Retail threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by sustained Scattered Spider / DragonForce cartel activity following the M&S, Co-op and Harrods incidents of April–May 2025, continued exploitation of edge-appliance CVEs…
- Reference: TI-2026-0522-004 (public edition)
- Sector: Retail
- Reporting period: 16–22 May 2026
- Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report assesses the threat landscape affecting the Retail vertical for the period 16 May 2026 to 22 May 2026. The reporting cycle has been shaped by sustained Scattered Spider / DragonForce cartel activity following the M&S, Co-op and Harrods incidents of April–May 2025, continued exploitation of edge-appliance CVEs, and the consolidation of the IAB-into-RaaS economic model that materially extended the 2025 retail attack wave into 2026.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the Scattered Spider / DragonForce alliance will continue to produce material UK retail incidents through 2026, with the IT helpdesk and BPO supply-chain remaining the dominant entry vector. (HIGH confidence)
- It is likely that at least one further UK or EU retailer of comparable scale to M&S will publicly disclose a disruptive ransomware event before the end of Q3 2026. (MEDIUM confidence)
- It is highly likely that double-extortion will remain the dominant business model for retail-targeted ransomware, with operational disruption (warehouse stoppage, EPOS / payments downtime, online-order suspension) being the principal lever rather than data theft alone. (HIGH confidence)
- It is likely that the third-party-IT-supplier weakness exposed by the M&S incident (where the TCS-operated helpdesk was the entry point) will continue to be exploited against UK retailers using similarly-structured outsourcing arrangements. (MEDIUM confidence)
- There is a realistic possibility that the 2026 Christmas-trading window will be specifically targeted by cartel-aligned operators for maximum retailer ransom leverage, mirroring the operational pattern observed in 2024 and 2025. (MEDIUM confidence)
2. Sector threat landscape
The retail vertical's threat picture remains dominated by the consequences of the April–May 2025 Scattered Spider / DragonForce campaign against UK retailers. M&S sustained a multi-week operational disruption (online-order suspension, contactless-payment failures, warehouse staff stood down, an estimated £30m immediate profit loss plus £15m/week of continued lost profit until restoration, and a market-cap impact at one point of approximately £750 million). Co-op and Harrods sustained adjacent incidents within days. The entry vector at M&S was via the TCS-operated outsourced helpdesk — a model still in use across multiple UK retailers, which sustains the credibility of the threat into 2026.
Operationally, the alliance has matured into a coherent multi-strand operation. Scattered Spider as the IAB front-end performs the social-engineering against helpdesks and identity providers; DragonForce / LockBit / Qilin provide the post-compromise ransomware payload and the leak-site for double-extortion; the cartel-style structure means that an attack presents either with cartel-affiliated cosmetic features or as bespoke-looking activity, depending on which affiliate is running the operation. The defensive challenge is that the social-engineering signature is robust but operationally undetectable until the post-call lateral movement begins.
Beyond the cartel cluster, retail remains a recurring target for Akira (operational tempo and ESXi-aware payload), Qilin (sustained leak-site cadence including retail victims), and TheGentlemen (rapid affiliate growth, 424 named victims by 18 May 2026). Cl0p exposure for retail is reduced compared to 2023 — managed-file-transfer-anchored extortion is now less operationally relevant to the retail estate — but the residual victim disclosures from earlier campaigns continue to surface.
From a vulnerability perspective, the May 2026 vulnerability picture for retail is dominated by Cisco Catalyst SD-WAN (CVE-2026-20182, active ITW exploitation by UAT-8616), Ivanti EPMM (CVE-2026-6973, in CISA KEV from 7 May 2026), Trend Micro Apex One (CVE-2026-34926, added to CISA KEV on 21 May 2026) and Citrix NetScaler (CVE-2026-3055 / 4368). Retail estates that lean on any of these as the perimeter or remote-access stack should treat the next reporting cycle as the operational window for emergency patching.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.
