SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Retail threat intelligence report — 16–22 May 2026

The reporting cycle has been shaped by sustained Scattered Spider / DragonForce cartel activity following the M&S, Co-op and Harrods incidents of April–May 2025, continued exploitation of edge-appliance CVEs…

  • Reference: TI-2026-0522-004 (public edition)
  • Sector: Retail
  • Reporting period: 16–22 May 2026
  • Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report assesses the threat landscape affecting the Retail vertical for the period 16 May 2026 to 22 May 2026. The reporting cycle has been shaped by sustained Scattered Spider / DragonForce cartel activity following the M&S, Co-op and Harrods incidents of April–May 2025, continued exploitation of edge-appliance CVEs, and the consolidation of the IAB-into-RaaS economic model that materially extended the 2025 retail attack wave into 2026.

Key Judgements

The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  • It is highly likely that the Scattered Spider / DragonForce alliance will continue to produce material UK retail incidents through 2026, with the IT helpdesk and BPO supply-chain remaining the dominant entry vector. (HIGH confidence)
  • It is likely that at least one further UK or EU retailer of comparable scale to M&S will publicly disclose a disruptive ransomware event before the end of Q3 2026. (MEDIUM confidence)
  • It is highly likely that double-extortion will remain the dominant business model for retail-targeted ransomware, with operational disruption (warehouse stoppage, EPOS / payments downtime, online-order suspension) being the principal lever rather than data theft alone. (HIGH confidence)
  • It is likely that the third-party-IT-supplier weakness exposed by the M&S incident (where the TCS-operated helpdesk was the entry point) will continue to be exploited against UK retailers using similarly-structured outsourcing arrangements. (MEDIUM confidence)
  • There is a realistic possibility that the 2026 Christmas-trading window will be specifically targeted by cartel-aligned operators for maximum retailer ransom leverage, mirroring the operational pattern observed in 2024 and 2025. (MEDIUM confidence)

2. Sector threat landscape

The retail vertical's threat picture remains dominated by the consequences of the April–May 2025 Scattered Spider / DragonForce campaign against UK retailers. M&S sustained a multi-week operational disruption (online-order suspension, contactless-payment failures, warehouse staff stood down, an estimated £30m immediate profit loss plus £15m/week of continued lost profit until restoration, and a market-cap impact at one point of approximately £750 million). Co-op and Harrods sustained adjacent incidents within days. The entry vector at M&S was via the TCS-operated outsourced helpdesk — a model still in use across multiple UK retailers, which sustains the credibility of the threat into 2026.

Operationally, the alliance has matured into a coherent multi-strand operation. Scattered Spider as the IAB front-end performs the social-engineering against helpdesks and identity providers; DragonForce / LockBit / Qilin provide the post-compromise ransomware payload and the leak-site for double-extortion; the cartel-style structure means that an attack presents either with cartel-affiliated cosmetic features or as bespoke-looking activity, depending on which affiliate is running the operation. The defensive challenge is that the social-engineering signature is robust but operationally undetectable until the post-call lateral movement begins.

Beyond the cartel cluster, retail remains a recurring target for Akira (operational tempo and ESXi-aware payload), Qilin (sustained leak-site cadence including retail victims), and TheGentlemen (rapid affiliate growth, 424 named victims by 18 May 2026). Cl0p exposure for retail is reduced compared to 2023 — managed-file-transfer-anchored extortion is now less operationally relevant to the retail estate — but the residual victim disclosures from earlier campaigns continue to surface.

From a vulnerability perspective, the May 2026 vulnerability picture for retail is dominated by Cisco Catalyst SD-WAN (CVE-2026-20182, active ITW exploitation by UAT-8616), Ivanti EPMM (CVE-2026-6973, in CISA KEV from 7 May 2026), Trend Micro Apex One (CVE-2026-34926, added to CISA KEV on 21 May 2026) and Citrix NetScaler (CVE-2026-3055 / 4368). Retail estates that lean on any of these as the perimeter or remote-access stack should treat the next reporting cycle as the operational window for emergency patching.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.

