Retail threat intelligence report — 30 May – 5 June 2026
The retail collection picture this week has been dominated by the continuing fallout from the 2025 Scattered Spider / DragonForce campaign against UK retailers, with M&S, Co-op and Harrods continuing to feature in trade-press analysis of the cyber-loss cycle.
- Reference: TI-2026-0605-004 (public edition)
- Sector: Retail
- Reporting period: 30 May – 5 June 2026
- Issued: 5 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The retail collection picture this week has been dominated by the continuing fallout from the 2025 Scattered Spider / DragonForce campaign against UK retailers, with M&S, Co-op and Harrods continuing to feature in trade-press analysis of the cyber-loss cycle. The addition of CVE-2026-45247 (Mirasvit Full Page Cache Warmer, Magento) to KEV on 03 June is acutely relevant to the vertical: any UK retailer running a Magento or Adobe Commerce storefront with Mirasvit modules should treat the cache-warmer endpoint as a candidate compromise pending patch verification. Continuing edge-appliance exploitation against Fortinet EMS (CVE-2026-35616), Cisco SD-WAN (CVE-2026-20182) and Exchange OWA (CVE-2026-42897) all carry direct retail relevance.
Perimeter scrubbing was dominated by sustained brute-force pressure against SSH and CMS surfaces from the standing IP Insights 'critical' tail. May 2026 leak-site telemetry from BreachSense placed retail in the top five sub-sectors by posting volume, with Qilin and DragonForce as the dominant brand-name threats.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware and IAB activity against UK and EU retailers will continue at the elevated 2026 cadence, with Scattered Spider continuing as the dominant English-speaking IAB front-end and Qilin / DragonForce as the principal extortion brands. (HIGH confidence)
- It is highly likely that CVE-2026-45247 (Mirasvit / Magento) will be exploited against UK retailers running affected modules within the next reporting cycle, with consequences ranging from Magecart-style cardholder-data theft to full storefront compromise. (HIGH confidence)
- It is likely that CVE-2026-35616 (Fortinet FortiClient EMS) will be exploited against retail estates over the next two reporting cycles, given the prevalence of FortiClient EMS in distributed-retail head-office and DC environments. (MEDIUM-HIGH confidence)
- It is highly likely that helpdesk-impersonation vishing against retail IT support and outsourced contact-centres will continue at the cadence observed in 2025, with credential-reset and MFA-bypass as the primary objectives. (HIGH confidence)
- It is likely that POS-malware and skimmer-implant activity against UK retailers will produce at least one confirmed cardholder-data exfiltration disclosure in the next reporting cycle. (MEDIUM confidence)
2. Sector threat landscape
The retail vertical continues to define the UK ransomware-loss narrative on account of the M&S, Co-op and Harrods incidents through April-May 2025. M&S's annual results, published 20 May, confirmed cyber-attack cost of GBP 300m and a 23.8% reduction in adjusted pre-tax profit; the trade press has continued to use the case as the reference for the 2026 cycle. BreachSense's May 2026 retrospective places retail in the top five sub-sectors by leak-site posting volume.
The most operationally consequential single development this week is the addition of CVE-2026-45247 (Mirasvit Full Page Cache Warmer) to CISA KEV on 03 June. Mirasvit modules are widely deployed across Magento and Adobe Commerce storefronts, including in the UK mid-market; the deserialisation primitive against the cache-warmer endpoint is acutely valuable to attackers and should be treated as actively exploited. Retailers running affected modules should treat the cache-warmer endpoint as a candidate compromise pending patch verification.
Edge-appliance and identity-provider exposure remains the principal IT-side initial-access route. Fortinet FortiClient EMS (CVE-2026-35616), Cisco Catalyst SD-WAN (CVE-2026-20182) and Microsoft Exchange OWA (CVE-2026-42897) are all relevant to UK retail head-office estates. Scattered Spider continuing tradecraft against retail IT helpdesks and outsourced contact-centres remains the dominant credential-driven initial-access pattern.
POS-malware and skimmer-implant activity continues at a steady-state cadence against UK retailers. The Retail and Hospitality ISAC (RH-ISAC) reports a continuing rise in JavaScript-skimmer (Magecart-style) infrastructure, with the addition of Mirasvit to KEV likely to accelerate this trend in the next reporting cycle.
