SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Retail threat intelligence report — 27 June – 3 July 2026

Coverage this period is dominated by the NCA arrests on 30 Jun 2026 of four UK nationals connected to the M&S / Co-op / Harrods DragonForce / Scattered Spider cluster, the CISA KEV addition of CVE-2026-45659 (SharePoint deserialisation RCE)…

  • Reference: TI-2026-0703-004 (public edition)
  • Sector: Retail
  • Reporting period: 27 June – 3 July 2026
  • Issued: 3 July 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Retail sector during the period 27 Jun 2026 - 03 Jul 2026. It is intended to support operational defenders and risk owners in retailers and adjacent hospitality organisations and is graded TLP:CLEAR. Coverage this period is dominated by the NCA arrests on 30 Jun 2026 of four UK nationals connected to the M&S / Co-op / Harrods DragonForce / Scattered Spider cluster, the CISA KEV addition of CVE-2026-45659 (SharePoint deserialisation RCE), and the sustained reputational and financial fall-out of the retail cluster on the broader UK retail sector.

The perimeter tail is dominated by IP Insights critical-scored Tor and bulletproof-hosting infrastructure, with sustained credential-stuffing volumes against customer-facing loyalty and account portals on retail client tenants.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that CVE-2026-45659 will be exploited against unpatched SharePoint estates in retailers within the next 14 days, given the CISA KEV three-day BOD timeline (HIGH confidence).
  2. It is highly likely that retail help-desk social engineering (DragonForce / Scattered Spider methodology) will continue against UK retailers over the next two reporting cycles despite the NCA arrests, driven by the alliance-affiliate model (HIGH confidence).
  3. It is likely that credential-stuffing and account-take-over campaigns against retail loyalty and account portals will continue at elevated volumes through Q3 2026 (HIGH confidence).
  4. It is likely that Qilin, Akira and DragonForce will continue to target retailers as opportunistic ransomware targets (HIGH confidence).
  5. It is a realistic possibility that Magecart-style JavaScript skimmers will reappear in volume against UK retailer checkout journeys during Q3 2026, following a period of relative quiet (MEDIUM confidence).

2. Sector threat landscape

The retail sector remains under sustained pressure following the M&S / Co-op / Harrods cluster, which continues to reverberate through board-level risk conversations and insurance renewals. M&S has estimated £300m in lost profits and £1.2bn wiped from market cap; Co-op's rural distribution disruption continues to be referenced in post-incident reporting; Harrods' precautionary internet-access restriction served as a model for other retailers preparing incident-response playbooks. The NCA arrests on 30 Jun 2026 mark an operational win for law enforcement but do not eliminate the threat: the alliance-affiliate model under which DragonForce and Scattered Spider have operated is designed to be resilient to individual operator disruption.

CVE-2026-45659 is operationally significant for retail. Successful exploitation would give an authenticated attacker (Site Member or higher) remote code execution on the SharePoint server, which in typical retailer estates has network reachability to store-management and back-office systems. The M&S / Co-op / Harrods cluster demonstrated the operational reality of what happens when a retailer's head-office IT is disrupted; the CVE-2026-45659 chain provides a lower-friction path to the same operational outcome.

Credential-stuffing and account-take-over volumes against customer-facing retail portals have remained elevated throughout Q2 2026. The perimeter tail against monitored retail M365 and IdP endpoints continues to be dominated by IP Insights critical-scored Tor exits and bulletproof hosting. Payment-fraud crews continue to monetise the credential corpus for account-take-over against loyalty accounts (redeeming points, adding cards to wallet, generating gift-card codes), against retailer buy-now-pay-later accounts, and against retailer store-credit facilities. Magecart-style JavaScript skimming has been quiet in recent months but historically returns in volume around peak-trading periods; we assess a realistic possibility of a return in volume during Q3 2026.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