THREAT ACTOR PROFILE — Scattered Spider / DragonForce / LockBit / Qilin cartel
AliasesUNC3944, Octo Tempest, Muddled Libra, 0ktapus (Scattered Spider front-end); partner RaaS payloads
Suspected OriginEnglish-speaking criminal community (front-end); Russian-speaking criminal milieu (partner ransomware)
Suspected SponsorCriminal cartel
Primary MotivationFinancial extortion via double-extortion ransomware
Sector FocusRetail, hospitality, banking BPO, telecommunications
ToolingVoice-phishing of IT helpdesks, SIM-swap, MFA push-bombing, OAuth consent-phishing, AnyDesk / TeamViewer / ScreenConnect for hands-on-keyboard, partner ransomware payload (DragonForce / LockBit / Qilin variants)
TTP HighlightsOutsourced helpdesk impersonation; identity-provider admin targeting; rapid ESXi-tier encryption; aggressive double-extortion
Reporting Cycle ActivityContinued voice-phishing campaigns against UK BPO partners; tradecraft consistent with prior M&S / Co-op activity pattern; no UK retail victim publicly confirmed this week
ConfidenceHIGH
AdmiraltyA2
ReferenceRefs 1, 2, 3
THREAT ACTOR PROFILE — Qilin (retail subset)
AliasesAgenda, Qilin.B
Suspected OriginRussia
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial extortion / data theft
Sector FocusCross-sector — sustained retail-vertical targeting
ToolingQilin.B encryptor (ESXi-aware), SystemBC, AnyDesk, Cobalt Strike, rclone
TTP HighlightsIAB credential purchase; ESXi-aware encryption against retailer virtualised estates; double-extortion
Reporting Cycle Activity338 victims in Q1 2026; sustained leak-site cadence through the reporting period
ConfidenceHIGH
AdmiraltyB2
ReferenceRefs 4, 5
THREAT ACTOR PROFILE — Akira (retail subset)
Aliases
Suspected OriginRussian-speaking criminal milieu
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial extortion
Sector FocusManufacturing (352), business services (313), construction (132), technology (129), consumer services (96 — retail-relevant)
ToolingAkira encryptor for Windows / Linux / ESXi; AnyDesk; Cobalt Strike; rclone
TTP HighlightsHigh operational tempo; ESXi-aware payload; aggressive leak-site cadence
Reporting Cycle Activity30+ victims posted in one day on 20 May 2026; retail-relevant victims included in the consumer-services subset
ConfidenceHIGH
AdmiraltyA2
ReferenceRefs 7, 11
THREAT ACTOR PROFILE — TheGentlemen
Aliases
Suspected OriginUnattributed Russian-speaking milieu
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial extortion
Sector FocusCross-sector with retail / hospitality represented
ToolingGo-based encryptor for Windows, Linux, BSD, NAS; SystemBC C2
TTP HighlightsRapid affiliate growth; multi-platform encryptor; aggressive leak-site cadence
Reporting Cycle Activity424 named victims on leak-site by 18 May 2026
ConfidenceMEDIUM-HIGH
AdmiraltyB2
ReferenceRef 6

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1566.002Spear-phishing LinkVoice-phishing of outsourced IT helpdesks with pre-built identity-verification scripts.HIGH
Initial AccessT1078.004Valid Accounts: CloudReuse of IAB-purchased VPN / M365 credentials into retailer corporate tenants.HIGH
Initial AccessT1190Exploit Public-Facing ApplicationExploitation of edge appliances (Cisco SD-WAN, Citrix NetScaler, Ivanti EPMM) against retailer perimeter estates.HIGH
ExecutionT1059.001PowerShellEncoded loaders for ransomware staging.MEDIUM
Credential AccessT1621Multi-Factor Authentication Request Generation (MFA Bombing)Push-bombing of MFA prompts against retailer admin accounts following helpdesk reset.HIGH
Lateral MovementT1021.001Remote Services: RDPPivot into ESXi management of EPOS, WMS and online-orders infrastructure.HIGH
Defence EvasionT1562.001Impair Defences: Disable Security ToolsEDR / Apex One disable via stolen admin; CVE-2026-34926 increases this exposure.MEDIUM
ExfiltrationT1567.002Exfiltration to Cloud Storagerclone / MEGAcmd / AzCopy for staged data theft prior to encryption.HIGH
ImpactT1486Data Encrypted for ImpactDragonForce / Qilin.B / Akira ESXi-aware encryption against retailer virtualised estates.HIGH

