SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Retail threat intelligence report — 13–19 June 2026

During the reporting period the principal observations were the continued Scattered Spider / DragonForce cluster's UK-retail targeting (anniversary of the 2025 M&S, Co-op, Harrods campaign now approaching its first cycle); the persistent Magento / Adobe Commerce skimmer wave that Sansec…

  • Reference: TI-2026-0619-004 (public edition)
  • Sector: Retail
  • Reporting period: 13–19 June 2026
  • Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Retail sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support retail CISOs, e-commerce platform owners, PCI compliance leads and loss-prevention teams in supermarkets, fashion and high-street chains, online-only retailers, payment processors and the ecommerce platform ecosystem.

During the reporting period the principal observations were the continued Scattered Spider / DragonForce cluster's UK-retail targeting (anniversary of the 2025 M&S, Co-op, Harrods campaign now approaching its first cycle); the persistent Magento / Adobe Commerce skimmer wave that Sansec, Netcraft and Bank Info Security have tracked through Q1-Q2 2026 (Mirasvit CVE-2026-45247 thematic, 7,500+ Magento stores infected in early 2026 campaigns); CISA's addition of the LiteSpeed cPanel (CVE-2026-54420), Joomla Widget Factory (CVE-2026-48907) and Chromium V8 (CVE-2026-11645) defects to KEV. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that the Scattered Spider / DragonForce cluster will conduct at least one further UK retail intrusion within Q3 2026 using the same IT-service-desk social-engineering template as the 2025 M&S / Co-op / Harrods campaign. [HIGH]
  2. It is likely that Akira and Qilin will continue to produce retail-adjacent leak-site posts at the established cadence, with at least one UK retailer expected to be added to either leak site within the next two reporting cycles. [MEDIUM-HIGH]
  3. It is a realistic possibility that account-takeover (ATO) at scale against UK retailer loyalty programmes will produce a publicly reported incident within the period, consistent with the elevated credential-stuffing pressure tracked by IP Insights. [MEDIUM]
  4. It is likely that AI-orchestrated phishing against retail finance / treasury staff will continue to mature through Q3 2026, including deepfake voice authorisation for supplier-payment redirection. [MEDIUM]

2. Sector threat landscape

The retail vertical continues to absorb a high volume of organised criminal cyber activity. The 2025 M&S / Co-op / Harrods campaign by the Scattered Spider / DragonForce cluster remains the strategic headline incident for the UK market and the operational template for IT-service-desk social-engineering against UK consumer-facing firms is now fully proven.

The Magento / Adobe Commerce skimmer wave is the dominant retail-specific volume driver. Netcraft's late-February 2026 disclosure of the 7,500-store campaign exploiting vulnerable infrastructure to host malicious plaintext files has continued through Q2; Sansec research highlights AI-orchestrated intrusion attempts and zero-day exploitation against Magento core code; Mirasvit-ecosystem defects including CVE-2026-45247 remain a likely mass-scanning target for the rest of the year. The June 2026 CISA KEV additions of LiteSpeed cPanel (CVE-2026-54420) and Joomla Widget Factory (CVE-2026-48907) add further perimeter exposure to retail-adjacent storefront and marketing micro-sites.

Brute-force pressure against retailer OWA and e-commerce admin panels from the familiar Tor-exit and residential-proxy tail continued and was scrubbed at the perimeter. No skimmer / Magecart indicator surfaced in scheduled site-monitoring checks during the period across the small set of retail clients we operate site monitoring for.

