Retail threat intelligence report — 23–29 May 2026
The week's collection picture is shaped first by M&S's 20 May annual results disclosure confirming the April 2025 Scattered Spider / DragonForce attack cost £300m in lost trading and supply-chain disruption — pre-tax profit down 23.8% to £671.4m for the year to 29 March…
- Reference: TI-2026-0529-004 (public edition)
- Sector: Retail
- Reporting period: 23–29 May 2026
- Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Retail vertical during the period 23 May 2026 to 29 May 2026. The week's collection picture is shaped first by M&S's 20 May annual results disclosure confirming the April 2025 Scattered Spider / DragonForce attack cost £300m in lost trading and supply-chain disruption — pre-tax profit down 23.8% to £671.4m for the year to 29 March, with Co-op separately at £206m revenue loss. This is now the canonical UK retail cyber case study and is reshaping resilience expectations for the vertical. The Scattered Spider IAB front-end continues to target retail and hospitality BPO partners, with researchers warning the same TTPs are pivoting to the US retail sector. Ransomware leak-site cadence from Qilin, Akira, DragonForce and TheGentlemen continued at Q1 2026 levels through the reporting period. Sources are graded against the Admiralty System.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the Scattered Spider / DragonForce playbook against UK retail and hospitality BPO and outsourced-helpdesk partners will continue at sustained cadence through the next two reporting cycles. (HIGH confidence)
- It is highly likely that ransomware operators — Qilin, Akira, TheGentlemen, DragonForce — will continue to target UK and EU retail operators over the next reporting cycle, with mid-tier department-store, grocery and apparel chains the most exposed segment. (HIGH confidence)
- It is likely that the Scattered Spider IAB front-end will materially expand US retail targeting over the next two reporting cycles, per researcher warnings published the week of 24 May. (MEDIUM-HIGH confidence)
- It is likely that the M&S 20 May £300m disclosure will produce a measurable uplift in board-level cyber-resilience investment across UK retail through Q3 2026, with corresponding short-term increases in helpdesk-identity-verification spend, EDR licensing and segmentation projects. (MEDIUM confidence)
2. Sector threat landscape
The UK retail vertical has been reshaped by the April 2025 Scattered Spider / DragonForce campaign against M&S, Co-op and Harrods, and the financial picture is now public: M&S's 20 May 2026 annual results confirmed adjusted pre-tax profit down 23.8% to £671.4m for the year to 29 March, with the cyber-attack costing approximately £300m in lost trading and supply-chain disruption. Co-op separately confirmed £206m revenue loss. These numbers are now common knowledge inside UK retail boardrooms and are visibly reshaping investment priorities, particularly in helpdesk-identity-verification, EDR coverage and segmentation. NCSC and UK experts described the M&S / Co-op events as a 'Category 2 cyber hurricane' at the time of the campaign, and that framing persists.
The Scattered Spider IAB front-end continues to operate against UK retail and hospitality, with the operational pivot in 2026 towards BPO and outsourced helpdesk partners. Researchers warned the week of 24 May that the same TTPs are now pivoting to the US retail sector — Cybersecurity Dive and Retail Dive both ran prominent coverage that week. The operational pattern is consistent: voice-phishing of IT helpdesks with pre-built identity-verification scripts, SIM-swap, MFA fatigue and push bombing, OAuth consent-phishing, pivot to identity-provider admin accounts, rapid lateral movement to ESXi, and partner-supplied DragonForce / LockBit / Qilin encryptor for the final disruption. UK retail clients should treat their inbound helpdesk channel as a credible attack surface and exercise voice-authentication, callback and ID-verification controls against an explicit Scattered Spider scenario.
Ransomware leak-site activity against retail-adjacent operators remained at sustained Q1 2026 cadence through the reporting period. Qilin, Akira, DragonForce and TheGentlemen each posted new victims in the week of 24 May, with multiple cross-posted entries (Sunrise Company on both Akira and Qilin) reflecting the affiliate-overlap dynamics in the cartel-aligned RaaS operators. The legal-and-professional-services and small-mid-tier retail slices of the leak-site population have remained roughly proportional to historic ratios.
