Retail threat intelligence report — 20–26 June 2026
The dominant theme this period is the continuing operational dominance of the DragonForce / Scattered Spider cluster against UK retail - its 2025 M&S…
- Reference: TI-2026-0626-004 (public edition)
- Sector: Retail
- Reporting period: 20–26 June 2026
- Issued: 26 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Retail sector during the period 20 Jun 2026 - 26 Jun 2026. It is intended to support retail IT and security functions, fraud and loss-prevention teams, e-commerce platform owners and the senior risk owner, and is graded TLP:CLEAR. The dominant theme this period is the continuing operational dominance of the DragonForce / Scattered Spider cluster against UK retail - its 2025 M&S, Co-op and Harrods campaigns remain the defining sector reference point - combined with edge-appliance exposure introduced by CISA's 23 June addition of the Ubiquiti UniFi OS chain to the Known Exploited Vulnerabilities catalogue, which is operationally relevant to retail store-network and back-office estates.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the DragonForce / Scattered Spider cluster will continue to be the dominant ransomware threat to UK retail through Q3 2026, given the proven business-disruption capability demonstrated against M&S and Co-op in 2025 and continued leak-site activity in the current period (HIGH confidence).
- It is highly likely that the three Ubiquiti UniFi OS defects added to KEV on 23 June will be exploited against unpatched retail back-office and store-network UniFi deployments within the next 14 days (HIGH confidence).
- It is highly likely that BEC against retail finance functions, payment-redirection scams against suppliers and gift-card fraud against customer-facing channels will remain at sustained volume through the summer-trading peak (HIGH confidence).
- It is likely that ShinyHunters / Lynx cluster activity against retail SaaS tenants (Salesforce, Snowflake, BigCommerce, Shopify-Plus) will continue or escalate through Q3 2026, given continued documented SaaS-tenant compromise activity through 2026 (MEDIUM-HIGH confidence).
- It is a realistic possibility that the prior-period Mirasvit Magento defect (CVE-2026-45247) will be exploited at scale against UK e-commerce estates within the next reporting cycle, given confirmed KEV listing and the continued prevalence of unpatched Magento extensions in the sector (MEDIUM confidence).
2. Sector threat landscape
The UK retail vertical has been the standout sector for sustained, high-impact criminal cyber activity since the 2025 Scattered Spider / DragonForce campaign against M&S, Co-op and Harrods. M&S estimated GBP 300m attack cost, Co-op estimated GBP 206m revenue loss, and both endured operational disruption that materially affected the summer 2025 trading period. The sector enters the 2026 summer-trading peak with this experience fresh, regulator (ICO, Ofcom for telco-retail crossover) attention elevated, and customer-trust capital still in repair.
The collection picture this period is dominated by the 23 June Ubiquiti UniFi OS KEV addition (operationally significant for retail because UniFi hardware is widely deployed in store networks, back-office sites and head-office estates), continued DragonForce / Scattered Spider leak-site activity, sustained credential-stuffing against loyalty-program and customer-account portals, and continued BEC and payment-redirection activity against retail finance functions.
SaaS-tenant compromise via the ShinyHunters / Lynx / WorldLeaks cluster remains a current threat for retail. The 2026 Crunchbase, Charter and Foxconn incidents demonstrate the pattern: vishing or stolen credentials against the SaaS tenant (Salesforce, Snowflake, BigCommerce, Shopify-Plus) followed by bulk export of customer and supplier records. UK retailers with these platforms in their stack are direct in-scope.
