Retail threat intelligence report — 4–10 July 2026
The retail vertical remains defined operationally by the DragonForce / Scattered Spider methodology - voice-phishing IT service desks to reset MFA, help-desk social engineering, aggressive cloud-tenant pivot, and DragonForce ransomware detonation.
- Reference: TI-2026-0710-004 (public edition)
- Sector: Retail
- Reporting period: 4–10 July 2026
- Issued: 10 July 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Retail sector during the period 04 Jul 2026 - 10 Jul 2026. The retail vertical remains defined operationally by the DragonForce / Scattered Spider methodology - voice-phishing IT service desks to reset MFA, help-desk social engineering, aggressive cloud-tenant pivot, and DragonForce ransomware detonation. The 10 Jul 2026 NCA arrests of four further individuals in connection with the M&S / Co-op / Harrods cluster add to the 30 Jun operational activity; the total loss picture now sits at £300m for M&S and £206m for the Co-op. These arrests reduce, but do not eliminate, the operational threat given the alliance-affiliate model.
Weighting RH-ISAC and NCSC intelligence above vendor reporting, the analyst's view is that DragonForce, The Gentlemen, Qilin and Akira are the four actors of most operational significance to the vertical over the next two reporting cycles. The 07 Jul CISA KEV additions covering Joomla-based content management (CVE-2026-48908 JoomShaper SP Page Builder and CVE-2026-56290 Joomlack Page Builder) create a specific residual exposure across retailer marketing, campaign and comparison sites, many of which are still Joomla-based.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that DragonForce / Scattered Spider help-desk voice-phishing tradecraft will continue to drive materially-disruptive intrusions against UK retail brands over the next two reporting cycles, despite the 10 Jul additional NCA arrests (HIGH confidence).
- It is highly likely that CVE-2026-48908 (JoomShaper) and CVE-2026-56290 (Joomlack) will be exploited against retail Joomla-based marketing, campaign and comparison sites over the next 14 days given the 07 Jul CISA KEV listings and typical Joomla plugin patching timelines (HIGH confidence).
- It is highly likely that ransomware and pure data-extortion crews - DragonForce, The Gentlemen, Qilin and Akira - will continue to drive the majority of materially-disruptive incidents against UK retail (HIGH confidence).
- It is likely that CitrixBleed 3 follow-on (CVE-2026-8451) will drive fresh access to retail NetScaler estates over the next two cycles given the 24-hour exploitation cadence (MEDIUM-HIGH confidence).
- It is likely that CVE-2026-45659 SharePoint deserialisation exposure remains material for retailer document-management estates, particularly holding supplier contract and buyer negotiation records (MEDIUM-HIGH confidence).
2. Sector threat landscape
The retail vertical remains defined operationally by the DragonForce / Scattered Spider methodology - voice-phishing IT service desks to reset MFA, help-desk social engineering, aggressive cloud-tenant pivot, and DragonForce ransomware detonation. The 10 Jul 2026 NCA arrests of four further individuals in connection with the M&S / Co-op / Harrods cluster add to the 30 Jun operational activity; the total loss picture now sits at £300m for M&S and £206m for the Co-op. These arrests reduce, but do not eliminate, the operational threat given the alliance-affiliate model.
Weighting RH-ISAC and NCSC intelligence above vendor reporting, the analyst's view is that DragonForce, The Gentlemen, Qilin and Akira are the four actors of most operational significance to the vertical over the next two reporting cycles. The 07 Jul CISA KEV additions covering Joomla-based content management (CVE-2026-48908 JoomShaper SP Page Builder and CVE-2026-56290 Joomlack Page Builder) create a specific residual exposure across retailer marketing, campaign and comparison sites, many of which are still Joomla-based.