| THREAT ACTOR PROFILE — Scattered Spider / DragonForce / LockBit / Qilin cartel | |
|---|---|
| Aliases | UNC3944, Octo Tempest, Muddled Libra, 0ktapus (Scattered Spider front-end); partner RaaS payloads |
| Suspected Origin | English-speaking criminal community (front-end); Russian-speaking criminal milieu (partner ransomware) |
| Suspected Sponsor | Criminal cartel |
| Primary Motivation | Financial extortion via double-extortion ransomware |
| Sector Focus | Retail, hospitality, banking BPO, telecommunications |
| Tooling | Voice-phishing of IT helpdesks, SIM-swap, MFA push-bombing, OAuth consent-phishing, AnyDesk / TeamViewer / ScreenConnect for hands-on-keyboard, partner ransomware payload (DragonForce / LockBit / Qilin variants) |
| TTP Highlights | Outsourced helpdesk impersonation; identity-provider admin targeting; rapid ESXi-tier encryption; aggressive double-extortion |
| Reporting Cycle Activity | Continued voice-phishing campaigns against UK BPO partners; tradecraft consistent with prior M&S / Co-op activity pattern; no UK retail victim publicly confirmed this week |
| Confidence | HIGH |
| Admiralty | A2 |
| Reference | Refs 1, 2, 3 |
| THREAT ACTOR PROFILE — Qilin (retail subset) | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russia |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial extortion / data theft |
| Sector Focus | Cross-sector — sustained retail-vertical targeting |
| Tooling | Qilin.B encryptor (ESXi-aware), SystemBC, AnyDesk, Cobalt Strike, rclone |
| TTP Highlights | IAB credential purchase; ESXi-aware encryption against retailer virtualised estates; double-extortion |
| Reporting Cycle Activity | 338 victims in Q1 2026; sustained leak-site cadence through the reporting period |
| Confidence | HIGH |
| Admiralty | B2 |
| Reference | Refs 4, 5 |
| THREAT ACTOR PROFILE — Akira (retail subset) | |
|---|---|
| Aliases | — |
| Suspected Origin | Russian-speaking criminal milieu |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial extortion |
| Sector Focus | Manufacturing (352), business services (313), construction (132), technology (129), consumer services (96 — retail-relevant) |
| Tooling | Akira encryptor for Windows / Linux / ESXi; AnyDesk; Cobalt Strike; rclone |
| TTP Highlights | High operational tempo; ESXi-aware payload; aggressive leak-site cadence |
| Reporting Cycle Activity | 30+ victims posted in one day on 20 May 2026; retail-relevant victims included in the consumer-services subset |
| Confidence | HIGH |
| Admiralty | A2 |
| Reference | Refs 7, 11 |
| THREAT ACTOR PROFILE — TheGentlemen | |
|---|---|
| Aliases | — |
| Suspected Origin | Unattributed Russian-speaking milieu |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial extortion |
| Sector Focus | Cross-sector with retail / hospitality represented |
| Tooling | Go-based encryptor for Windows, Linux, BSD, NAS; SystemBC C2 |
| TTP Highlights | Rapid affiliate growth; multi-platform encryptor; aggressive leak-site cadence |
| Reporting Cycle Activity | 424 named victims on leak-site by 18 May 2026 |
| Confidence | MEDIUM-HIGH |
| Admiralty | B2 |
| Reference | Ref 6 |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1566.002 | Spear-phishing Link | Voice-phishing of outsourced IT helpdesks with pre-built identity-verification scripts. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud | Reuse of IAB-purchased VPN / M365 credentials into retailer corporate tenants. | HIGH |
| Initial Access | T1190 | Exploit Public-Facing Application | Exploitation of edge appliances (Cisco SD-WAN, Citrix NetScaler, Ivanti EPMM) against retailer perimeter estates. | HIGH |
| Execution | T1059.001 | PowerShell | Encoded loaders for ransomware staging. | MEDIUM |
| Credential Access | T1621 | Multi-Factor Authentication Request Generation (MFA Bombing) | Push-bombing of MFA prompts against retailer admin accounts following helpdesk reset. | HIGH |
| Lateral Movement | T1021.001 | Remote Services: RDP | Pivot into ESXi management of EPOS, WMS and online-orders infrastructure. | HIGH |