E-commerce platform vulnerabilities continue to attract collection. The Mirasvit Magento Full Page Cache Warmer defect (CVE-2026-45247, KEV-listed 03 June) remains a high-priority remediation item for UK retailers running Magento with the Mirasvit extension. The Joomla Widget Factory defect (CVE-2026-48907, KEV-listed 16 June) remains relevant for retail marketing micro-sites and consumer-facing portals.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
DragonForce / Scattered Spider cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
- Suspected Origin: Western (UK / US) English-speaking criminal cluster + DragonForce RaaS infrastructure
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - extortion via encryption and data leak
- Sector Targeting: Retail, financial services, hospitality, telecoms, BPO / outsourced helpdesk providers, education
- Geographic Focus: UK and US primary; spreading EMEA
- Signature TTPs: IT-service-desk social engineering for MFA reset; Okta / Entra session hijack; rapid AD compromise; data theft via Rclone; deployment of DragonForce affiliate ransomware
- Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
- Recent Activity: 22 Jun leak-site posts of BITS Pilani and mihana-v.com (estimated attack 20 Jun); sustained UK retail / hospitality activity through the period
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, financial services, healthcare, professional services, retail
- Geographic Focus: Global; sustained EU and UK targeting through 2026
- Signature TTPs: Initial access via phishing and exposed VPN / RDP; abuse of valid accounts; rapid AD escalation; data exfiltration via Rclone to Mega / Backblaze prior to encryption
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust and Go builders), Cobalt Strike, AnyDesk, Rclone, PsExec
- Recent Activity: 22 Jun leak-site posting of Central Bank of Libya; sustained volume leadership across the reporting period (Insikt / ransomware.live)
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
Akira
- Aliases: Akira, Storm-1567 (some Microsoft attribution overlaps)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Financial services, professional services, manufacturing, education, legal, retail
- Geographic Focus: Global; consistent UK / EU presence
- Signature TTPs: Initial access via Cisco ASA / FTD SSL VPN brute force and exposed admin panels; abuse of valid accounts; rapid network mapping; ChaCha20 ransomware encryption
- Tooling / Malware Families: Akira ransomware (Linux and Windows variants), AnyDesk, RustDesk, WinSCP, Mimikatz
- Recent Activity: 22 Jun NTD Apparel posted to leak site; continued mid-week activity against professional-services sub-verticals
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: HIGH
ShinyHunters / Lynx cluster
- Aliases: ShinyHunters, Lynx, WorldLeaks overlap, ScatteredLapsus overlap
- Suspected Origin: English-speaking criminal cluster with intermittent Russian-speaking operator overlap
- Suspected Sponsor: Criminal
- Primary Motivation: Data theft, extortion, dark-market resale
- Sector Targeting: Retail, fintech, technology, BPO, professional services, trade bodies
- Geographic Focus: UK, US, EU, APAC
- Signature TTPs: Compromise of SaaS tenant via stolen credentials or vishing; bulk export of customer / member records; sale or leak via dark-market
- Tooling / Malware Families: Salesforce / Snowflake credential abuse, custom data-exfiltration scripts, Tor-fronted leak sites
- Recent Activity: Continued 2026 SaaS-tenant compromise activity following Charter / Foxconn / Crunchbase / Klue incidents
- Assessed Threat to Vertical: HIGH for SaaS-heavy verticals
- Analytic Confidence: MEDIUM-HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Anticipated mass-exploitation of Ubiquiti UniFi OS chain at store and back-office edge; continued exposure of Mirasvit / Magento and Joomla retail micro-sites | HIGH |
| Initial Access | T1078 | Valid Accounts | DragonForce / Scattered Spider helpdesk social-engineering for MFA reset; ShinyHunters-style stolen-credential abuse against SaaS tenants | HIGH |
| Initial Access | T1566.002 | Spearphishing Link | Phishing against retail finance functions for BEC; payment-redirection lures against supplier-onboarding teams | HIGH |
| Initial Access | T1110.004 | Credential Stuffing | Sustained credential-stuffing against loyalty-program and customer-account portals; observed in IP Insights enrichment of perimeter traffic | HIGH |
| Persistence | T1136 | Create Account | Scattered Spider creation of attacker-controlled federation accounts in Entra ID / Okta after initial helpdesk compromise | HIGH |
| Defense Evasion | T1562.001 | Disable or Modify Tools | EDR tampering during DragonForce intrusions; pattern consistent with 2025 M&S / Co-op campaign | HIGH |
| Credential Access | T1539 | Steal Web Session Cookie | Okta / Entra session hijack via AiTM phishing kits; observed against monitored retail tenants this period | HIGH |
| Collection | T1213 | Data from Information Repositories | ShinyHunters-style bulk export of Salesforce / Snowflake / BigCommerce customer records | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi prior to encryption; standard DragonForce / Qilin tradecraft | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of DragonForce, Qilin and Akira intrusions; theoretical operational-disruption impact during summer-trading peak | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 23 Jun 2026 | Ubiquiti UniFi OS Server (vendor) | Unattributed | Three CVEs added to CISA KEV; retail store, back-office and head-office estates with UniFi hardware in scope | CISA KEV / Bishop Fox PoC |