IP Insights enrichment shows the persistent perimeter brute-force tail continuing to be dominated by dmzhost, serverion, PPTECHNOLOGY and UAB Host Baltic ranges plus F3 Netze / for-privacy.net Tor exits.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
DragonForce / Scattered Spider cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, Muddled Libra, 0ktapus, DragonForce affiliate
- Suspected Origin: Anglophone (UK/US); further four arrests 10 Jul 2026 per NCA
- Suspected Sponsor: Organised criminal alliance / RaaS
- Primary Motivation: Financial (ransomware + data extortion)
- Sector Targeting: Retail, hospitality, telecoms, technology, real estate, manufacturing, construction, FS (payments)
- Geographic Focus: Anglophone western targets
- Signature TTPs: Voice-phishing IT service desk to reset MFA, help-desk social engineering, EDR bypass via legitimate RMM tooling, DragonForce Linux/ESXi ransomware, aggressive cloud-tenant pivot
- Tooling / Malware Families: DragonForce ransomware, Ngrok, AnyDesk, SplashTop, Impacket, Chisel
- Recent Activity: 7 leak-site postings in trailing 24h (Real Estate, Manufacturing, Construction focus); 4 additional UK arrests connected to M&S/Co-op/Harrods case 10 Jul 2026; alliance-affiliate operations continue
- Assessed Threat to Vertical: HIGH - social-engineering methodology transfers directly across verticals
- Analytic Confidence: HIGH
Qilin (a.k.a. Agenda)
- Aliases: Agenda, Qilin.B, Water Galura
- Suspected Origin: Russian-speaking (unattributed)
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion)
- Sector Targeting: Financial services, healthcare, manufacturing, retail, professional services, logistics
- Geographic Focus: Global; UK and EU disproportionately represented in H1 2026 leak-site postings
- Signature TTPs: Initial access via brokered credentials, Check Point VPN CVE-2026-50751 exploitation, RMM abuse (AnyDesk, SplashTop), PowerShell + Rust ransomware payload; ESXi Linux variant
- Tooling / Malware Families: Qilin.B ransomware (Rust), Cobalt Strike, Rclone-to-Mega, Mimikatz, SharpHound
- Recent Activity: 1,496 leak-site victims across trailing 12 months (dominant RaaS); 78 postings in June 2026 (temporarily overtaken by The Gentlemen at 115); continued CVE-2026-50751 exploitation reported this period
- Assessed Threat to Vertical: HIGH - dominant RaaS operator across UK/EU
- Analytic Confidence: HIGH
The Gentlemen
- Aliases: The Gentlemen (single-name RaaS brand)
- Suspected Origin: Unattributed (Russian-speaking assessed)
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion)
- Sector Targeting: Broad mid-market; disproportionately professional services, retail, healthcare, manufacturing
- Geographic Focus: Global; western Europe and North America dominant in June-July 2026 tally
- Signature TTPs: Initial access via brokered credentials, LOTL tooling, aggressive leak-site publication cadence, PowerShell + custom Rust payload
- Tooling / Malware Families: The Gentlemen ransomware (Rust), Rclone, PsExec, Cobalt Strike
- Recent Activity: 115 leak-site postings in Jun 2026 - highest of any single brand and first month above Qilin in over a year; sustained cadence into 04-10 Jul 2026
- Assessed Threat to Vertical: HIGH - fastest-growing RaaS brand
- Analytic Confidence: MEDIUM-HIGH
Akira
- Aliases: Akira, Storm-1567
- Suspected Origin: Russian-speaking (unattributed)
- Suspected Sponsor: Organised criminal RaaS
- Primary Motivation: Financial (double extortion)
- Sector Targeting: Manufacturing, professional services, mid-market FS, education, hospitality, logistics
- Geographic Focus: North America and Europe; UK and Ireland heavily represented in FY26 tally
- Signature TTPs: Cisco / Citrix VPN unpatched initial access, valid credentials from IABs, weak-MFA bypass, RDP lateral movement, ESXi hypervisor targeting
- Tooling / Malware Families: Akira ransomware (Rust / C++), Megazord ESXi variant, Cobalt Strike, Mimikatz, Rclone, AnyDesk
- Recent Activity: 1,205 leak-site victims across trailing 12 months; continued mid-cycle activity through 04-10 Jul 2026 per ransomware.live
- Assessed Threat to Vertical: HIGH - direct threat to mid-market back-office ESXi estates