| Defence Evasion | T1562.001 | Impair Defences: Disable Security Tools | EDR / Apex One disable via stolen admin; CVE-2026-34926 increases this exposure. | MEDIUM |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd / AzCopy for staged data theft prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | DragonForce / Qilin.B / Akira ESXi-aware encryption against retailer virtualised estates. | HIGH |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Throughout period | Multiple UK retail BPO providers | Scattered Spider / DragonForce | Continued voice-phishing of outsourced helpdesks; tradecraft consistent with M&S / Co-op pattern. | Refs 1, 2 |
| 18 May 2026 | Foxconn (NA operations) | Nitrogen ransomware | Claimed 8TB exfiltration; consumer-electronics supply-chain impact downstream of retail channel partners. | Ref 12 |
| 20 May 2026 | Multiple Akira victims | Akira RaaS | 30+ victims posted in one day on leak site; retail-relevant entities in the consumer-services bracket. | Ref 11 |
| 18 May 2026 | Multiple TheGentlemen victims | TheGentlemen RaaS | 424 named victims on leak-site by 18 May; retail-adjacent entities in disclosures. | Ref 6 |
| Recent prior (2025) | Marks & Spencer | Scattered Spider / DragonForce (historic reference) | Multi-week operational disruption; £30m immediate profit loss + £15m/wk; ~£750m market-cap impact at peak; TCS-operated helpdesk as entry vector. Continues to anchor 2026 risk modelling. | Refs 1, 3 |
| Recent prior (2025) | Co-op and Harrods | Scattered Spider / DragonForce (historic reference) | Operational disruption within days of M&S incident. | Ref 3 |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN | 10.0 | Yes | Active ITW (UAT-8616) | Patch immediately; review SSH keys / NETCONF activity. |
| CVE-2026-6973 | Ivanti EPMM (on-prem) | 7.2 | Yes | Active ITW | Patch; rotate pre-Feb 2026 admin credentials. |
| CVE-2026-34926 | Trend Micro Apex One (on-prem) | 8.7 | Yes | Active ITW | Apply fix; review Apex One console exposure across the retailer Windows estate. |
| CVE-2026-3055 / CVE-2026-4368 | Citrix NetScaler | 9.3 / 8.6 | Yes | Active ITW | Apply Citrix builds and force-rotate session keys. |
| CVE-2026-41091 / 45498 | Microsoft Defender | 7.8 / 6.5 | Yes | Confirmed | Apply May 2026 Patch Tuesday roll-up. |
| CVE-2026-31431 | Linux Kernel | 7.0 | Yes | Active ITW | Apply distribution-supplied kernel; relevant to Linux-hosted e-commerce and headless-CMS estates. |
| Sector-specific | EPOS / payments edge gateway exposure | varies | n/a | Recurring | Audit EPOS vendor patch posture; ensure PCI DSS scope is current; rotate EPOS service-account credentials. |
| Sector-specific | E-commerce platform admin-credential exposure | varies | n/a | Recurring | Audit Shopify Plus / Magento / Salesforce Commerce admin grants; enforce phishing-resistant MFA. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IP | 185.243.78.42 | Reporting period | MEDIUM | Bamboozle Web Services MEA FZ-LLC; business hosting; IP Insights flagged 'block'; egress-deny candidate. |
| Domain | store-helpdesk-portal[.]com | Reporting period | MEDIUM | Scattered Spider-style helpdesk-phishing domain pattern; add to URL filter. |
| Domain | epos-update-cert[.]net | Reporting period | MEDIUM | EPOS / payments-gateway impersonation pattern. |
| TTP | MFA push-bombing against retail admin accounts | Recurring | HIGH | Configure number-matching MFA on Microsoft Authenticator; disable push-approve where possible. |
| TTP | OAuth consent-phishing for M365 mailbox.read scope | Reporting period | MEDIUM | Block third-party consent grants without admin review. |
| Hash (SHA-256) | DragonForce ESXi payload variant (redacted) | Reporting period | MEDIUM | Deploy YARA-based detection. |
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Ransomware compromise via outsourced IT helpdesk social engineering | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation leading to ESXi-tier encryption of retail estate | MEDIUM-HIGH | HIGH | CRITICAL |
| E-commerce platform admin-credential theft and online-orders disruption | MEDIUM | HIGH | HIGH |
| Brand-reputation damage from cartel leak-site disclosure | HIGH | MEDIUM | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.
Detect
- Helpdesk-impersonation telemetry: instrument the outsourced helpdesk channel for callback verification, voice-biometric or shared-secret challenge, and alert on any admin password-reset performed without secondary verification.
- M365 identity-provider telemetry: alert on impossible-travel, new device registration on admin accounts, and OAuth consent grants from non-admin users.
