Retail threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the retail threat picture continued to be defined by the aftermath and direct lineage of the M&S and Co-op cyber attacks attributable to the Scattered Spider / DragonForce affiliate cluster.
- Reference: TI-2026-0517-004 (public edition)
- Sector: Retail
- Reporting period: 11–17 May 2026
- Issued: 17 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
During the reporting period 11 May 2026 – 17 May 2026 the retail threat picture continued to be defined by the aftermath and direct lineage of the M&S and Co-op cyber attacks attributable to the Scattered Spider / DragonForce affiliate cluster. The UK Cyber Monitoring Centre Category 2 cyber hurricane rating (combined cost envelope £270m–£440m) has now become the operational reference case the sector is planning against. M&S has publicly projected $400m / £300m of profit impact from the attack. The Retail and Hospitality ISAC has continued to circulate sector-tailored guidance on helpdesk social-engineering, MFA fatigue, identity-provider abuse and living-off-the-land tradecraft. The 14 May addition of CVE-2026-20182 (Cisco Catalyst SD-WAN) to the CISA KEV catalogue under Emergency Directive 26-03 is directly relevant to multi-store and distribution-centre estates across UK retail.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the Scattered Spider / DragonForce affiliate cluster will continue to drive the majority of material risk to the UK retail vertical over the next reporting cycle. The M&S / Co-op pattern (Category 2 cyber hurricane, £270m–£440m combined cost) provides a replicable playbook and tooling stack that English-speaking affiliates are continuing to exercise (HIGH confidence).
- It is likely that CISA Emergency Directive 26-03 (Cisco SD-WAN, CVE-2026-20182) will produce at least one publicly-disclosed UK retail multi-store or distribution-centre exploitation event within the next two reporting cycles, given the prevalence of Cisco SD-WAN in retail WAN architectures (HIGH confidence).
- It is likely that consumer-data extortion (loyalty-scheme records, customer PII, loyalty-scheme transaction histories) will continue to feature in DragonForce-affiliate campaigns; the Co-op precedent (6.5m member records accessed) is the structural reference case (HIGH confidence).
- There is a realistic possibility of a UK retailer being targeted by an opportunistic ransomware operator attempting to exploit the post-M&S patch-and-harden window — operators monitor sector cyber-spending news and frequently target operations during transition periods (MEDIUM confidence).
2. Sector threat landscape
The UK retail sector continues to absorb the operational and financial lessons of the spring 2025 Scattered Spider / DragonForce campaign that struck M&S, Co-op and Harrods. The UK Cyber Monitoring Centre Category 2 cyber hurricane rating, awarded after the launch of its hurricane-scale rating system, places the combined cost envelope at £270m–£440m; M&S has publicly projected a £300m / $400m profit impact from the incident, with system-disruption and customer-data-impact tails running through 2025 and into early 2026. The English-speaking affiliate cluster remains the most operationally consequential threat actor against UK retail, and the playbook — helpdesk social-engineering, MFA fatigue, identity-provider abuse, rapid pivot to cloud and SaaS — is now well-documented in public reporting and within the Retail and Hospitality ISAC trust group.
The 14 May 2026 addition of CVE-2026-20182 (Cisco Catalyst SD-WAN Controller authentication bypass) to the CISA KEV catalogue under Emergency Directive 26-03 is materially relevant to UK retail. Cisco SD-WAN is widely deployed in multi-store WAN architectures connecting branch tills, in-store networks and distribution-centre estates back to corporate. Authentication-bypass on the SD-WAN controller plane places retailer-wide WAN trust in scope of a single CVE. Ivanti EPMM CVE-2026-6973 (active exploitation, FCEB deadline 10 May passed) applies to retailers using EPMM for managed mobile and ruggedised-device fleet management. Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055 / CVE-2026-4368) and Palo Alto PAN-OS User-ID Portal CVE-2026-0300 remain the standing edge-appliance risk set.