- Analytic Confidence: HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Continued exploitation of CitrixBleed 3 follow-on (CVE-2026-8451, exploited within 24h of disclosure), SharePoint deserialisation (CVE-2026-45659, remediation deadline 04 Jul passed) and Ivanti Sentry (CVE-2026-10520). RH-ISAC member exchange during the period continues to prioritise Scattered Spider / DragonForce tradecraft as the dominant threat picture for UK retail, with the M&S / Co-op / Harrods long-tail (£300m and £206m loss estimates respectively) the anchor context. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts | Sustained OAuth / refresh-token replay against Microsoft 365 tenants sourced from UAB Host Baltic (141.98.10.0/24, 141.98.11.0/24) and rotating Tor egress; consistent with NCSC Anubis-affiliate tradecraft advisory this period | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | IcedID, Latrodectus and DarkGate loader chains via ISO/IMG/OneNote continued to dominate the phishing tail; volume steady week-on-week per Proofpoint and Sophos public telemetry | HIGH |
| Persistence | T1219 | Remote Access Software | Anubis-affiliate abuse of ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC and Total Software Deployment noted in NCSC advisory; RMM install-signal hunts remain the primary early-warning telemetry | HIGH |
| Discovery | T1046 | Network Service Discovery | Automated port sweeps from datacentre-hosted infrastructure - IP Insights flagged multiple AS209605 (HOSTBALTIC) and dmzhost sources in the perimeter tail this period | MEDIUM |
| Command and Control | T1071.001 | Application Layer Protocol: Web | Cobalt Strike, Sliver and Havoc HTTPS C2 beaconing observed in incident retrospectives via ISAC channels this period; JARM / JA3 fingerprint hunts remain the primary detection | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone-to-Mega and rclone-to-Backblaze exfiltration patterns dominant in Qilin, Akira, DragonForce and The Gentlemen double-extortion intrusions this period | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin, Akira, DragonForce and the newly-dominant The Gentlemen ransomware deployment observed against sector-adjacent peers per ransomware.live and ISAC reporting | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 10 Jul 2026 | M&S / Co-op / Harrods long-tail arrests | DragonForce / Scattered Spider (allegedly) | NCA arrests four further individuals in connection with the cluster on 10 Jul 2026, adding to the 30 Jun arrests; total loss estimates now £300m (M&S) and £206m (Co-op) | NCA / Cybersecurity Dive |
| 04-10 Jul 2026 | DragonForce victim tail | DragonForce | 7 leak-site postings in trailing 24h focused on real estate, manufacturing and construction adjacencies; retail-supplier overlap is material | Purple Ops / ransomware.live |
| 04-10 Jul 2026 | Sector peers | The Gentlemen | Continued leak-site cadence at record pace following June overtake of Qilin; UK retail mid-market victims noted in aggregate ransomware.live tracker | ransomware.live |
| Ongoing | SharePoint document-management estates | Unattributed | Rolling CVE-2026-45659 exposure; retail commercial teams commonly hold supplier contracts and buyer negotiations in SharePoint | CISA KEV / Microsoft |
| Ongoing | e-commerce and web-facing retail brands | Unattributed | CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Joomlack Page Builder) exposure across Joomla-based marketing and campaign sites | CISA KEV / vendor advisories |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-8451 | Citrix NetScaler ADC / Gateway - memory overread (CitrixBleed 3 follow-on) | 9.3 | Yes | Yes | Apply fixed builds 14.1-66.59 / 13.1-62.23 / 13.1-37.262 FIPS/NDcPP; must run 'kill icaconnection -all', 'kill pcoipConnection -all', 'kill aaa session -all' post-patch; exploited within 24h of 30 Jun disclosure |
| CVE-2026-45659 | Microsoft SharePoint Server SubEd / 2019 / 2016 - deserialisation RCE (rolling exposure from prior week) | 8.8 | Yes | Yes | Continue enforcement of 04 Jul CISA KEV deadline; audit Site Member permissions; hunt w3wp.exe children (cmd.exe / powershell.exe / rundll32.exe) under the SharePoint app pool; restrict /_layouts/15 uploader paths at the WAF |
| CVE-2026-10520 | Ivanti Sentry (formerly MobileIron Sentry) - unauthenticated OS command injection on admin interface | 9.8 | Yes | Yes | Apply Ivanti hotfix immediately; restrict admin interface to management VLAN; Shadowserver confirms exposed instances actively backdoored during the reporting period |