Edge-appliance exploitation pressure remains relevant to the vertical, particularly for operators with substantial point-of-sale or store-network WAN topologies. Cisco Catalyst SD-WAN CVE-2026-20182 (CVSS 10.0, KEV, UAT-8616 in-the-wild) is the highest-priority patch action of the cycle for retail operators on the affected configuration. Ivanti EPMM (CVE-2026-6973) is relevant where retail operators use EPMM for store-staff mobile-device management. Trend Micro Apex One (CVE-2026-34926, KEV 21 May) carries EDR-control-plane risk against retail estates with Apex One deployed. Microsoft Exchange Server OWA (CVE-2026-42897) and Citrix NetScaler (CVE-2026-3055/4368) round out the edge-exposure picture.
Hospitality-sector pressure is rising in parallel, per Kennedys Law's May 2026 coverage of targeted hospitality-industry attacks. Hotels and hospitality businesses across the UK are facing a steep rise in cyber incidents using highly-targeted social-engineering techniques and sector-specific malware. The booking.com phishing campaign reported by Ching Chiao in 2026 remains active. Retail operators with combined retail-and-hospitality exposure — particularly department stores with restaurant operations and grocery chains with cafe businesses — should treat hospitality TTPs as in-scope for their planning.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
- Suspected Origin: UK / US / English-speaking community
- Suspected Sponsor: Criminal (IAB into DragonForce / LockBit / Qilin cartel)
- Primary Motivation: Financial — extortion via partner ransomware
- Sector Targeting: Cross-sector with sustained Retail relevance.
- Geographic Focus: UK, US, increasing reach into EU and outsourced helpdesks abroad
- Signature TTPs: Voice-phishing of IT helpdesks, SIM-swap, MFA fatigue, OAuth consent-phishing, RMM (AnyDesk / TeamViewer / ScreenConnect)
- Tooling / Malware Families: DragonForce / LockBit / Qilin partner encryptors; ESXi-targeted mass-encryption
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — NCSC, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty A2.
- Analytic Confidence: HIGH — NCSC, Sophos X-Ops, CrowdStrike, Mandiant multi-sourced
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial — extortion / data theft
- Sector Targeting: Cross-sector with sustained Retail relevance.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
- Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
- Analytic Confidence: HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
Akira
- Aliases: —
- Suspected Origin: Russia-aligned criminal milieu
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial — encryption + extortion
- Sector Targeting: Cross-sector with sustained Retail relevance.
- Geographic Focus: Global; SMB and mid-market heavy
- Signature TTPs: Cisco VPN account abuse without MFA; rapid AD reconnaissance; ESXi targeting; brand-pressure leak-site
- Tooling / Malware Families: Akira encryptor (Rust); RustDesk; AnyDesk; rclone; PCHunter; Mimikatz
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
- Analytic Confidence: HIGH
TheGentlemen
- Aliases: —
- Suspected Origin: Unattributed (likely Russian-speaking criminal milieu)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial — extortion
- Sector Targeting: Cross-sector with sustained Retail relevance.