DragonForce / Scattered Spider cluster

  • Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
  • Suspected Origin: Anglophone (UK/US); four arrests 30 Jun 2026
  • Suspected Sponsor: Organised criminal alliance
  • Primary Motivation: Financial (ransomware + data extortion)
  • Sector Targeting: Retail, hospitality, technology, telecoms
  • Geographic Focus: Anglophone western targets
  • Signature TTPs: Voice-phishing IT service desk to reset MFA, help-desk social engineering, EDR bypass via RMM, aggressive cloud-tenant pivot, Linux/ESXi encryption via DragonForce payload
  • Tooling / Malware Families: DragonForce ransomware (Linux/ESXi), AnyDesk, SplashTop, Ngrok, Impacket, Chisel
  • Recent Activity: NCA arrests 30 Jun 2026 (four individuals, West Midlands / London); operational threat reduced but not eliminated under alliance-affiliate model
  • Assessed Threat to Vertical: HIGH - retail is the primary sector focus of this cluster
  • Analytic Confidence: HIGH

Qilin (a.k.a. Agenda)

  • Aliases: Agenda, Qilin.B, Water Galura
  • Suspected Origin: Russian-speaking (unattributed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Retail, healthcare, financial services, manufacturing
  • Geographic Focus: Global
  • Signature TTPs: IAB-brokered credentials, RMM abuse, RDP; Rust payload; ESXi Linux variant; sustained LOTL
  • Tooling / Malware Families: Qilin.B, Cobalt Strike, Rclone-to-Mega, Mimikatz
  • Recent Activity: Sustained cadence into July 2026 per ransomware.live
  • Assessed Threat to Vertical: HIGH
  • Analytic Confidence: HIGH

Akira

  • Aliases: Akira, Storm-1567
  • Suspected Origin: Russian-speaking (unattributed)
  • Suspected Sponsor: Organised criminal RaaS
  • Primary Motivation: Financial (double extortion)
  • Sector Targeting: Retail, manufacturing, professional services, hospitality
  • Geographic Focus: North America and Europe
  • Signature TTPs: Cisco VPN unpatched initial access, IAB credentials, RDP lateral movement, ESXi hypervisor targeting
  • Tooling / Malware Families: Akira ransomware, Megazord ESXi variant, Rclone, AnyDesk
  • Recent Activity: Refinery Hotel NYC posted 01 Jul 2026 per ransomware.live; sustained sector-adjacent cadence
  • Assessed Threat to Vertical: HIGH
  • Analytic Confidence: HIGH

[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1566.001Spearphishing AttachmentMalicious ISO / IMG / OneNote attachments delivering IcedID, Latrodectus and DarkGate loaders continued to dominate the phishing tail this period; volume steady week-on-week per Proofpoint and SophosHIGH
Initial AccessT1078.004Cloud AccountsOAuth token replay and refresh-token abuse against Microsoft 365 tenants; credential-stuffing tail from Tor exits and bulletproof rangesMEDIUM
PersistenceT1053.005Scheduled Task/JobPost-exploitation scheduled-task creation observed in Akira intrusions, particularly on domain controllers immediately following DCSync activityMEDIUM
DiscoveryT1046Network Service DiscoveryAutomated port sweeps from datacentre-hosted infrastructure - IP Insights flagged multiple AS135771 and AS14061 sources in the perimeter tailMEDIUM
Command and ControlT1071.001Web ProtocolsCobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives from FS-ISAC and H-ISAC partners this period; JARM / JA3 fingerprint hunts remain the primary detectionHIGH
ExfiltrationT1567.002Exfiltration to Cloud StorageRclone-to-Mega and rclone-to-MEGAsync exfiltration patterns dominant in Qilin double-extortion intrusions; Akira favours MEGA and Backblaze B2HIGH
ImpactT1486Data Encrypted for ImpactQilin, Akira and DragonForce ransomware deployment observed against sector-adjacent peers this period per ransomware.live and FS-ISAC / H-ISAC reportingHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
30 Jun 2026Four UK nationals arrested (West Midlands / London)DragonForce / Scattered Spider clusterNCA arrests on suspicion of Computer Misuse Act offences, blackmail, money laundering, participating in an OCG; connected to M&S, Co-op, Harrods intrusionsNational Crime Agency press release
01 Jul 2026Microsoft SharePoint Server (vendor)UnattributedCVE-2026-45659 KEV entry; direct impact on retailer head-office SharePoint estatesCISA KEV / Microsoft advisory
Continuing impactMarks & SpencerDragonForce / Scattered SpiderM&S continues to report incident-related profit impact of c. £300m and market-cap impact of £1.2bn; online recovery ongoingAir IT Group / Brabners / TechRadar
Continuing impactCo-opDragonForce / Scattered SpiderRural distribution disruption continues to be referenced in post-incident reporting; recovery ongoingAir IT Group / Cyber Magazine
Continuing impactHarrodsDragonForce / Scattered Spider (attempted)Precautionary internet-access restriction served as model incident-response playbook; no confirmed data exfiltrationAir IT Group / Cyber Magazine