| CVE-2026-25089 | Fortinet FortiSandbox - unauthenticated command injection (FortiBleed activity cluster) | 9.8 | Yes | Yes | Upgrade to fixed FortiSandbox release train; segment FortiSandbox management interface; hunt for FortiBleed indicators including 74,000 stolen credential set referenced by NCSC and vendor reporting |
| CVE-2026-26083 | Fortinet FortiSandbox - additional unauthenticated command injection (paired with -25089) | 9.8 | Yes | Yes | As per CVE-2026-25089; both must be remediated together; unauthenticated pre-condition removes any residual doubt about exposure |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile - unauthenticated RCE (limited targeted exploitation) | 9.2 | Yes | Yes | Apply Ivanti EPMM hotfix; restrict admin interface; enable audit logging on device-registration workflows |
| CVE-2026-48908 | JoomShaper SP Page Builder (Joomla) - unrestricted file upload of dangerous type | 9.8 | Yes | Yes | Update SP Page Builder / Joomla installations; audit uploads directory for webshells; added to CISA KEV 07 Jul 2026 |
| CVE-2026-55255 | Langflow - authorisation bypass through user-controlled key | 9.1 | Yes | Yes | Upgrade Langflow to patched release; restrict LLM-tooling admin interfaces to internal networks; added to CISA KEV 07 Jul 2026 |
| CVE-2026-56290 | Joomlack Page Builder (Joomla) - improper access control on administration endpoints | 9.1 | Yes | Yes | Update the extension immediately; restrict administrator paths at the WAF; added to CISA KEV 07 Jul 2026 |
| CVE-2026-50751 | Check Point Security Gateway - improper authentication (Qilin-affiliate exploitation reported) | 9.8 | Yes | Yes | Apply Check Point R81.20 / R81.10 / R80.40 hotfixes; hunt admin sessions from non-management source addresses; Qilin affiliates observed leveraging as initial-access |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]101[.]34 | 05 Jul 2026 | HIGH | for-privacy.net Tor exit (185.220.101.0/24); IP Insights score 100 / critical; 8 blacklists; observed in credential-spray tail against Entra ID sign-in endpoints |
| IP | 45[.]148[.]10[.]240 | 06 Jul 2026 | HIGH | dmzhost bulletproof (45.148.10.0/24); IP Insights score 100 / critical; 5 active blacklists including SSH/Telnet Brute Force honeypot capture; SSH / RDWeb brute-force tail |
| IP | 92[.]118[.]39[.]203 | 07 Jul 2026 | HIGH | dmzhost / PPTECHNOLOGY LIMITED (UK/NL, 92.118.39.0/24); IP Insights score 85 / critical; 4 blacklists; Exchange OWA credential-spray tail |
| IP | 194[.]180[.]48[.]18 | 08 Jul 2026 | MEDIUM | serverion (NL, 194.180.48.0/24); IP Insights score 85 / critical; ThreatFox and malicious-outgoing-ip listings; SSH brute-force tail against perimeter jump hosts |
| IP | 141[.]98[.]10[.]140 | 09 Jul 2026 | MEDIUM | UAB Host Baltic AS209605 (LT, hostname pivotsudo-leang.outreachratio.com); IP Insights score 95 / critical; AbuseIPDB s100 30d listing; datacentre-hosted scripted attack traffic |
| IP | 141[.]98[.]11[.]90 | 10 Jul 2026 | LOW | UAB Host Baltic AS209605 (LT); IP Insights score 10 / low but datacentre-flagged; observed as source of scripted OAuth token replay against Microsoft 365 tenants |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| DragonForce / Scattered Spider help-desk voice-phishing intrusion into a monitored UK retail brand | H | H | CRITICAL |
| CVE-2026-48908 / CVE-2026-56290 webshell deployment against Joomla-based retailer sites | H | M | HIGH |
| Ransomware deployment via CitrixBleed 3 follow-on session-token theft | M | H | HIGH |
| Rolling SharePoint (CVE-2026-45659) exposure of supplier contracts and buyer negotiations | M | H | HIGH |
| BEC / vendor payment redirect targeting retail buying and merchandising function | H | H | CRITICAL |
| Ransomware follow-on from Qilin, The Gentlemen and Akira against retail mid-market | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the DragonForce / Scattered Spider help-desk voice-phishing playbook as the principal hunting hypothesis for the vertical. Hunt for anomalous MFA reset patterns, particularly out-of-hours or from unusual geographies, cross-referenced against IT service-desk call logs; instrument the service desk to alert on password- and MFA-reset requests without corroborating identity verification. Deploy web-server hunts against Joomla /administrator/, /components/com_sppagebuilder/ and file-upload path patterns for CVE-2026-48908 and CVE-2026-56290. Retain SharePoint w3wp.exe process-tree hunts. Deploy IP Insights critical-tail block / alert lists to WAF and Entra ID Conditional Access.