- ESXi / vSphere management-plane telemetry: alert on new SSH sessions outside the documented admin source-range; alert on vSphere admin login from previously-unseen user-agent.
- Edge-appliance telemetry per CISA / NCSC joint guidance on Cisco SD-WAN, Ivanti EPMM and Citrix NetScaler.
Defend
- Patch Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One, Citrix NetScaler and apply May 2026 Microsoft Patch Tuesday roll-up across the retailer estate before the next reporting cycle.
- Tighten the outsourced-helpdesk control package — callback-via-trusted-channel for password resets, voice-biometric or shared-secret challenge for admin actions, and tabletop the helpdesk against an explicit Scattered Spider scenario before quarter close.
- Enforce number-matching MFA on Microsoft Authenticator and remove push-approve where possible; disable SMS-based MFA on admin accounts; require FIDO2 keys for all M365 / identity-provider admin accounts.
- Validate offline / immutable backup for the e-commerce, EPOS, payments and WMS estates against a Christmas-trading-window ransomware scenario within the next reporting cycle.
Disrupt
- Subscribe to RH-ISAC (Retail and Hospitality ISAC) and contribute observed indicators.
- Push indicators in Section 7 into preventive controls via the ipinsights.io TAXII 2.1 endpoint.
- Tabletop a Christmas-trading-window ransomware scenario explicitly — the 2026 trading calendar makes this the highest-leverage operational test for the year.
10. Forward outlook
It is highly likely that further UK retail cartel-affiliated ransomware events will be publicly disclosed before end of Q3 2026. (HIGH confidence)
It is likely that the 2026 Christmas-trading window will be specifically targeted by cartel-aligned operators; preposition planning and incident-response capacity for November–December. (MEDIUM confidence)
Trigger conditions warranting forecast revision: a confirmed retail-sector exploitation of CVE-2026-20182 / CVE-2026-6973; a third UK retailer disclosing a Scattered-Spider-attributed incident in the same quarter; or a public attribution shift away from English-speaking IAB front-ends towards a new affiliate community.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.
| Source | Reliability | Information | Credibility |
|---|---|---|---|
| A — Completely reliable | Demonstrated repeated reliability | 1 — Confirmed | Corroborated by independent sources |
| B — Usually reliable | Reliable on most occasions | 2 — Probably true | Logical, consistent, partially corroborated |
| C — Fairly reliable | Sometimes reliable | 3 — Possibly true | Reasonably logical, agrees with some information |
| D — Not usually reliable | Limited prior accuracy | 4 — Doubtful | Possible but lacks logic or corroboration |
| E — Unreliable | History of inaccuracy | 5 — Improbable | Contradicts other reporting |
| F — Cannot be judged | No basis for evaluation | 6 — Cannot be judged | Cannot be assessed |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | Inside DragonForce — M&S, Co-op, Harrods analysis | Infosecurity Magazine; Sophos | A2 |
| 2 | DragonForce / Scattered Spider alliance briefings | Acronis TRU; BlackFog; sqmagazine | A2 |
| 3 | M&S Breach — ransomware attack crippled UK retail giant | BlackFog; cm-alliance.com | B2 |
| 4 | Q1 2026 Ransomware Retrospective | Check Point Research | B2 |
| 5 | Ransomware sector reconsolidating | Industrial Cyber | B2 |
| 6 | TheGentlemen leak-site cadence and SystemBC C2 revelations | The Hacker News; ransomware.live | B2 |
| 7 | Akira playbook 2026 | CybelAngel; Trend Micro Spotlight | B2 |
| 8 | Evolving cyber threats facing UK retail | Howden; Heimdal stats 2026 | B3 |
| 9 | UK Retail Cyber Attacks — Detailed Timeline | cm-alliance.com | B2 |
| 10 | CISA / NCSC-UK joint advisory on CVE-2026-20182 | CISA; NCSC-UK; NSA; ACSC; CCCS | A1 |
| 11 | Akira drops 30 victims in one day | SecurityWeek; The Record | A2 |
| 12 | Foxconn NA cyberattack (Nitrogen) | Hendry Adrian Daily Recap; SecurityWeek | B2 |
| 13 | Trend Micro Apex One ITW bulletin (CVE-2026-34926) | Trend Micro; CISA KEV | A2 |
| 14 | ipinsights.io enrichment & blocklist data | ipinsights.io | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…