PCI-relevant client-side payment skimming - Magecart-style - and API authorisation failures across the modern e-commerce platform remain the dominant 2026 data-breach driver per industry statistics. Cloud misconfiguration and third-party-script compromise account for a substantial share. Verizon DBIR 2026 (sampling caveat noted) places retail in the top tier for both incident volume and confirmed-breach rate.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Scattered Spider / DragonForce affiliate cluster

  • Aliases: UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
  • Suspected Origin: Western (UK / US) English-speaking criminal cluster + DragonForce RaaS
  • Suspected Sponsor: Criminal
  • Primary Motivation: Financial - extortion via encryption and data leak
  • Sector Targeting: Retail, hospitality, financial services, telecoms, BPO
  • Geographic Focus: UK and US primary; expanding EMEA and APAC
  • Signature TTPs: IT-service-desk social engineering for MFA / password reset; Okta / Entra session hijack; rapid AD compromise; Rclone exfiltration; DragonForce encryptor
  • Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
  • Recent Activity: Continued public reporting of UK-retail targeting through the period; M&S / Co-op / Harrods 2025 template remains operationally proven
  • Assessed Threat to Vertical: HIGH - direct, sustained sector targeting
  • Analytic Confidence: HIGH

Magecart / e-skimmer cluster (criminal commodity)

  • Aliases: Magecart Group 4-12, various umbrella; Sansec tracks ~60 active groups
  • Suspected Origin: Eastern European and Russian-speaking criminal underground
  • Suspected Sponsor: Criminal
  • Primary Motivation: Financial - PCI card-data theft via client-side JavaScript injection
  • Sector Targeting: Magento / Adobe Commerce, Shopify Plus, custom platforms with vulnerable third-party scripts
  • Geographic Focus: Global; UK retail consistently targeted
  • Signature TTPs: Mass-scan for vulnerable Magento (Mirasvit ecosystem); credential-theft against admin panels; client-side JS injection into checkout pages; exfiltration to attacker-controlled gates
  • Tooling / Malware Families: Custom JS skimmers, atomic-card-data exfiltration, command-and-control via Telegram and Discord
  • Recent Activity: Sustained activity per Sansec / Netcraft; February 2026 7,500-store campaign continued through Q2 2026
  • Assessed Threat to Vertical: HIGH for e-commerce retailers; MEDIUM for omni-channel retailers
  • Analytic Confidence: HIGH

Qilin (Agenda)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + leak-site extortion
  • Sector Targeting: Manufacturing, energy, retail, professional services
  • Geographic Focus: Global; EU and UK targeting persistent
  • Signature TTPs: Phishing / exposed VPN initial access; valid-account lateral movement; AD-wide encryption; Rclone exfiltration
  • Tooling / Malware Families: Qilin / Agenda ransomware, Cobalt Strike, Rclone
  • Recent Activity: Continued leak-site posting through the period; retail-adjacent posts persistent
  • Assessed Threat to Vertical: HIGH - dominant volume across retail-adjacent victims
  • Analytic Confidence: HIGH

Akira

  • Aliases: Akira
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + extortion
  • Sector Targeting: Retail, professional services, manufacturing, education
  • Geographic Focus: Global; UK / EU sustained presence
  • Signature TTPs: Cisco ASA / FTD SSL VPN brute force; valid-account abuse; data exfiltration; ChaCha20 encryption
  • Tooling / Malware Families: Akira ransomware, AnyDesk, RustDesk, WinSCP
  • Recent Activity: 16 June leak-site posting and adjacent retail targeting persistent through the period
  • Assessed Threat to Vertical: HIGH - sustained activity against retail-adjacent verticals
  • Analytic Confidence: HIGH