Defend
Preventive priorities follow Section 6 directly. Update Joomla and all SP Page Builder / Joomlack Page Builder installations immediately. Complete NetScaler CVE-2026-8451 patching with session invalidation. Verify CVE-2026-45659 SharePoint patching. Restrict IT service-desk password- and MFA-reset workflows to require verified identity checks (video, callback to registered numbers, out-of-band token). Enforce phishing-resistant MFA on all retail buying-function and merchandising accounts to protect vendor-payment workflows. Complete FortiSandbox patching (CVE-2026-25089 / -26083). Review NCSC retail-sector guidance.
Disrupt
Disruption activity within client lawful authority should focus on: (i) sustained participation in RH-ISAC member exchange, with this week's IP Insights critical / block tail submitted as the highest-value contributable; (ii) honeypot deployment fronting Joomla admin paths and NetScaler Gateway; (iii) coordinated take-down requests via NCSC Takedown Service; (iv) proactive briefing of IT service desks on voice-phishing tradecraft, ideally with a live tabletop exercise; (v) close liaison with NCSC and NCA on the M&S / Co-op / Harrods cluster follow-on activity.
10. Forward outlook
Looking forward to the next reporting period (11 Jul - 17 Jul 2026), it is likely that at least one further UK retail brand will publicly disclose an intrusion, given the sustained DragonForce / Scattered Spider tempo despite arrests. It is highly likely that at least one Joomla-based retailer site will be exploited via CVE-2026-48908 or CVE-2026-56290 given the 07 Jul KEV listing and typical patching lag. Ransomware leak-site cadence from DragonForce, The Gentlemen, Qilin and Akira is expected to remain steady week-on-week.
Trigger conditions that would prompt revision of this outlook include: (a) a UK retail brand publicly attributing a breach to CVE-2026-8451, CVE-2026-45659, CVE-2026-48908 or CVE-2026-56290, which would warrant immediate out-of-cycle reporting; (b) further NCA arrests materially changing the DragonForce / Scattered Spider alliance-affiliate operational picture; (c) further CISA KEV additions materially affecting retail-sector infrastructure or e-commerce plugins; (d) any confirmed intrusion against a monitored retail client attributable to the actors profiled in Section 3.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities catalogue (daily updates) | CISA | A1 |
| 3 | CISA KEV addition of CVE-2026-48908, -55255, -56290 (07 Jul 2026) | CISA | A1 |
| 4 | CISA KEV entry rolling forward for CVE-2026-45659 (SharePoint deserialisation) | CISA / Microsoft | A1 |
| 5 | Citrix Security Bulletin - CVE-2026-8451 (CitrixBleed follow-on) memory overread | Citrix / Cloud Software Group | A2 |
| 6 | Ivanti Security Advisory - CVE-2026-10520 (Sentry unauthenticated command injection) | Ivanti | A2 |
| 7 | Shadowserver Foundation - Ivanti Sentry active-backdoor reporting | Shadowserver Foundation | A1 |
| 8 | Fortinet PSIRT - CVE-2026-25089 and CVE-2026-26083 (FortiSandbox unauthenticated command injection) | Fortinet | A2 |
| 9 | FortiBleed campaign reporting - 74,000 stolen credentials, 12 confirmed ransomware infections | Cyprus Shipping News / vendor reporting | B2 |
| 10 | Ivanti EPMM CVE-2026-6973 limited targeted exploitation advisory | Ivanti / The Hacker News | B2 |
| 11 | NCSC Anubis ransomware advisory (VPN credential abuse and RMM tradecraft) | National Cyber Security Centre | A1 |