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
Throughout periodMultiple UK retail BPO providersScattered Spider / DragonForceContinued voice-phishing of outsourced helpdesks; tradecraft consistent with M&S / Co-op pattern.Refs 1, 2
18 May 2026Foxconn (NA operations)Nitrogen ransomwareClaimed 8TB exfiltration; consumer-electronics supply-chain impact downstream of retail channel partners.Ref 12
20 May 2026Multiple Akira victimsAkira RaaS30+ victims posted in one day on leak site; retail-relevant entities in the consumer-services bracket.Ref 11
18 May 2026Multiple TheGentlemen victimsTheGentlemen RaaS424 named victims on leak-site by 18 May; retail-adjacent entities in disclosures.Ref 6
Recent prior (2025)Marks & SpencerScattered Spider / DragonForce (historic reference)Multi-week operational disruption; £30m immediate profit loss + £15m/wk; ~£750m market-cap impact at peak; TCS-operated helpdesk as entry vector. Continues to anchor 2026 risk modelling.Refs 1, 3
Recent prior (2025)Co-op and HarrodsScattered Spider / DragonForce (historic reference)Operational disruption within days of M&S incident.Ref 3

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN10.0YesActive ITW (UAT-8616)Patch immediately; review SSH keys / NETCONF activity.
CVE-2026-6973Ivanti EPMM (on-prem)7.2YesActive ITWPatch; rotate pre-Feb 2026 admin credentials.
CVE-2026-34926Trend Micro Apex One (on-prem)8.7YesActive ITWApply fix; review Apex One console exposure across the retailer Windows estate.
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler9.3 / 8.6YesActive ITWApply Citrix builds and force-rotate session keys.
CVE-2026-41091 / 45498Microsoft Defender7.8 / 6.5YesConfirmedApply May 2026 Patch Tuesday roll-up.
CVE-2026-31431Linux Kernel7.0YesActive ITWApply distribution-supplied kernel; relevant to Linux-hosted e-commerce and headless-CMS estates.
Sector-specificEPOS / payments edge gateway exposurevariesn/aRecurringAudit EPOS vendor patch posture; ensure PCI DSS scope is current; rotate EPOS service-account credentials.
Sector-specificE-commerce platform admin-credential exposurevariesn/aRecurringAudit Shopify Plus / Magento / Salesforce Commerce admin grants; enforce phishing-resistant MFA.

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.

TypeIndicatorFirst SeenConf.Notes
IP185.243.78.42Reporting periodMEDIUMBamboozle Web Services MEA FZ-LLC; business hosting; IP Insights flagged 'block'; egress-deny candidate.
Domainstore-helpdesk-portal[.]comReporting periodMEDIUMScattered Spider-style helpdesk-phishing domain pattern; add to URL filter.
Domainepos-update-cert[.]netReporting periodMEDIUMEPOS / payments-gateway impersonation pattern.
TTPMFA push-bombing against retail admin accountsRecurringHIGHConfigure number-matching MFA on Microsoft Authenticator; disable push-approve where possible.
TTPOAuth consent-phishing for M365 mailbox.read scopeReporting periodMEDIUMBlock third-party consent grants without admin review.
Hash (SHA-256)DragonForce ESXi payload variant (redacted)Reporting periodMEDIUMDeploy YARA-based detection.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.

Threat ScenarioLikelihoodImpactComposite
Ransomware compromise via outsourced IT helpdesk social engineeringHIGHHIGHCRITICAL
Edge-appliance exploitation leading to ESXi-tier encryption of retail estateMEDIUM-HIGHHIGHCRITICAL
E-commerce platform admin-credential theft and online-orders disruptionMEDIUMHIGHHIGH
Brand-reputation damage from cartel leak-site disclosureHIGHMEDIUMHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.