Perimeter scrubbing handled sustained brute-force pressure from the standing IP Insights 'critical' tail - none successful.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, Scatter Swine
- Suspected Origin: UK / US / English-speaking community
- Suspected Sponsor: Criminal (IAB into DragonForce / Qilin)
- Primary Motivation: Financial - extortion via partner ransomware
- Sector Targeting: Cross-sector with sustained Retail relevance.
- Geographic Focus: UK, US, increasing EU
- Signature TTPs: Voice-phishing of IT helpdesks; SIM-swap; OAuth consent-phish; RMM abuse
- Tooling / Malware Families: DragonForce / Qilin partner encryptors; ESXi mass-encryption
- Recent Activity: Continuing focus on retail IT helpdesks and outsourced contact-centres; defined the 2025 UK retail loss narrative.
- Assessed Threat to Vertical: HIGH - Admiralty A2.
- Analytic Confidence: HIGH
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Retail relevance.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential IAB initial access; ESXi-aware encryptor; double-extortion
- Tooling / Malware Families: Qilin.B encryptor; SystemBC, AnyDesk, rclone
- Recent Activity: 101 victims posted in May 2026 - fifth consecutive month at top of leak-site postings.
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH
Magecart-style skimmer cluster (multiple actors)
- Aliases: Various
- Suspected Origin: Unattributed
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - cardholder-data theft
- Sector Targeting: Cross-sector with sustained Retail relevance.
- Geographic Focus: Global
- Signature TTPs: JavaScript skimmer implantation via vulnerable Magento / Adobe Commerce modules; Mirasvit primitive plausible new vector
- Tooling / Malware Families: Custom obfuscated JS; bullet-proof hosted exfil endpoints
- Recent Activity: CVE-2026-45247 KEV addition (03 June) elevates near-term threat to retailers running Mirasvit modules.
- Assessed Threat to Vertical: HIGH for affected stack; Admiralty C2.
- Analytic Confidence: MEDIUM
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mirasvit cache-warmer deserialisation (CVE-2026-45247); Fortinet EMS (CVE-2026-35616); Cisco SD-WAN (CVE-2026-20182); Exchange OWA (CVE-2026-42897). | HIGH |
| Initial Access | T1566.002 | Spear-phishing Link | Helpdesk and contact-centre vishing - Scattered Spider standing tradecraft. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud | Reuse of IAB-purchased VPN credentials. | HIGH |
| Execution | T1059.007 | Command and Scripting: JavaScript | Skimmer-implant JavaScript on storefront pages. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded loaders for SystemBC / Cobalt Strike in Qilin and DragonForce tradecraft. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Microsoft Defender BlueHammer LPE relevant to retail endpoint estates. | MEDIUM |
| Collection | T1056 | Input Capture | Skimmer collection of cardholder data at storefront checkout. | HIGH |
| Lateral Movement | T1021.001 | Remote Services: RDP | Pivot via RDP to ESXi and DC infrastructure prior to encryption. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd push to attacker cloud prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware Qilin.B and DragonForce encryptors against retail hypervisor estates. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 03 Jun 2026 | CISA KEV - CVE-2026-45247 Mirasvit / Magento | Unattributed | Cache-warmer deserialisation primitive added to KEV; FCEB remediation 24 Jun 2026; UK retail exposure substantial. | CISA |
| 02 Jun 2026 | Fortinet FortiClient EMS (vendor) | Unattributed | CVE-2026-35616 confirmed in-the-wild; retail head-office and DC exposure. | watchTowr Labs |
| 02 Jun 2026 | Microsoft Defender platform (vendor) | Multiple | BlueHammer LPE chain disclosed; EDR-control-plane risk. | Microsoft / The Hacker News |
| Continuing | M&S / Co-op / Harrods aftermath | Scattered Spider / DragonForce | Continuing trade-press analysis of the 2025 loss cycle; GBP 300m M&S cost confirmed at FY25 results. | ITV / Computer Weekly |
| Ongoing | Qilin / DragonForce / TheGentlemen leak sites | Multiple | May 2026: retail in top five sub-sectors by posting volume. | BreachSense |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; active in-the-wild exploitation reported by watchTowr 02 Jun 2026 | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (<4.18.26040.1011) | 8.4 | Yes | Yes | Force MoCAMP rollout; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH |
