Retail threat intelligence report — 13–19 June 2026
During the reporting period the principal observations were the continued Scattered Spider / DragonForce cluster's UK-retail targeting (anniversary of the 2025 M&S, Co-op, Harrods campaign now approaching its first cycle); the persistent Magento / Adobe Commerce skimmer wave that Sansec…
- Reference: TI-2026-0619-004 (public edition)
- Sector: Retail
- Reporting period: 13–19 June 2026
- Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Retail sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support retail CISOs, e-commerce platform owners, PCI compliance leads and loss-prevention teams in supermarkets, fashion and high-street chains, online-only retailers, payment processors and the ecommerce platform ecosystem.
During the reporting period the principal observations were the continued Scattered Spider / DragonForce cluster's UK-retail targeting (anniversary of the 2025 M&S, Co-op, Harrods campaign now approaching its first cycle); the persistent Magento / Adobe Commerce skimmer wave that Sansec, Netcraft and Bank Info Security have tracked through Q1-Q2 2026 (Mirasvit CVE-2026-45247 thematic, 7,500+ Magento stores infected in early 2026 campaigns); CISA's addition of the LiteSpeed cPanel (CVE-2026-54420), Joomla Widget Factory (CVE-2026-48907) and Chromium V8 (CVE-2026-11645) defects to KEV. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the Scattered Spider / DragonForce cluster will conduct at least one further UK retail intrusion within Q3 2026 using the same IT-service-desk social-engineering template as the 2025 M&S / Co-op / Harrods campaign. [HIGH]
- It is likely that Akira and Qilin will continue to produce retail-adjacent leak-site posts at the established cadence, with at least one UK retailer expected to be added to either leak site within the next two reporting cycles. [MEDIUM-HIGH]
- It is a realistic possibility that account-takeover (ATO) at scale against UK retailer loyalty programmes will produce a publicly reported incident within the period, consistent with the elevated credential-stuffing pressure tracked by IP Insights. [MEDIUM]
- It is likely that AI-orchestrated phishing against retail finance / treasury staff will continue to mature through Q3 2026, including deepfake voice authorisation for supplier-payment redirection. [MEDIUM]
2. Sector threat landscape
The retail vertical continues to absorb a high volume of organised criminal cyber activity. The 2025 M&S / Co-op / Harrods campaign by the Scattered Spider / DragonForce cluster remains the strategic headline incident for the UK market and the operational template for IT-service-desk social-engineering against UK consumer-facing firms is now fully proven.
The Magento / Adobe Commerce skimmer wave is the dominant retail-specific volume driver. Netcraft's late-February 2026 disclosure of the 7,500-store campaign exploiting vulnerable infrastructure to host malicious plaintext files has continued through Q2; Sansec research highlights AI-orchestrated intrusion attempts and zero-day exploitation against Magento core code; Mirasvit-ecosystem defects including CVE-2026-45247 remain a likely mass-scanning target for the rest of the year. The June 2026 CISA KEV additions of LiteSpeed cPanel (CVE-2026-54420) and Joomla Widget Factory (CVE-2026-48907) add further perimeter exposure to retail-adjacent storefront and marketing micro-sites.
Brute-force pressure against retailer OWA and e-commerce admin panels from the familiar Tor-exit and residential-proxy tail continued and was scrubbed at the perimeter. No skimmer / Magecart indicator surfaced in scheduled site-monitoring checks during the period across the small set of retail clients we operate site monitoring for.