Geopolitical pressure is sub-dominant in retail compared with criminal activity, but ScarCruft's gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the wider pattern of state-aligned actors using third-party software supply chains as a delivery vector — a pattern of acute concern in retail, where loyalty-platform and payment-orchestration software are tightly concentrated across a small number of vendors.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Threat Actor Profile — Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra
- Suspected Origin: Western (UK / US, English-speaking)
- Suspected Sponsor: Organised criminal — affiliate of multiple RaaS
- Primary Motivation: Financial — ransomware, data theft, extortion
- Sector Targeting: Retail, hospitality, financial services, telecoms, BPO
- Geographic Focus: Global; high-tempo UK and North American operations
- Signature TTPs: SIM-swap and helpdesk social engineering; MFA fatigue; identity-provider abuse (Okta, Entra ID); rapid pivot to cloud and SaaS; living-off-the-land
- Tooling / Malware Families: Living-off-the-land; commercial RMM tooling; DragonForce ransomware payload
- Recent Activity: M&S / Co-op / Harrods campaign rated Category 2 cyber hurricane by UK Cyber Monitoring Centre, combined cost £270m–£440m; M&S publicly projecting £300m / $400m profit impact
- Assessed Threat to Vertical: HIGH — proven UK-vertical victimology, helpdesk social-engineering vector poorly mitigated
- Analytic Confidence: HIGH
Threat Actor Profile — Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Retail, financial services, healthcare, professional services
- Geographic Focus: Global
- Signature TTPs: Initial access via stolen / brute-forced credentials and edge-appliance exploitation; double-extortion model
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptor variants
- Recent Activity: 338 Q1 2026 leak-site postings (Check Point Research) — third consecutive quarter as global leader
- Assessed Threat to Vertical: HIGH — opportunistic targeting of UK retail estates post-patch window
- Analytic Confidence: HIGH
Threat Actor Profile — Akira
- Aliases: Akira ransomware
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Retail, manufacturing, professional services
- Geographic Focus: Global
- Signature TTPs: Initial access via stolen credentials and edge-appliance exploitation; rapid lateral movement; double-extortion
- Tooling / Malware Families: Akira encryptor; LOLBins
- Recent Activity: $244m in total proceeds reported; 34 percent share of IR engagements (vendor IR retrospectives); sector selection optimised for ransom-pressure response
- Assessed Threat to Vertical: HIGH — sustained tempo and retail-vertical relevance
- Analytic Confidence: HIGH
Threat Actor Profile — Cl0p
- Aliases: TA505 affiliate
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal
- Primary Motivation: Financial — pure data extortion
- Sector Targeting: Any vertical with exposed managed file-transfer or SaaS platforms
- Geographic Focus: Global
- Signature TTPs: Mass-exploitation of zero-day / n-day in trusted file-transfer products (MOVEit-pattern); pure data extortion
- Tooling / Malware Families: Custom web shells; Truebot loader; Cl0p leak portal
- Recent Activity: Progress MOVEit Automation CVE-2026-4670 active exploitation continues; relevance to retailer MFT deployments for supplier and EDI document exchange
- Assessed Threat to Vertical: MEDIUM-HIGH — applicable to retailers operating MFT for supplier / EDI integration
- Analytic Confidence: HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts | Scattered Spider / DragonForce affiliate cluster compromise of Okta and Entra ID admin roles via helpdesk social-engineering — M&S / Co-op pattern, replicable against UK retail helpdesk operations. | H |
| Initial Access | T1190 | Exploit Public-Facing Application | Cisco Catalyst SD-WAN CVE-2026-20182 (KEV 14 May, ED 26-03) and Ivanti EPMM CVE-2026-6973 (active exploitation) place authentication-bypass and pre-auth RCE on retail edge surfaces. | H |
| Initial Access | T1133 | External Remote Services | Citrix NetScaler ADC / Gateway, Palo Alto PAN-OS User-ID Portal expose retail multi-site remote-access surfaces. | H |
| Defence Evasion | T1556.006 | Modify Authentication Process: MFA Request Generation | Scattered Spider MFA-fatigue tradecraft continues against UK retail outsourced-IT helpdesks. | H |