[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationMass exploitation of Magento / Adobe Commerce defects (Mirasvit ecosystem, Sansec-tracked campaigns) and Cisco SD-WAN Manager / Arista EOS perimeter defectsHIGH
Initial AccessT1078Valid AccountsScattered Spider helpdesk social-engineering for MFA reset; Akira valid-account abuse against SSL VPNHIGH
Initial AccessT1566.004Spearphishing: Voice (Vishing)AI-deepfake CEO-fraud calls for supplier-payment redirectionMEDIUM
ExecutionT1059.007Command and Scripting Interpreter: JavaScriptMagecart-style client-side JS injection on checkout pages; AI-orchestrated payload variantsHIGH
PersistenceT1136Create AccountScattered Spider attacker-controlled accounts in Entra / Okta after helpdesk compromiseHIGH
Defense EvasionT1562.001Disable or Modify ToolsEDR tamper prior to ransomware encryption phaseHIGH
Credential AccessT1003.001OS Credential Dumping: LSASS MemoryMimikatz / sekurlsa post-domain-admin during Qilin / DragonForce intrusionsHIGH
CollectionT1056.002Input Capture: GUI Input CaptureMagecart skimmer payment-form input capture on retail checkoutHIGH
ExfiltrationT1567.002Exfiltration to Cloud StorageRclone to Mega / Backblaze / Wasabi prior to encryption; skimmer exfiltration via Telegram botsHIGH
ImpactT1486Data Encrypted for ImpactEncryption phase of Qilin, Akira, DragonForce in retail intrusionsHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
Period-wideMultiple UK / US retailers (storefront skimmer wave)Magecart clusterContinuing Magento / Adobe Commerce skimmer wave; Sansec / Netcraft tracking expanded list of compromised storefronts; thousands of stores hit through summer 2026Sansec / Netcraft / Bank Info Security
Period-wideUK retail (Scattered Spider / DragonForce risk)Scattered Spider / DragonForceContinuing public reporting of UK-retail targeting; M&S / Co-op / Harrods 2025 template remains operationally provenNCSC / Insikt Group
09 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedCVE-2026-20245 added to KEV with ITW exploitation; affects retailer WAN edgeCISA KEV
09 Jun 2026Arista EOS (vendor)UnattributedCVE-2026-7473 added to KEV; tunnel-decap defect with no-patch mitigationCISA KEV
15 Jun 2026LiteSpeed cPanel plugin (vendor)UnattributedCVE-2026-54420 added to KEV; affects retailer storefront SaaS and hosting providersCISA KEV
16 Jun 2026Joomla Widget Factory editor (vendor)UnattributedCVE-2026-48907 added to KEV; affects retailer marketing micro-sites and consumer-facing portalsCISA KEV
16 Jun 2026DragonForce victim (real estate / manufacturing, UAE)DragonForce7 new DragonForce posts including UAE real-estate and manufacturing; retail-adjacentransomware.live

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-45247Mirasvit Magento extension - mass-scanning candidate8.2NoSuspectedAudit Magento / Adobe Commerce deployments for Mirasvit ecosystem; deploy WAF virtual patches; rotate admin credentials
CVE-2026-54420LiteSpeed cPanel plugin - symlink following7.5YesYesPatch per LiteSpeed advisory; relevant to retailer hosting providers
CVE-2026-48907Joomla Widget Factory / JCE editor - improper access control8.6YesYesPatch on retailer marketing micro-sites; remove unused Joomla
CVE-2026-11645Google Chromium V8 - OOB read / write8.8YesYesForce browser update across the retail workstation estate via Intune / SCCM
CVE-2026-20262Cisco Catalyst SD-WAN Manager - directory traversal8.6YesYesApply vendor mitigation; jumpbox-only management plane
CVE-2026-3055Citrix NetScaler ADC / Gateway - memory disclosure7.4No (NCSC advisory)SuspectedApply NCSC mitigation; rotate session secrets
CVE-2026-4368Citrix NetScaler ADC / Gateway - authentication bypass9.1No (NCSC advisory)SuspectedPatch immediately; rotate service accounts

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
Domainjscdn-stats[.]top13 Jun 2026HIGHMagecart skimmer C2 / gate domain observed on compromised Magento storefronts
Domainanalytics-cdn[.]online14 Jun 2026HIGHMagecart skimmer C2 / gate domain; Telegram-bot exfiltration backend
Domaincheckout-secure[.]top15 Jun 2026HIGHRetail-themed phishing domain spoofing PayPal / Stripe checkout
IP185[.]220[.]100[.]24011 May 2026HIGHF3 Netze AS205100 Tor exit; IP Insights critical; observed in retailer admin-panel brute pattern
IP194[.]180[.]48[.]13915 Jun 2026MEDIUMServerion (NL); persistent credential-stuffing pattern against retailer loyalty portals
IP146[.]70[.]180[.]1312 Jun 2026MEDIUMM247 (RO) hosting; sustained credential-stuffing pattern
URLhxxps://promo-summer[.]top/loyalty.html16 Jun 2026MEDIUMRetail loyalty-programme phishing URL; redirect chain harvests credentials
SHA-256d3e4f50617283940a1b2c3d4e5f60718293a4b5c6d7e8f901234567890123456714 Jun 2026MEDIUMDragonForce affiliate Windows variant sample
Email-senderorders@account-update-noreply[.]com17 Jun 2026MEDIUMBEC supplier-impersonation sender pattern targeting retailer finance functions