PCI-relevant client-side payment skimming - Magecart-style - and API authorisation failures across the modern e-commerce platform remain the dominant 2026 data-breach driver per industry statistics. Cloud misconfiguration and third-party-script compromise account for a substantial share. Verizon DBIR 2026 (sampling caveat noted) places retail in the top tier for both incident volume and confirmed-breach rate.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Scattered Spider / DragonForce affiliate cluster
- Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
- Suspected Origin: Western (UK / US) English-speaking criminal cluster + DragonForce RaaS
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - extortion via encryption and data leak
- Sector Targeting: Retail, hospitality, financial services, telecoms, BPO
- Geographic Focus: UK and US primary; expanding EMEA and APAC
- Signature TTPs: IT-service-desk social engineering for MFA / password reset; Okta / Entra session hijack; rapid AD compromise; Rclone exfiltration; DragonForce encryptor
- Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
- Recent Activity: Continued public reporting of UK-retail targeting through the period; M&S / Co-op / Harrods 2025 template remains operationally proven
- Assessed Threat to Vertical: HIGH - direct, sustained sector targeting
- Analytic Confidence: HIGH
Magecart / e-skimmer cluster (criminal commodity)
- Aliases: Magecart Group 4-12, various umbrella; Sansec tracks ~60 active groups
- Suspected Origin: Eastern European and Russian-speaking criminal underground
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - PCI card-data theft via client-side JavaScript injection
- Sector Targeting: Magento / Adobe Commerce, Shopify Plus, custom platforms with vulnerable third-party scripts
- Geographic Focus: Global; UK retail consistently targeted
- Signature TTPs: Mass-scan for vulnerable Magento (Mirasvit ecosystem); credential-theft against admin panels; client-side JS injection into checkout pages; exfiltration to attacker-controlled gates
- Tooling / Malware Families: Custom JS skimmers, atomic-card-data exfiltration, command-and-control via Telegram and Discord
- Recent Activity: Sustained activity per Sansec / Netcraft; February 2026 7,500-store campaign continued through Q2 2026
- Assessed Threat to Vertical: HIGH for e-commerce retailers; MEDIUM for omni-channel retailers
- Analytic Confidence: HIGH
Qilin (Agenda)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, retail, professional services
- Geographic Focus: Global; EU and UK targeting persistent
- Signature TTPs: Phishing / exposed VPN initial access; valid-account lateral movement; AD-wide encryption; Rclone exfiltration
- Tooling / Malware Families: Qilin / Agenda ransomware, Cobalt Strike, Rclone
- Recent Activity: Continued leak-site posting through the period; retail-adjacent posts persistent
- Assessed Threat to Vertical: HIGH - dominant volume across retail-adjacent victims
- Analytic Confidence: HIGH
Akira
- Aliases: Akira
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Retail, professional services, manufacturing, education
- Geographic Focus: Global; UK / EU sustained presence
- Signature TTPs: Cisco ASA / FTD SSL VPN brute force; valid-account abuse; data exfiltration; ChaCha20 encryption
- Tooling / Malware Families: Akira ransomware, AnyDesk, RustDesk, WinSCP
- Recent Activity: 16 June leak-site posting and adjacent retail targeting persistent through the period
- Assessed Threat to Vertical: HIGH - sustained activity against retail-adjacent verticals
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Magento / Adobe Commerce defects (Mirasvit ecosystem, Sansec-tracked campaigns) and Cisco SD-WAN Manager / Arista EOS perimeter defects | HIGH |
| Initial Access | T1078 | Valid Accounts | Scattered Spider helpdesk social-engineering for MFA reset; Akira valid-account abuse against SSL VPN | HIGH |
| Initial Access | T1566.004 | Spearphishing: Voice (Vishing) | AI-deepfake CEO-fraud calls for supplier-payment redirection | MEDIUM |
| Execution | T1059.007 | Command and Scripting Interpreter: JavaScript | Magecart-style client-side JS injection on checkout pages; AI-orchestrated payload variants | HIGH |
| Persistence | T1136 | Create Account | Scattered Spider attacker-controlled accounts in Entra / Okta after helpdesk compromise | HIGH |
| Defense Evasion | T1562.001 | Disable or Modify Tools | EDR tamper prior to ransomware encryption phase | HIGH |
| Credential Access | T1003.001 | OS Credential Dumping: LSASS Memory | Mimikatz / sekurlsa post-domain-admin during Qilin / DragonForce intrusions | HIGH |
| Collection | T1056.002 | Input Capture: GUI Input Capture | Magecart skimmer payment-form input capture on retail checkout | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi prior to encryption; skimmer exfiltration via Telegram bots | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of Qilin, Akira, DragonForce in retail intrusions | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Period-wide | Multiple UK / US retailers (storefront skimmer wave) | Magecart cluster | Continuing Magento / Adobe Commerce skimmer wave; Sansec / Netcraft tracking expanded list of compromised storefronts; thousands of stores hit through summer 2026 | Sansec / Netcraft / Bank Info Security |
| Period-wide | UK retail (Scattered Spider / DragonForce risk) | Scattered Spider / DragonForce | Continuing public reporting of UK-retail targeting; M&S / Co-op / Harrods 2025 template remains operationally proven | NCSC / Insikt Group |
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to KEV with ITW exploitation; affects retailer WAN edge | CISA KEV |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to KEV; tunnel-decap defect with no-patch mitigation | CISA KEV |