| 22 Jun 2026 | Retail-adjacent professional services (NTD Apparel posted by Akira) | Akira | Akira leak-site post on 22 June; merchandising-supply-chain exposure to retail clients | ransomware.live |
| 20 Jun 2026 | Mid-tier retail (DragonForce estimated attack date) | DragonForce / Scattered Spider | DragonForce victims posted 22 June with estimated 20 June attack date; retail-adjacent exposure | ransomware.live |
| Continuing | 2026 SaaS-tenant compromise pattern (Charter, Foxconn, Crunchbase, Nike) | ShinyHunters / Lynx cluster | Continued documented pattern of SaaS-tenant compromise via stolen credentials and vishing; UK retailers using Salesforce / Snowflake / BigCommerce / Shopify-Plus inherit risk | Industry reporting |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-34908 | Ubiquiti UniFi OS Server < 5.0.8 - improper access control | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8 immediately per CISA BOD 26-04 (due 26 Jun 2026); audit management plane exposure |
| CVE-2026-34909 | Ubiquiti UniFi OS Server < 5.0.8 - path traversal | 10.0 | Yes | Yes | Patch to UniFi OS Server 5.0.8; restrict management plane to dedicated VLAN; review for file-system access anomalies |
| CVE-2026-34910 | Ubiquiti UniFi OS Server < 5.0.8 - improper input validation (chains to root RCE) | 10.0 | Yes | Yes | Patch immediately - Bishop Fox PoC chains the three UniFi defects to unauthenticated root RCE |
| CVE-2026-45247 | Mirasvit Magento Full Page Cache Warmer - deserialization of untrusted data | 8.2 | Yes | Yes | Patch / disable Mirasvit FPC Warmer module; deploy WAF virtual patch; audit Magento estate |
| CVE-2026-48907 | Joomla Widget Factory / JCE editor - improper access control | 8.6 | Yes | Yes | Patch JCE editor on customer-facing micro-sites; remove unused Joomla deployments |
| CVE-2026-11645 | Google Chromium V8 - out-of-bounds read / write | 8.8 | Yes | Yes | Force Chrome / Edge update across workstation estate via Intune / SCCM; verify against KEV due-date |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager - CLI command injection | 7.8 | Yes | Yes | Restrict netadmin role; rotate netadmin credentials; apply vendor mitigation; monitor for CLI abuse |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply Citrix advisory; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per LiteSpeed; confirm with hosting providers; relevant under outsourced-ICT regulatory regimes |
| CVE-2025-48595 | Android Framework - integer overflow leading to local privilege escalation | 7.8 | Yes | Yes | Push June 2026 Android security patch via MDM; require minimum patch level on BYOD enrolments |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 21 Jun 2026 | HIGH | F3 Netze AS205100 Tor exit (DE); IP Insights threat score 100 / critical; observed in EmilyAI-tagged perimeter brute-force tail this period |
| IP | 92[.]118[.]39[.]95 | 23 Jun 2026 | HIGH | UNMANAGED LTD (AS47890, GB-registered); IP Insights critical / suggest=block; appears in SSH and OWA brute-force tail |
| IP | 80[.]94[.]95[.]115 | 24 Jun 2026 | HIGH | SS-Net (RO) AS204428; IP Insights critical / suggest=block; sustained mass-scan against management plane endpoints |
| IP | 134[.]122[.]114[.]42 | 23 Jun 2026 | MEDIUM | DigitalOcean droplet IP; IP Insights critical / suggest=block; pattern-matches NetScaler probe traffic |
| IP | 198[.]235[.]24[.]31 | 20 Jun 2026 | MEDIUM | Google Cloud Platform US (AS396982); IP Insights critical / suggest=block; aggressive web-scan against client portals |
| IP | 162[.]142[.]125[.]34 | 25 Jun 2026 | LOW | Censys research scanner; benign but high-volume - exclude from alerting via known-scanner allow-list to reduce noise |
| IP | 64[.]227[.]107[.]117 | 24 Jun 2026 | MEDIUM | DigitalOcean droplet; IP Insights suggest=block; new this period - submitted to ipinsights.io reciprocal feed via EmilyAI |
| IP | 152[.]32[.]143[.]49 | 22 Jun 2026 | MEDIUM | UCloud HK (AS135377) hosting / datacenter, NG geolocation; observed in SaaS-tenant credential-stuffing tail |
| IP | 146[.]70[.]180[.]13 | 21 Jun 2026 | MEDIUM | M247 (RO) hosting; persistent credential-stuffing pattern against public-facing portals across multiple verticals |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| DragonForce / Scattered Spider ransomware deployment during summer-trading peak | H | H | CRITICAL |
| Ubiquiti UniFi OS exploitation at store / back-office edge as ransomware initial-access vector | H | H | CRITICAL |
| ShinyHunters / Lynx SaaS-tenant compromise with bulk customer-record exfiltration | M | H | HIGH |
| BEC / payment-redirection against finance or supplier-onboarding function | H | M | HIGH |
| E-commerce platform exploitation via Mirasvit Magento or Joomla defects | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
*Detection engineering should treat the Ubiquiti UniFi OS chain and DragonForce / Scattered Spider TTPs as the principal hunting hypotheses for this period. For e-commerce, hunt for outbound POST requests from Magento estates to non-Mirasvit destinations and for Joomla Widget Factory editor endpoint anomalies.