| 12 | NCSC advisory - action following Middle East conflict escalation | National Cyber Security Centre | A1 |
| 13 | SonicWall - 10x surge in IPS events across UK hospitals Jan-May 2026 (264k events) | SonicWall / Enterprise Times | B2 |
| 14 | ransomware.live daily leak-site tracker (Qilin, Akira, DragonForce, The Gentlemen) | ransomware.live | B2 |
| 15 | Qilin ransomware 2026 profile - 1,496 leak-site victims trailing 12 months; CVE-2026-50751 exploitation | MOXFIVE / Infosecurity Magazine | B2 |
| 16 | Akira ransomware profile - 1,205 leak-site victims trailing 12 months | SOCRadar / Infosecurity Magazine | B2 |
| 17 | DragonForce ransomware - 7 victims in a 24h period; Real Estate / Manufacturing / Construction focus | Purple Ops | B2 |
| 18 | The Gentlemen ransomware overtakes Qilin in Jun 2026 (115 vs 78 victims) | Cybereason / Infosecurity Magazine | B2 |
| 19 | NCA arrests four further UK nationals connected to M&S / Co-op / Harrods cluster (10 Jul 2026) | National Crime Agency / Cybersecurity Dive | A1 |
| 20 | Google Cloud - Threats to the Defense Industrial Base (2026 update) | Google Cloud / Mandiant | A2 |
| 21 | NCSC Cyber Threat Report - UK Legal Sector | National Cyber Security Centre | A1 |
| 22 | NCSC Cyber Threat Report - UK Charity Sector | National Cyber Security Centre | A1 |
| 23 | Adriatic Port Authority - Anubis ransomware intrusion ($10m demand) | Industrial Cyber / Resecurity | B2 |
| 24 | Maritime cyber incidents 2025 - 103% year-on-year increase (retro reference) | SAFETY4SEA / CYTUR | B2 |
| 25 | Cybersecurity Breaches Survey 2025/2026 - UK statutory dataset | DSIT / GOV.UK | A1 |
| 26 | FS-ISAC daily indicator exchange (member portal - TLP:CLEAR) | FS-ISAC | A1 |
| 27 | H-ISAC daily bulletin (member portal - TLP:CLEAR) | H-ISAC | A1 |
| 28 | MTS-ISAC daily bulletin and Cyware indicator exchange (TLP:CLEAR) | MTS-ISAC | A1 |
| 29 | RH-ISAC member exchange (TLP:CLEAR) | Retail and Hospitality ISAC | A1 |
| 30 | Space ISAC / National Council of ISACs bulletins (TLP:CLEAR) | NCI / Space ISAC | A1 |
| 31 | IP Insights REST API enrichment (multiple lookups during the reporting period, week ending 10 Jul 2026) | IP Insights / UK Cyber Defence Ltd | A1 |
| 33 | NCSC blog - Incidents impacting retailers (recommendations) | National Cyber Security Centre | A1 |
| 34 | How UK Retail responded to the Scattered Spider hack wave (Infosecurity Magazine) | Infosecurity Magazine | B2 |
| 35 | Retail Ransomware Attacks Jump 58% Globally in Q2 2025 (Infosecurity Magazine) | Infosecurity Magazine | B2 |
| 36 | M&S, Co-op & Harrods cyber-attacks - lessons for retailers (Brabners) | Brabners | C2 |
| 37 | Cybersecurity Dive - UK authorities warn of retail-sector risks | Cybersecurity Dive | B2 |
| 38 | RH-ISAC member exchange (TLP:CLEAR) | Retail and Hospitality ISAC | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Retail Threat Intelligence Briefing
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Retail threat intelligence report — 27 April – 3 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025, which has been classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m.
Retail threat intelligence report — 4–8 May 2026
The retail vertical continues to operate in the wake of the Marks & Spencer / Co-op / Harrods cyber-attack wave of spring 2025 — classed as a Category 2 cyber-event with combined cost estimates of £270m–£440m…