| Collection | T1530 | Data from Cloud Storage Object | Anomalous bulk-export from customer-data and loyalty-scheme platforms — Co-op-pattern precursor (6.5m member records accessed). | M |
| Impact | T1486 | Data Encrypted for Impact | Scattered Spider / DragonForce, Qilin, Akira affiliates deploying encryptors against retail estates. | H |
| Impact | T1657 | Financial Theft | Sustained card-not-present fraud and BEC tradecraft against retailer finance teams. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Ongoing | M&S / Co-op / Harrods cyber attack tail | Scattered Spider / DragonForce affiliate cluster | UK Cyber Monitoring Centre Category 2 cyber hurricane rating (combined £270m–£440m); M&S publicly projecting £300m / $400m profit impact; sector reference case | UK Cyber Monitoring Centre; M&S investor disclosure |
| 14 May 2026 | Cisco Catalyst SD-WAN exploitation surface (sector-wide) | Multiple — CISA ED 26-03 | CVE-2026-20182 authentication-bypass added to KEV; ED 26-03 hunt-and-hardening direction; UK multi-store and distribution-centre estates with Cisco SD-WAN immediately exposed | CISA; NCSC |
| May 2026 | Retail leak-site listings (global) | Qilin, Akira, DragonForce, Lynx | Retail subset of Q1 2026 leak-site total (2,122 victims, 91 active DLS, Check Point Research) | Check Point Research; Ransomware.live |
| Carry-forward | Co-op consumer-data exfiltration (6.5m member records) | Scattered Spider / DragonForce | Demonstrative of consumer-data extortion vector; loyalty-scheme records as primary target class | Co-op public disclosure; press |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller (authentication bypass) | 9.8 | Yes (14 May) | Yes | Patch immediately; align with CISA ED 26-03 / Supplemental Direction; hunt for compromise; FCEB hardening guidance applies |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline now passed (10 May); rotate admin sessions; review MDM admin auth logs |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch; rotate session keys; hunt for indicators |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation (< 2025.1.5 / 2025.0.9 / 2024.1.8) | 9.8 | Yes | Yes (low-complexity) | Patch; audit MFT operator and admin authentication |
| CVE-2026-8043 | Ivanti Xtraction (external control of file name, RCE) | 9.6 | — | Pending | Patch; restrict reporting console exposure |
| CVE-2026-44277 | Fortinet FortiAuthenticator (improper access control) | 9.1 | — | Pending | Patch; restrict management plane exposure |
| CVE-2026-26083 | Fortinet FortiSandbox (missing authorisation, RCE) | 9.1 | — | Pending | Patch; restrict sandbox API exposure |
| CVE-2026-34260 | SAP S/4HANA Enterprise Search for ABAP | 9.6 | — | Pending | Patch; restrict access to enterprise search endpoints |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force pattern — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 7 active blacklists; carry-forward IOC |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298) — IP Insights threat 100/critical; mass scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical |
| ASN | AS200651 | Ongoing | H | FlokiNET — 112/134 known IPs blacklisted; risk 100/critical; risk breakdown low 19 / med 3 / high 31 / critical 81; bulletproof hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Scattered Spider / DragonForce helpdesk social-engineering campaign against UK retail helpdesk operations | H | H | CRITICAL |
| Cisco SD-WAN exploitation chain (CVE-2026-20182, ED 26-03) against multi-store / distribution-centre estate | H | H | CRITICAL |
| Consumer-data extortion against loyalty-scheme or customer-data platform (Co-op pattern) | H | H | CRITICAL |
| Pure data extortion via supplier-EDI / MFT compromise (Cl0p / MOVEit pattern) | M | M | MEDIUM |
| Card-not-present fraud and BEC against retailer finance / treasury teams | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on three concurrent threads. First, identity-provider helpdesk social-engineering: detect MFA fatigue, SIM-swap precursors and risky-sign-in patterns against Okta and Entra ID — Scattered Spider / DragonForce affiliate tradecraft remains the dominant threat to UK retail support operations. Second, edge-appliance exploitation telemetry on Citrix NetScaler, Ivanti EPMM and Palo Alto PAN-OS. Third, customer-data-platform and loyalty-scheme platform telemetry — anomalous bulk-export, anomalous admin-role assignment, and large-scale member-record query patterns are the precursor hunt signatures for Co-op-pattern consumer-data extortion.