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-45659Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE8.8YesYesPatch immediately per CISA KEV entry 01 Jul 2026, remediation deadline 04 Jul 2026; audit Site Member permissions; restrict inbound SharePoint /_layouts and /_vti_bin paths at the WAF; hunt w3wp.exe child processes
CVE-2026-34908Ubiquiti UniFi OS Server < 5.0.8 - improper access control10.0YesYesPatch to UniFi OS Server 5.0.8; BOD 26-04 deadline 26 Jun 2026 has passed; restrict management plane to dedicated VLAN
CVE-2026-34909Ubiquiti UniFi OS Server - path traversal9.8YesYesAs per -34908; component of the Bishop Fox unauthenticated root RCE chain
CVE-2026-34910Ubiquiti UniFi OS Server - improper input validation9.8YesYesAs per -34908; component of the Bishop Fox unauthenticated root RCE chain
CVE-2026-3055Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3)9.3YesYesFixed builds 14.1-66.59, 13.1-62.23, 13.1-37.262 FIPS/NDcPP; must run 'kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all' post-patch
CVE-2026-4368Citrix NetScaler Gateway / AAA vserver - race condition7.7YesYesApplied by the same patches as -3055; session mix-up risk against Gateway and AAA virtual servers
CVE-2025-67038Lantronix EDS5000 serial-to-IP bridge - command injection9.6YesSuspectedVendor patch pending; segment device management to dedicated OT VLAN
CVE-2026-50751Check Point Security Gateway - improper authentication9.8YesYesApply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses
CVE-2026-20245Cisco Catalyst SD-WAN Manager - authenticated RCE8.4YesSuspectedCisco fixed release train; disable public-facing vManage where feasible

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]101[.]3428 Jun 2026HIGHfor-privacy.net Tor exit; IP Insights score 100 / critical; 8 blacklists; observed in credential-spray tail against Entra ID sign-in endpoints
IP194[.]180[.]48[.]1830 Jun 2026HIGHserverion (NL); IP Insights score 85 / critical; 2 active + 3 degraded blacklists; observed in SSH brute-force tail against perimeter jump hosts
IP141[.]98[.]11[.]9002 Jul 2026MEDIUMUAB Host Baltic AS209605 (LT); IP Insights score 10 / low but datacentre-flagged; source of scripted OAuth token replay against Microsoft 365

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Help-desk social engineering (DragonForce methodology) into retailer head officeHHCRITICAL
SharePoint (CVE-2026-45659) mass-exploitation at head-office estateHHCRITICAL
Ransomware disruption to store operations / online journey / distributionMHHIGH
Account-take-over of loyalty / BNPL / store-credit accounts via credential stuffingHMHIGH
Magecart-style JavaScript skimmer on checkout journeyMHHIGH
Supplier-portal compromise leading to price / stock file manipulationLHMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection engineering should treat help-desk social engineering as the principal hunting hypothesis for the next reporting cycle, with CVE-2026-45659 close behind. Deploy detections for MFA reset events immediately followed by first-time sign-in from a non-corporate device or IP, particularly on IT-admin or store-management accounts. Deploy SharePoint w3wp.exe child-process hunts and ULS deserialisation exception rules. Baseline anomalous script activity on retailer checkout journeys - unexpected third-party JavaScript, unexpected fetch / XHR to non-approved domains, unexpected form-field interception - as a Magecart hedge. Deploy credential-stuffing detections at the CDN and IdP layer, including impossible-travel and password-spray patterns.

Defend

Preventive priorities follow Section 6 directly. SharePoint patching must be applied to meet the CISA KEV 04 Jul deadline. Deploy phishing-resistant MFA (FIDO2, Windows Hello for Business) to all IT-admin, help-desk, store-management and head-office accounts. Harden the help-desk workflow to require verified callback or manager approval for any MFA reset or credential-recovery action - the operational lesson of the M&S / Co-op cluster is that help-desk process, not technology, is the pivot point. Deploy WAF and CDN-layer bot management against loyalty and account portals. Baseline JavaScript integrity monitoring on checkout journeys (Subresource Integrity, third-party script allow-listing).