| CVE-2026-45585 | Microsoft Windows BitLocker - YellowKey bypass; in-the-wild PoC live | 7.1 | Yes | Suspected | Apply June mitigation guidance; enforce TPM+PIN on regulated workstations |
| CVE-2026-42897 | Microsoft Exchange Server (SE / 2019 / 2016) - OWA crafted-email XSS (continuing exploitation) | 8.1 | Yes | Yes | Apply 14 May 2026 OOB update if not already; disable external OWA pending patch |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager - auth bypass; UAT-8616 continuing campaign | 10.0 | Yes | Yes | Verify Emergency Directive 26-03 closure; rotate SSH keys; review NETCONF logs |
| CVE-2026-6973 | Ivanti EPMM - admin credential reuse chain (post CVE-2026-1340) | 7.2 | Yes | Yes | Rotate any EPMM admin credential issued before 01 Feb 2026; confirm patch level |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer (Magento) - deserialisation; KEV 03 Jun 2026 | 9.8 | Yes | Yes | Patch immediately; isolate Magento admin behind WAF; hunt for unsigned PHP cache entries |
| CVE-2025-48595 | Android Framework - integer-overflow LPE; KEV 02 Jun 2026; limited/targeted exploitation observed by Google | 7.8 | Yes | Yes | Push June 2026 Android security patch to MDM-managed handsets |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - KEV 02 Jun 2026 for revived container-escape campaigns | 7.8 | Yes | Yes | Validate kernels >=5.17; audit container hosts for unconfined cgroup mounts |
| CVE-2026-41091 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-45498 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-N8N-CRIT | n8n self-hosted - max-severity authentication-bypass per CyberScoop research (defenders rushing PoC) | 9.8 | Yes | Suspected | Upgrade to patched build; restrict n8n console to private network only |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 30 May 2026 | H | ServeTheWorld AS (NO); IP Insights threat_score 100, 8 blacklists incl. Emerging Threats Compromised, Brute Force Blocker, Malicious IP - SSH/brute-force cluster |
| IP | 79[.]143[.]178[.]79 | 31 May 2026 | H | contabo.DE; threat_score 100, 7 blacklists incl. ThreatFox malware family - staged loader infrastructure |
| IP | 176[.]65[.]139[.]151 | 01 Jun 2026 | H | Offshore LC (LU); threat_score 100, 7 blacklists - recurring bullet-proof hosting for brute-force |
| IP | 212[.]19[.]134[.]75 | 02 Jun 2026 | H | JSC Kazakhtelecom (KZ); threat_score 100, 8 blacklists; SSH/Telnet brute force at scale |
| IP | 27[.]79[.]41[.]68 | 03 Jun 2026 | H | Viettel Group (VN); threat_score 100, 7 blacklists; SSH brute force |
| IP | 103[.]77[.]246[.]158 | 04 Jun 2026 | H | Megacore Technology (VN); threat_score 100, 7 blacklists; sustained brute-force |
| IP | 34[.]86[.]81[.]254 | 31 May 2026 | M | Google LLC datacentre (US); IP Insights flagged 'critical'; abuse of cloud egress for compromised-stack traffic |
| IP | 136[.]117[.]199[.]185 | 02 Jun 2026 | M | Google LLC datacentre (US); IP Insights 'critical'; cloud-egress abuse |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via Scattered Spider -> DragonForce / Qilin | HIGH | HIGH | CRITICAL |
| Magecart-style skimmer implantation via Mirasvit / Magento exploitation | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation (Fortinet EMS / Cisco SD-WAN / Exchange OWA) | HIGH | HIGH | CRITICAL |
| Helpdesk-impersonation vishing against IT support and outsourced contact-centres | HIGH | MEDIUM | HIGH |
| POS-malware deployment via head-office IT compromise | MEDIUM | HIGH | HIGH |
| BEC against finance functions | HIGH | MEDIUM | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities: patch any Magento / Adobe Commerce instance running affected Mirasvit modules as the single highest-value action of the cycle, and place the cache-warmer endpoint behind a WAF rule pending closure; patch Fortinet FortiClient EMS to 7.4.2 or later; force MoCAMP 4.18.26040.1011; apply the 14 May Exchange OOB update; verify SD-WAN ED 26-03 closure. Strengthen helpdesk identity-verification scripts and enforce out-of-band verification for any payment-instruction change. Reference RH-ISAC playbooks for storefront-skimmer defence and ISO/IEC 27001 Annex A.5.7, A.8.8 and A.5.23.