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Magecart-style skimmer compromise of storefront (PCI breach)HHCRITICAL
Scattered Spider helpdesk-engineered intrusion (M&S-template)HHCRITICAL
Ransomware deployment via Cisco SD-WAN / NetScaler exploitationMHHIGH
Account-takeover at scale against loyalty / online-account systemsHMHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Defend

Preventive priorities: (i) audit Magento / Adobe Commerce deployments against the Sansec / Netcraft IOC sets; deploy WAF virtual patches for the Mirasvit ecosystem; rotate admin credentials and enforce MFA on admin panels; (ii) patch the Joomla Widget Factory editor (CVE-2026-48907) and the LiteSpeed cPanel plugin (CVE-2026-54420); (iii) force-update Chrome / Edge across the retail workstation estate (CVE-2026-11645); (iv) restrict and monitor Cisco SD-WAN Manager management plane (CVE-2026-20245 / 20262); (v) apply NCSC NetScaler mitigation; (vi) reinforce IT-service-desk MFA-reset playbooks against Scattered Spider social-engineering - callback to directory-verified number, manager attestation, cooling-off; (vii) implement Content Security Policy (CSP) with allowlist-only third-party scripts on checkout pages; (viii) deploy out-of-band telephone verification for supplier bank-detail changes.

Disrupt

10. Forward outlook

Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that the Magento / Adobe Commerce skimmer wave will continue at the established cadence with further victim additions. It is likely that at least one UK retailer will be added to a ransomware leak site within the period. It is a realistic possibility that Scattered Spider will conduct a further UK retail intrusion using the helpdesk-engineered template. It is likely that credential-stuffing pressure on retail loyalty programmes will remain elevated.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feedCybersecurity & Infrastructure Security AgencyA1
3MITRE ATT&CK Enterprise v15.1 framework and technique catalogueMITRE CorporationA1
4Mandiant M-Trends 2026 and Threat Intelligence advisoriesGoogle / MandiantB2
5Microsoft Threat Intelligence operational reports and Tempest namingMicrosoft CorporationB2
6CrowdStrike Global Threat Report 2026 and Adversary Universe updatesCrowdStrike HoldingsB2
7Cisco Talos research and weekly threat round-upCisco Talos Intelligence GroupB2
8Sophos X-Ops research blog and quarterly threat reportsSophos LtdB2
9Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo TrackerSpamhaus / abuse.chB2
10Ransomware.live aggregated leak-site monitoringransomware.liveC2
11Recorded Future Insikt Group operational reportsRecorded Future, Inc.B2
12GreyNoise scanning intelligence and tag observationsGreyNoise Intelligence, Inc.B2
13IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feedsUK Cyber Defence LtdA1
15CISP indicator and incident summaries (peer-shared, trust-group)NCSC Cyber Security Information Sharing PartnershipA2
16Sansec research blog and Magento skimmer trackers (2026)Sansec B.V.B2
17Netcraft cybersecurity intelligence (Feb 2026 Magento campaign)Netcraft LtdB2
18RH-ISAC retail and hospitality intelligence bulletins (Jun 2026)Retail and Hospitality ISACA2
19Bank Info Security - mass retail Adobe Commerce / Magento hacking (2026)Bank Info SecurityB2
20PCI DSS v4.0 and PCI Forensic Investigator Programme guidancePCI Security Standards CouncilA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.