- Geographic Focus: Cross-sector, global
- Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows/Linux/BSD/NAS); SystemBC C2
- Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
- Analytic Confidence: MEDIUM-HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1566.002 | Spear-phishing Link | Voice-phishing of IT helpdesks with pre-built identity-verification scripts; AiTM phishing pages mimicking M365 / Okta sign-in. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud | IAB-purchased M365 / Okta admin credentials; session tokens harvested from AiTM. | HIGH |
| Initial Access | T1190 | Exploit Public-Facing Application | Cisco SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Exchange OWA CVE-2026-42897, Apex One CVE-2026-34926, Citrix NetScaler CVE-2026-3055/4368 against unpatched internet-facing tiers. | HIGH |
| Credential Access | T1539 | Steal Web Session Cookie | Session-token theft from AiTM phishing; reuse against M365 / Okta admin endpoints. | HIGH |
| Credential Access | T1621 | Multi-Factor Authentication Request Generation | MFA-fatigue push-bombing of helpdesk and admin accounts following voice-phish foothold. | HIGH |
| Persistence | T1098 | Account Manipulation | Creation of attacker-controlled identity-provider admin accounts and OAuth-app consent grants for persistent access. | HIGH |
| Defence Evasion | T1562.001 | Impair Defences: Disable Security Tools | EDR control-plane targeting via stolen admin credentials; Apex One CVE-2026-34926 directory-traversal as fresh primitive. | MEDIUM |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGA / AzCopy egress of customer and operational data prior to ransomware stage. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin.B / DragonForce / Akira ESXi-aware encryption of retail hypervisor and store-back-office estates. | HIGH |
| Impact | T1657 | Financial Theft | Gift-card abuse, payment-card data theft via Magecart-pattern web-skimmer compromise. | MEDIUM |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 20 May 2026 | M&S — annual results disclosure of April 2025 attack | Scattered Spider / DragonForce | Confirmed £300m cyber-attack cost; pre-tax profit down 23.8% to £671.4m. Co-op £206m revenue loss. Canonical UK retail cyber case study. | ITV / Computer Weekly / M&S |
| Week of 24 May 2026 | US retail sector — Scattered Spider pivot warning | Scattered Spider IAB front-end | Cybersecurity Dive and Retail Dive: researchers warn UK retail TTPs are now targeting US retail; expect material US victim disclosures over next two cycles. | Cybersecurity Dive / Retail Dive |
| Week of 26 May 2026 | Sunrise Company (real-estate / resort hospitality, US) | Akira / Qilin (cross-posted) | Cross-posted to both Akira and Qilin leak-sites; resort-hospitality-adjacent. | Ransomware.live |
| 24 May 2026 | Global Retool Group (Business Services, retail-adjacent) | Qilin | Posted to Qilin leak-site 24 May; data-extortion ongoing. | Ransomware.live |
| Ongoing | Booking.com phishing campaign — hospitality booking pretext | Unattributed criminal | Sustained credential-theft against hotel and booking-platform staff; relevant to retail operators with hospitality exposure. | LinkedIn / Kennedys Law |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild) | 10.0 | Yes | Yes | Patch immediately; rotate SSH keys; review NETCONF logs |
| CVE-2026-6973 | Ivanti EPMM (post-CVE-2026-1340 credential reuse chain) | 7.2 | Yes | Yes | Patch and rotate any admin credential issued before 1 Feb 2026 |
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) — directory traversal | 9.4 | Yes | Yes | Patch to build ≥17079; treat as EDR-control-plane exposure until verified |
| CVE-2026-42897 | Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email | 8.1 | Yes | Yes | Apply 14 May 2026 OOB update; disable OWA externally pending patch |
| CVE-2025-34291 | Langflow — origin validation error (added KEV 21 May 2026) | 9.1 | Yes | Suspected | Patch and restrict admin endpoints to trusted networks |
| CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027 | DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May) | 8.0–8.8 | Yes | Yes | Audit developer endpoints; remove compromised package versions |
| CVE-2026-3055 / CVE-2026-4368 | Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May) | 9.0 / 7.5 | No | Suspected | Apply Citrix advisory updates; review session tokens |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]101[.]5 | ongoing | M | TOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block |
| IP | 193[.]32[.]162[.]157 | ongoing | M | Brute-force / malware family — listed on 6 blacklists per IP Insights |
| Domain | global-retool-leaks[.]onion | 24 May 2026 | M | Qilin leak-site post — Global Retool Group disclosure |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Scattered Spider voice-phish → DragonForce / Qilin ransomware deployment via helpdesk BPO | HIGH | HIGH | CRITICAL |
| Ransomware deployment via IAB front-end against retail estate | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation (Cisco SD-WAN / Ivanti EPMM / Citrix NetScaler) against store-network WAN | MEDIUM | HIGH | HIGH |
| Magecart / web-skimmer compromise of payment pages | MEDIUM | HIGH | HIGH |
| Gift-card abuse / loyalty-fraud automation | HIGH | MEDIUM | HIGH |
| Supply-chain compromise via shared SaaS, BPO partner or hospitality booking platform | MEDIUM | HIGH | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For retail tenants specifically, instrument helpdesk-identity-verification voice logging against Scattered Spider linguistic markers; correlate identity-provider admin account creations with helpdesk-call timestamps. Hunt for Okta / EntraID OAuth consent grants outside the retail-allow-list, and treat any cross-store SharePoint sharing-grant of POS / payment / loyalty data folders as a P1 trigger. Watch payment-page DOM for unexpected script-source additions (Magecart pattern) on a 24-hour cadence.
