active blacklists |
| ASN | AS200651 | Ongoing | H | FlokiNET — 110/132 known IPs blacklisted; bulletproof-style hosting consistently observed in retail-themed phishing |
| Pattern | Helpdesk voice social-engineering against outsourced retail support BPO | Ongoing | H | Templated on M&S / Co-op campaign; community-shared indicator sets via RH-ISAC |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Helpdesk social-engineering against outsourced retail support BPO leading to MFA-bypass and identity-provider compromise | H | H | CRITICAL |
| Ransomware deployment via DragonForce / Qilin against ESXi or PoS estate | M | H | HIGH |
| Pure data extortion via shared payment / loyalty SaaS platform compromise | M | H | HIGH |
| AI-assisted phishing of head-office and procurement inboxes leading to BEC and supplier-payment fraud | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on two concurrent themes. First, identity-provider abuse — phishing-resistant MFA bypass, MFA-fatigue, and Okta / Azure AD configuration-drift telemetry, with explicit alerting on first-seen IP geolocation for privileged accounts and on helpdesk-mediated credential resets. Second, edge-appliance exploitation telemetry: Citrix NetScaler, Ivanti EPMM and PAN-OS User-ID portal access correlated against published indicator-of-compromise sets. The Retail and Hospitality ISAC remains the single highest-value source for retail-specific helpdesk-tradecraft indicators.
Defend
Patch posture and helpdesk procedure are the two highest-leverage defensive priorities. The Ivanti EPMM, PAN-OS, NetScaler, MOVEit Automation, Weaver E-Cology and cPanel patch-wave should be circulated to all retail clients with edge-appliance or hosted-platform exposure. Helpdesk procedure should be reviewed against the M&S / Co-op operational lessons: voice authentication should never permit credential reset on its own, callback-to-known-number protocols should be standard for any privileged identity change, and identity-provider configuration changes should require multi-person authorisation. ISO/IEC 27001 Annex A 5.16, 5.17 and 8.5 are the relevant references; PCI-DSS 4.0 sections 8 and 12 remain authoritative for any retailer in cardholder-data scope.
Disrupt
Disruption priorities are concentrated in three areas. First, indicator sharing within the Retail and Hospitality ISAC and CiSP, particularly the helpdesk social-engineering tradecraft that templated on the M&S / Co-op campaign. Second, takedown coordination on phishing infrastructure attributable to AS200651 (FlokiNET), particularly retail-themed loyalty-program impersonation kits. Third, tabletop exercise activity covering the helpdesk social-engineering scenario at outsourced support BPO scope.
10. Forward outlook
It is highly likely that the AI-driven patch-wave dynamic will continue to dominate the operational picture for the next reporting cycle, with retail-sector Citrix and Ivanti exposure the highest-leverage gating factor. It is likely that helpdesk social-engineering tradecraft templated on the M&S / Co-op campaign will continue to be replicated against UK retail support operations, particularly during the May-bank-holiday and early-summer trading windows.
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 against a UK retailer; emergence of a new affiliate cluster with explicit retail-sector victimology distinct from the Scattered Spider / DragonForce template; or a material change in the Cl0p / ShinyHunters operational tempo against retail trust platforms.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Preparing for a vulnerability patch wave (4 May 2026 blog) | NCSC | A2 |
| 2 | NCSC Annual Review 2025 – ransomware and nationally significant incidents | NCSC | A1 |
| 3 | UK Cyber Security Breaches Survey 2025/2026 (DSIT) | GOV.UK | A1 |
| 4 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 5 | CISA Alert – Ivanti EPMM CVE-2026-6973 added to KEV (1 May 2026) | CISA | A1 |
| 6 | CISA Alert – Palo Alto PAN-OS CVE-2026-0300 added to KEV (6 May 2026) | CISA | A1 |
| 7 | Breachsense – April 2026 Ransomware Report (772 victims, 70 groups) | Breachsense | B2 |
| 8 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 9 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
| 11 | Computer Weekly – M&S, Co-op attacks a 'Category 2 cyber hurricane' | Computer Weekly | B2 |
| 12 | BlackFog – Marks & Spencer Breach: How a Ransomware Attack Crippled a UK Retail Giant | BlackFog | C2 |
| 13 | BleepingComputer – Marks & Spencer breach linked to Scattered Spider ransomware attack | BleepingComputer | C2 |
| 14 | Eye Security – Retail Giants Breached: M&S, Harrods & UNFI | Eye Security | C2 |
| 15 | Infosecurity Magazine – How the UK Retail Sector Responded to the Scattered Spider Hack Wave | Infosecurity Magazine | C2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the retail threat picture continued to be defined by the aftermath and direct lineage of the M&S and Co-op cyber attacks attributable to the Scattered Spider / DragonForce affiliate cluster.