Defend
Preventive priorities follow Section 6 directly. Ubiquiti UniFi OS 5.0.8 patch must be applied across the retail estate by 26 June to meet CISA BOD 26-04 - retail store networks are typically the most challenging UniFi estate to patch quickly because of operational hours, so priority must be given to head-office and back-office estates with store-network patching staged. Apply Magento and Joomla patches across the e-commerce estate. Force-update Chrome / Edge across the workstation estate. For identity hardening, enforce number-matching MFA on all Okta / Entra tenants; ensure helpdesk has out-of-band identity-verification for MFA reset; enforce phishing-resistant authentication for privileged accounts. For SaaS-tenant hardening per Salesforce / Snowflake / BigCommerce / Shopify-Plus, enforce IP-restricted login for admin roles, audit OAuth-connected app grants and require step-up MFA on bulk-export and data-loader use.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the Retail and Hospitality ISAC (RH-ISAC) and the NCSC CiSP retail community, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) takedown coordination via NCSC ACD for retailer-brand-themed phishing infrastructure flagged during the period; (iii) coordination with payment processors on BEC and payment-redirection indicators; (iv) submission of observed credential-stuffing source IPs to ipinsights.io for community blocklisting; (v) honeypot deployment fronting Magento and Joomla profiles to capture Mirasvit and Widget Factory exploit attempts.
10. Forward outlook
Looking forward to the next reporting period (27 Jun - 03 Jul 2026), it is highly likely that DragonForce / Scattered Spider leak-site activity against UK retail will continue at the current cadence and a realistic possibility that one mid-tier UK retailer will publicly disclose a material incident during the summer-trading peak. Credential-stuffing volume against loyalty-program portals is likely to remain at or above the current sustained level. SaaS-tenant compromise via ShinyHunters / Lynx remains an open and current threat.
*Trigger conditions that would prompt revision of this outlook include: (a) a UK retailer publicly attributing a breach to Ubiquiti UniFi OS exploitation, which would warrant immediate out-of-cycle reporting; (b) a repeat of the 2025 M&S / Co-op-scale incident affecting a UK top-twenty retailer, which would trigger NCSC sector-wide advisory and ICO engagement; (c) public attribution of a SaaS-tenant compromise affecting a UK retailer to ShinyHunters / Lynx, which would warrant an emergency advisory across all monitored tenants on the same platform; (d) emergence of a Magento extension defect surpassing Mirasvit in prevalence or severity, which would shift e-commerce remediation priority.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | CISA Alert: Three Ubiquiti UniFi OS Flaws Added to KEV (23 Jun 2026) | CISA | A1 |
| 4 | CISA Alert: CVE-2025-67038 Lantronix EDS5000 added to KEV (23 Jun 2026) | CISA | A1 |
| 5 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 6 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 7 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 8 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 9 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 10 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 11 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 12 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 13 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 14 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 15 | IP Insights (ipinsights.io) IP enrichment, blocklists and STIX 2.1 feed | UK Cyber Defence Ltd | A1 |
| 17 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 18 | NCSC Statement on Retailers Incident (2025 ongoing) and follow-up guidance | National Cyber Security Centre | A1 |
| 19 | Retail and Hospitality ISAC (RH-ISAC) sector advisories (Week 26, 2026) | Retail and Hospitality ISAC | A1 |
| 20 | Infosecurity Magazine: UK Retail Response to Scattered Spider Hack Wave | Infosecurity Magazine | B2 |
| 21 | Howden: Evolving cyber threats facing UK retail sector (2026 update) | Howden Group | B2 |
| 22 | Mirasvit Magento Full Page Cache Warmer advisory (Jun 2026) | Mirasvit | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…