Defend
Patch posture is the single most operationally consequential defensive action for the next reporting cycle. CVE-2026-20182 (Cisco SD-WAN, ED 26-03), CVE-2026-6973 (Ivanti EPMM), CVE-2026-0300 (PAN-OS), CVE-2026-3055 / CVE-2026-4368 (NetScaler) and CVE-2026-4670 (MOVEit Automation) are the prioritised set. Identity controls deserve particular focus on outsourced helpdesk operations: enforce risk-based MFA on privileged accounts, prohibit voice-channel password resets and PIN resets, deploy hardware tokens for IT-admin roles, and audit Okta / Entra ID admin-role assignments. Where retailers operate customer-portal authentication via third-party identity providers, request written confirmation of provider posture against the same set.
Disrupt
Disruption priorities for the next reporting cycle are concentrated in three areas. First, indicator sharing within the Retail and Hospitality ISAC and CiSP — the IP Insights enrichment service should be used to support prompt indicator submission. Second, takedown coordination on phishing infrastructure spoofing UK retailer brands and customer-loyalty programmes. Third, intelligence exchange with RH-ISAC peers around Scattered Spider / DragonForce affiliate TTP signatures observed against UK helpdesk operations.
10. Forward outlook
It is highly likely that Scattered Spider / DragonForce affiliate tradecraft will continue to be replicated against UK retail estates over the next reporting cycle. It is likely that CISA ED 26-03 (Cisco SD-WAN) will produce at least one publicly-disclosed UK retail multi-store exploitation event within the next two reporting cycles. It is likely that consumer-data extortion against loyalty-scheme and customer-data platforms will continue to feature in active campaigns. There is a realistic possibility of an opportunistic ransomware operator targeting a UK retailer during the post-M&S patch-and-harden window.
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-20182 against a UK multi-store retailer (raises the vertical-risk to CRITICAL); a new helpdesk-social-engineering TTP variant observed in RH-ISAC reporting that bypasses current mitigations; novel UK retail-victim loyalty-platform compromise; ransomware operator publicly claiming attribution against a UK retailer during the post-M&S window.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Reports & Advisories (rolling) | NCSC | A1 |
| 2 | NCSC – Cisco Catalyst SD-WAN advisory and ED 26-03 alignment (May 2026) | NCSC / CISA | A1 |
| 3 | NCSC – Citrix NetScaler ADC / Gateway CVE-2026-3055 / CVE-2026-4368 | NCSC | A1 |
| 4 | NCSC – F5 BIG-IP Access Policy Manager unauthenticated RCE advisory | NCSC | A1 |
| 5 | NCSC – Middle East cyber posture review guidance | NCSC | A1 |
| 6 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 7 | CISA Alert – CVE-2026-20182 Cisco Catalyst SD-WAN Controller added to KEV (14 May 2026) | CISA | A1 |
| 8 | CISA Emergency Directive 26-03 – Mitigate Cisco SD-WAN Vulnerabilities | CISA | A1 |
| 9 | CISA Alert – Ivanti EPMM CVE-2026-6973 active exploitation | CISA | A1 |
| 10 | Check Point Research – State of Ransomware Q1 2026 | Check Point Research | B2 |
| 11 | Breachsense – April / Q1 2026 ransomware tracking | Breachsense | B2 |
| 12 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 13 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…