Disrupt

Disruption activity within client lawful authority should focus on: (i) participation in the Retail and Hospitality ISAC (RH-ISAC) indicator exchange, with this week's IP Insights critical / block tail contributed; (ii) NCSC CiSP membership for retailer technical staff; (iii) coordinated take-down requests to bulletproof providers for credential-stuffing and ATO infrastructure, submitted through the NCSC Takedown Service; (iv) participation in the British Retail Consortium's cyber-security peer group and RH-ISAC tabletop exercises for help-desk social-engineering playbook validation.

10. Forward outlook

Looking forward to the next reporting period (04 Jul - 10 Jul 2026), it is likely that at least one UK retailer will publicly disclose a SharePoint-borne incident attributable to CVE-2026-45659. It is likely that help-desk social-engineering attempts against UK retailers will continue, and it is a realistic possibility that a successful intrusion under the DragonForce / Scattered Spider methodology will occur during the period despite the arrests. Account-take-over volumes are expected to remain steady or elevated.

Trigger conditions that would prompt revision of this outlook include: (a) any publicly-disclosed UK retailer SharePoint incident; (b) any confirmed successful intrusion under the DragonForce / Scattered Spider methodology, which would warrant immediate out-of-cycle advisory; (c) return of Magecart-style JavaScript skimming in volume, which would warrant a checkout-journey advisory.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities catalogue (daily updates)CISAA1
3CISA KEV addition of CVE-2026-45659 SharePoint deserialisation RCE, 01 Jul 2026CISAA1
4CISA KEV addition of CVE-2026-34908, -34909, -34910 Ubiquiti UniFi OS chain, 23 Jun 2026CISAA1
5Citrix Security Bulletin CTX696300 for CVE-2026-3055 and CVE-2026-4368Citrix / Cloud Software GroupA2
6Microsoft Security Update Guide entry for CVE-2026-45659MicrosoftA2
7SharePoint RCE CVE-2026-45659 added to CISA KEV after active exploitationThe Hacker NewsB2
8CISA warns of actively exploited Microsoft SharePoint vulnerabilitySecurityWeekB2
9Rapid7 vulnerability database: Microsoft SharePoint CVE-2026-45659Rapid7B1
10NHS England Digital cyber alert CC-4759 - Citrix critical security updatesNHS DigitalA1
11ransomware.live daily leak-site trackerransomware.liveB2
12The State of Ransomware - Q1 2026Check Point ResearchA2
13Global ransomware activity for May 2026Industrial CyberB2
14FS-ISAC daily indicator exchange (member portal - TLP:CLEAR)FS-ISACA1
15H-ISAC daily bulletin (member portal - TLP:CLEAR)H-ISACA1
16MTS-ISAC daily bulletin and Cyware indicator exchange (TLP:CLEAR)MTS-ISACA1
17Retail and Hospitality ISAC member exchange (TLP:CLEAR)RH-ISACA1
18NCA arrests four for attacks on M&S, Co-op and Harrods (30 Jun 2026)National Crime AgencyA1
19AA25-239A: Countering Chinese State-Sponsored ActorsCISA / NSA / NCSC / partnersA1
20July rundown - Salt Typhoon and SharePoint scaresIT ProB2
21NHS South East London / Synnovis long-tail updateRecorded Future NewsB2
22NHS pathology reports backlog update (Q1 2026)Digital HealthB2
23NCSC Cyber Threat Report: UK Legal SectorNational Cyber Security CentreA1
24Cyber attacks on law firms jump by 77% (Jun 2026)Law Society GazetteB2
25226 UK law firms suffered data breaches in the past yearChaucer GroupC3
26SRA 2024 Risk Outlook (ongoing reference)Solicitors Regulation AuthorityA2
27M&S, Co-op & Harrods cyber-attacks - lessons for retailersBrabnersB2
28Cyber-attacks on M&S, Co-op, Harrods post-incident summaryAir IT GroupC2
29NCSC Cyber Threat Report: UK Charity SectorNational Cyber Security CentreA1
30GOV.UK: protect your charity from cyber crimeCabinet Office / DCMSA1
31IP Insights REST API enrichment (multiple lookups during the reporting period)IP Insights / UK Cyber Defence LtdA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.