Disrupt
Disruption priorities: (i) sustained RH-ISAC participation and indicator exchange, with this week's IP Insights 'critical' tail submitted as the highest-value contribution; (ii) coordinated takedown of skimmer-exfil endpoints via registrar-abuse and Cloudflare trust-and-safety channels; (iii) tabletop exercises around the Scattered Spider helpdesk vector and the storefront-skimmer scenario; (iv) deception deployment around fake storefront admin endpoints.
10. Forward outlook
Looking forward to the next reporting period (06 - 12 June 2026), it is likely that at least one UK retailer will publicly disclose a Mirasvit / Magento exploitation event, with MEDIUM-HIGH confidence based on the breadth of affected estate. It is highly likely that Scattered Spider helpdesk-impersonation activity will continue at the current cadence. It is a realistic possibility that a POS-malware or skimmer-implant incident against a UK retailer will be disclosed within the cycle.
Trigger conditions that would prompt revision include: (a) a UK retailer publicly attributing a breach to Mirasvit / Magento exploitation; (b) an RH-ISAC TLP:CLEAR advisory pointing to a sector-wide skimmer campaign; (c) novel Scattered Spider tradecraft confirmed by NCSC-UK.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | CISA KEV Catalog updates 27 May, 02 Jun and 03 Jun 2026 - https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA | A1 |
| 2 | CISA Alert - CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595), 02 Jun 2026 | CISA | A1 |
| 3 | CISA Alert - CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45247), 03 Jun 2026 | CISA | A1 |
| 4 | NCSC-UK weekly threat report and advisory feed (week ending 05 Jun 2026) - https://www.ncsc.gov.uk/section/keep-up-to-date/threat-reports | NCSC | A1 |
| 5 | ESET APT Activity Report - October 2025 to March 2026 | ESET | B2 |
| 6 | Health-ISAC Heartbeat & 2026 Global Health Sector Threat Landscape Report | Health-ISAC | A2 |
| 7 | Check Point Research - Ransomware Quarterly Insights and May 2026 retrospective | Check Point Research | B2 |
| 8 | BreachSense - May 2026 Ransomware Report (646 victims, 61 groups) | BreachSense | C2 |
| 9 | Ransomware.live - leak-site tracker (Qilin / TheGentlemen / Akira / DragonForce postings, w/e 05 Jun 2026) | Ransomware.live | C2 |
| 10 | watchTowr Labs - Fortinet FortiClient EMS Zero-Day CVE-2026-35616, 02 Jun 2026 | watchTowr | B2 |
| 11 | The Hacker News - Microsoft mitigation for YellowKey BitLocker bypass CVE-2026-45585 | The Hacker News | B2 |
| 12 | The Hacker News - Microsoft warns of two actively exploited Defender vulnerabilities (BlueHammer) | Microsoft / The Hacker News | B1 |
| 13 | CyberScoop - researchers warn of max-severity defect in n8n self-hosted | CyberScoop | B2 |
| 14 | IP Insights - IP reputation enrichment (https://www.ipinsights.io) | UK Cyber Defence Ltd | B2 |
| 16 | Retail and Hospitality ISAC (RH-ISAC) - standing skimmer-defence playbooks | RH-ISAC | A2 |
| 17 | Marks & Spencer - annual results 20 May 2026 confirming GBP 300m cyber-attack cost | M&S / ITV News | B2 |
| 18 | CISA - CVE-2026-45247 Mirasvit deserialisation KEV addition 03 Jun 2026 | CISA | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…