Detect

  • Helpdesk-impersonation telemetry: instrument the outsourced helpdesk channel for callback verification, voice-biometric or shared-secret challenge, and alert on any admin password-reset performed without secondary verification.
  • M365 identity-provider telemetry: alert on impossible-travel, new device registration on admin accounts, and OAuth consent grants from non-admin users.
  • ESXi / vSphere management-plane telemetry: alert on new SSH sessions outside the documented admin source-range; alert on vSphere admin login from previously-unseen user-agent.
  • Edge-appliance telemetry per CISA / NCSC joint guidance on Cisco SD-WAN, Ivanti EPMM and Citrix NetScaler.

Defend

  • Patch Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One, Citrix NetScaler and apply May 2026 Microsoft Patch Tuesday roll-up across the retailer estate before the next reporting cycle.
  • Tighten the outsourced-helpdesk control package — callback-via-trusted-channel for password resets, voice-biometric or shared-secret challenge for admin actions, and tabletop the helpdesk against an explicit Scattered Spider scenario before quarter close.
  • Enforce number-matching MFA on Microsoft Authenticator and remove push-approve where possible; disable SMS-based MFA on admin accounts; require FIDO2 keys for all M365 / identity-provider admin accounts.
  • Validate offline / immutable backup for the e-commerce, EPOS, payments and WMS estates against a Christmas-trading-window ransomware scenario within the next reporting cycle.

Disrupt

  • Subscribe to RH-ISAC (Retail and Hospitality ISAC) and contribute observed indicators.
  • Push indicators in Section 7 into preventive controls via the ipinsights.io TAXII 2.1 endpoint.
  • Tabletop a Christmas-trading-window ransomware scenario explicitly — the 2026 trading calendar makes this the highest-leverage operational test for the year.

10. Forward outlook

It is highly likely that further UK retail cartel-affiliated ransomware events will be publicly disclosed before end of Q3 2026. (HIGH confidence)

It is likely that the 2026 Christmas-trading window will be specifically targeted by cartel-aligned operators; preposition planning and incident-response capacity for November–December. (MEDIUM confidence)

Trigger conditions warranting forecast revision: a confirmed retail-sector exploitation of CVE-2026-20182 / CVE-2026-6973; a third UK retailer disclosing a Scattered-Spider-attributed incident in the same quarter; or a public attribution shift away from English-speaking IAB front-ends towards a new affiliate community.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.

SourceReliabilityInformationCredibility
A — Completely reliableDemonstrated repeated reliability1 — ConfirmedCorroborated by independent sources
B — Usually reliableReliable on most occasions2 — Probably trueLogical, consistent, partially corroborated
C — Fairly reliableSometimes reliable3 — Possibly trueReasonably logical, agrees with some information
D — Not usually reliableLimited prior accuracy4 — DoubtfulPossible but lacks logic or corroboration
E — UnreliableHistory of inaccuracy5 — ImprobableContradicts other reporting
F — Cannot be judgedNo basis for evaluation6 — Cannot be judgedCannot be assessed

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).

Source / TitlePublisherAdmiralty
1Inside DragonForce — M&S, Co-op, Harrods analysisInfosecurity Magazine; SophosA2
2DragonForce / Scattered Spider alliance briefingsAcronis TRU; BlackFog; sqmagazineA2
3M&S Breach — ransomware attack crippled UK retail giantBlackFog; cm-alliance.comB2
4Q1 2026 Ransomware RetrospectiveCheck Point ResearchB2
5Ransomware sector reconsolidatingIndustrial CyberB2
6TheGentlemen leak-site cadence and SystemBC C2 revelationsThe Hacker News; ransomware.liveB2
7Akira playbook 2026CybelAngel; Trend Micro SpotlightB2
8Evolving cyber threats facing UK retailHowden; Heimdal stats 2026B3
9UK Retail Cyber Attacks — Detailed Timelinecm-alliance.comB2
10CISA / NCSC-UK joint advisory on CVE-2026-20182CISA; NCSC-UK; NSA; ACSC; CCCSA1
11Akira drops 30 victims in one daySecurityWeek; The RecordA2
12Foxconn NA cyberattack (Nitrogen)Hendry Adrian Daily Recap; SecurityWeekB2
13Trend Micro Apex One ITW bulletin (CVE-2026-34926)Trend Micro; CISA KEVA2
14ipinsights.io enrichment & blocklist dataipinsights.ioB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.