Defend
Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. Retail clients should map controls onto PCI-DSS v4.0 (particularly Requirements 6.4.3 and 11.6.1 for the payment-page DOM-integrity case) and to the NCSC's Retail and Hospitality guidance set. Helpdesk identity-verification scripts must be exercised against an explicit Scattered Spider voice-phishing scenario; the post-M&S board environment makes this investment substantially easier to justify in 2026.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. The Retail and Hospitality ISAC (RH-ISAC) is the natural indicator-sharing forum, with sector-tailored reporting that public feeds simply cannot replicate. M&S's published hackers-utilising-TCS-employee-logins disclosure has been a useful peer-exchange case study. NCSC's CiSP retail trust group provides UK-anchored indicator sharing.
10. Forward outlook
Looking forward to the next reporting period (30 May – 5 June 2026), it is highly likely that the Scattered Spider IAB front-end will continue UK retail and hospitality helpdesk-voice-phishing at current cadence, and likely that at least one US-retail victim will publicly disclose a Scattered Spider attribution within the next two cycles. Qilin, Akira, DragonForce and TheGentlemen will continue at the current leak-site cadence. There is a realistic possibility that one or more UK mid-tier retailers will publicly disclose an incident traceable to the Cisco SD-WAN, Ivanti EPMM, Exchange OWA or Apex One vulnerabilities flagged in Section 6.
*Trigger conditions that would prompt revision of this outlook include: (a) a UK retailer publicly disclosing a Scattered Spider / DragonForce attack post-M&S, which would warrant an immediate amber-level client advisory; (b) the appearance of a UK or EU retail victim on a Qilin / Akira / TheGentlemen leak-site; (c) a US retail attribution to Scattered Spider with named victim, which would validate the researcher pivot-warning and prompt a UK / US cross-exchange; or (d) a fresh Magecart-pattern compromise affecting a UK-listed retailer.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA | A1 |
| 2 | Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZ | CISA et al. | A1 |
| 3 | Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616) | Cisco Talos | B2 |
| 4 | Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026 | CISA / Trend Micro | A1 |
| 5 | Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by Microsoft | Microsoft / Help Net Security | B1 |
| 6 | NCSC weekly threat reports and advisory feed (NCSC-UK) | NCSC | A1 |
| 7 | ESET APT Activity Report — Oct 2025 to Mar 2026 | ESET | B2 |
| 8 | Check Point Research — The State of Ransomware Q1 2026 | Check Point Research | B2 |
| 9 | Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026) | Ransomware.live | C2 |
| 10 | IP Insights — IP reputation enrichment (https://www.ipinsights.io) | UK Cyber Defence Ltd | B2 |
| 11 | FS-ISAC — sector resilience and AI-fraud advisories (subscription) | FS-ISAC | A2 |
| 12 | NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368 | NCSC | A1 |
| 13 | Marks & Spencer — annual results 20 May 2026 (£300m cyber cost) | M&S / ITV News | B2 |
| 14 | Cybersecurity Dive / Retail Dive — Scattered Spider US retail pivot warning (week of 24 May) | Cybersecurity Dive / Retail Dive | B2 |
| 15 | RH-ISAC — M&S hackers utilise employee logins from third-party consulting firm | Retail & Hospitality ISAC | A2 |
| 16 | Kennedys Law — Targeted attack on hospitality industry ramps up (UK) | Kennedys Law | B2 |
| 17 | Computer Weekly — M&S / Co-op attacks a 'Category 2 cyber hurricane' | Computer Weekly | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…