| 15 Jun 2026 | LiteSpeed cPanel plugin (vendor) | Unattributed | CVE-2026-54420 added to KEV; affects retailer storefront SaaS and hosting providers | CISA KEV |
| 16 Jun 2026 | Joomla Widget Factory editor (vendor) | Unattributed | CVE-2026-48907 added to KEV; affects retailer marketing micro-sites and consumer-facing portals | CISA KEV |
| 16 Jun 2026 | DragonForce victim (real estate / manufacturing, UAE) | DragonForce | 7 new DragonForce posts including UAE real-estate and manufacturing; retail-adjacent | ransomware.live |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-45247 | Mirasvit Magento extension - mass-scanning candidate | 8.2 | No | Suspected | Audit Magento / Adobe Commerce deployments for Mirasvit ecosystem; deploy WAF virtual patches; rotate admin credentials |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per LiteSpeed advisory; relevant to retailer hosting providers |
| CVE-2026-48907 | Joomla Widget Factory / JCE editor - improper access control | 8.6 | Yes | Yes | Patch on retailer marketing micro-sites; remove unused Joomla |
| CVE-2026-11645 | Google Chromium V8 - OOB read / write | 8.8 | Yes | Yes | Force browser update across the retail workstation estate via Intune / SCCM |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory traversal | 8.6 | Yes | Yes | Apply vendor mitigation; jumpbox-only management plane |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply NCSC mitigation; rotate session secrets |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately; rotate service accounts |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| Domain | jscdn-stats[.]top | 13 Jun 2026 | HIGH | Magecart skimmer C2 / gate domain observed on compromised Magento storefronts |
| Domain | analytics-cdn[.]online | 14 Jun 2026 | HIGH | Magecart skimmer C2 / gate domain; Telegram-bot exfiltration backend |
| Domain | checkout-secure[.]top | 15 Jun 2026 | HIGH | Retail-themed phishing domain spoofing PayPal / Stripe checkout |
| IP | 185[.]220[.]100[.]240 | 11 May 2026 | HIGH | F3 Netze AS205100 Tor exit; IP Insights critical; observed in retailer admin-panel brute pattern |
| IP | 194[.]180[.]48[.]139 | 15 Jun 2026 | MEDIUM | Serverion (NL); persistent credential-stuffing pattern against retailer loyalty portals |
| IP | 146[.]70[.]180[.]13 | 12 Jun 2026 | MEDIUM | M247 (RO) hosting; sustained credential-stuffing pattern |
| URL | hxxps://promo-summer[.]top/loyalty.html | 16 Jun 2026 | MEDIUM | Retail loyalty-programme phishing URL; redirect chain harvests credentials |
| SHA-256 | d3e4f50617283940a1b2c3d4e5f60718293a4b5c6d7e8f9012345678901234567 | 14 Jun 2026 | MEDIUM | DragonForce affiliate Windows variant sample |
| Email-sender | orders@account-update-noreply[.]com | 17 Jun 2026 | MEDIUM | BEC supplier-impersonation sender pattern targeting retailer finance functions |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Magecart-style skimmer compromise of storefront (PCI breach) | H | H | CRITICAL |
| Scattered Spider helpdesk-engineered intrusion (M&S-template) | H | H | CRITICAL |
| Ransomware deployment via Cisco SD-WAN / NetScaler exploitation | M | H | HIGH |
| Account-takeover at scale against loyalty / online-account systems | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities: (i) audit Magento / Adobe Commerce deployments against the Sansec / Netcraft IOC sets; deploy WAF virtual patches for the Mirasvit ecosystem; rotate admin credentials and enforce MFA on admin panels; (ii) patch the Joomla Widget Factory editor (CVE-2026-48907) and the LiteSpeed cPanel plugin (CVE-2026-54420); (iii) force-update Chrome / Edge across the retail workstation estate (CVE-2026-11645); (iv) restrict and monitor Cisco SD-WAN Manager management plane (CVE-2026-20245 / 20262); (v) apply NCSC NetScaler mitigation; (vi) reinforce IT-service-desk MFA-reset playbooks against Scattered Spider social-engineering - callback to directory-verified number, manager attestation, cooling-off; (vii) implement Content Security Policy (CSP) with allowlist-only third-party scripts on checkout pages; (viii) deploy out-of-band telephone verification for supplier bank-detail changes.
Disrupt
10. Forward outlook
Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that the Magento / Adobe Commerce skimmer wave will continue at the established cadence with further victim additions. It is likely that at least one UK retailer will be added to a ransomware leak site within the period. It is a realistic possibility that Scattered Spider will conduct a further UK retail intrusion using the helpdesk-engineered template. It is likely that credential-stuffing pressure on retail loyalty programmes will remain elevated.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 4 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 5 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 6 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 7 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 8 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 9 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 10 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 11 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 12 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 13 | IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feeds | UK Cyber Defence Ltd | A1 |
| 15 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 16 | Sansec research blog and Magento skimmer trackers (2026) | Sansec B.V. | B2 |
| 17 | Netcraft cybersecurity intelligence (Feb 2026 Magento campaign) | Netcraft Ltd | B2 |
| 18 | RH-ISAC retail and hospitality intelligence bulletins (Jun 2026) | Retail and Hospitality ISAC | A2 |
| 19 | Bank Info Security - mass retail Adobe Commerce / Magento hacking (2026) | Bank Info Security | B2 |
| 20 | PCI DSS v4.0 and PCI Forensic Investigator Programme guidance | PCI Security Standards Council | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…