Trade bodies and membership organisations threat intelligence report — 4–8 May 2026
The trade-body and membership-organisation threat picture for the reporting period continues to be dominated by phishing and ransomware against organisations holding member-PII at scale, augmented by Russian state-aligned hacktivist activity targeting representative bodies for political signalling.
- Reference: TI-2026-0508-007 (public edition)
- Sector: Trade bodies and membership organisations
- Reporting period: 4–8 May 2026
- Issued: 8 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The trade-body and membership-organisation threat picture for the reporting period continues to be dominated by phishing and ransomware against organisations holding member-PII at scale, augmented by Russian state-aligned hacktivist activity targeting representative bodies for political signalling. The UK Cyber Security Breaches Survey 2025/2026 continues to report 28 per cent of charities experiencing a cyber incident in the past year, with phishing the dominant disruptive incident type. The single most operationally-significant development inside the reporting window is NCSC's 4 May 2026 blog on the AI-accelerated patch wave; this matters for a vertical that has historically had patchy patch-cadence and significant cloud-platform exposure.
The Kokoro / About Loyalty supplier breach (sustained reporting through Q1–Q2 2026) — affecting RSPCA, Shelter, Dogs Trust, Battersea, Friends of the Earth and other major UK charities, with ICO investigation continuing — and the joint ICO / Channel-Islands DPA investigation into the Prospect trade union breach (160,000 members; financial, sensitive and trade-union-membership data) remain the operational reference cases for vertical-specific supplier and member-PII risk.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that phishing and ransomware against trade bodies and membership organisations holding member-PII at scale will continue at sustained tempo over the next reporting cycle, and that the Kokoro / About Loyalty pattern of supplier-mediated compromise will be replicated against other charity / membership data-processing suppliers within the next two reporting cycles. (HIGH confidence)
- It is likely that Russian state-aligned hacktivist activity will continue to target UK representative bodies for political signalling, particularly those representing sectors aligned with Ukraine support or Russia-sanctions enforcement. (MEDIUM-HIGH confidence)
- It is likely that the operational and reputational cost of a member-PII breach for a trade body — given the political sensitivity of the membership lists for some bodies, illustrated by the Prospect trade union case — will exceed the immediate financial and regulatory cost in any prosecution-of-membership scenario. (MEDIUM-HIGH confidence)
- It is likely that the AI-accelerated patch-wave dynamic flagged by NCSC on 4 May 2026 will produce at least one nationally-significant exploitation event across the vertical within the next two reporting cycles, particularly through Citrix NetScaler, Ivanti EPMM or PAN-OS User-ID portal exposure. (MEDIUM confidence)
- There is a realistic possibility that AI-assisted phishing tradecraft will materially improve the success rate of member-impersonation attacks against the customer-services / member-engagement functions of larger trade bodies, mirroring the helpdesk social-engineering tradecraft templated in the M&S / Co-op campaign. (MEDIUM confidence)
2. Sector threat landscape
Trade bodies and membership organisations sit at an unusual intersection in the threat landscape. The UK Cyber Security Breaches Survey 2025/2026 continues to report 28 per cent of charities experiencing a cyber incident in the past year; phishing remains the dominant disruptive incident type.
The Kokoro / About Loyalty supplier breach is the operational reference case for the period. The breach — affecting RSPCA, Shelter, Dogs Trust, Battersea, Friends of the Earth and other charities served by the consultancy About Loyalty's research partner Kokoro — exposed supporter names, email addresses and historic donation information, and is now under ICO investigation. About Loyalty works with more than 40 UK charities; the wider exposure footprint is still being characterised. Shelter's prompt notification to the ICO and the Charity Commission and decision to pause work with the supplier is the recommended template for downstream charity response.
The Prospect trade union breach (June 2025; 160,000 members) is now the subject of a joint investigation by the ICO and the Data Protection Authorities of Jersey, Guernsey and the Isle of Man. Prospect's membership includes scientists, engineers and technology specialists, and the breach touched financial information, trade-union-membership status, ethnic origin, sexual orientation, disability and religious belief — exemplifying the special-category data risk inherent in the vertical and providing a template for political-sensitivity-driven targeting.
The April 2026 ransomware leak-site picture (Breachsense, ransomware.live) — 772 victims across 70 groups — does not show charities or trade bodies as a leading target subset, but Akira (69 April postings, 1,299 historical) consistently presents in mid-market victimology with charities and trade bodies represented in the broader sample. Cl0p / ShinyHunters / WorldLeaks data-extortion against trusted file-transfer / SaaS platforms is operationally relevant to any trade body running CRM or member-engagement-platform integrations with file-transfer dependencies.
Edge-appliance exposure is a sub-dominant but real concern. The Citrix NetScaler / Ivanti EPMM / PAN-OS User-ID patch wave matters for any trade body running its own remote-access infrastructure; for cloud-only operators the patch posture of their SaaS providers becomes the dominant gating factor. NCSC's 4 May 2026 blog is the recommended client-facing reference for the wider patch-wave context.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Akira
- Aliases: —
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware
- Sector Targeting: Mid-market across professional services, charities, trade bodies, manufacturing
- Geographic Focus: Global; consistent UK activity
- Signature TTPs: Stolen-credential and edge-appliance initial access; double-extortion model
- Tooling / Malware Families: Akira encryptor; native admin tooling
- Recent Activity: 69 April 2026 leak-site postings (1,299 historical); consistent mid-market presence in trade-body / charity victim subset
- Assessed Threat to Vertical: MEDIUM-HIGH
- Analytic Confidence: MEDIUM-HIGH
Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Charities, professional services, healthcare, financial services
- Geographic Focus: Global
- Signature TTPs: Stolen / brute-forced credential access; abuse of remote-management tooling; double extortion
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptors
- Recent Activity: 103 April 2026 leak-site postings — fourth consecutive month leading
- Assessed Threat to Vertical: MEDIUM
- Analytic Confidence: MEDIUM-HIGH
Cl0p / ShinyHunters / WorldLeaks cluster
- Aliases: TA505 (Cl0p)
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal
- Primary Motivation: Financial — pure data extortion
- Sector Targeting: Any vertical operating exposed managed file-transfer or SaaS platforms — including charity CRM and member-engagement platforms
- Geographic Focus: Global
- Signature TTPs: Mass-exploitation of file-transfer / SaaS platform CVEs; pure data extortion without encryption
- Tooling / Malware Families: Custom web shells; Truebot loader
- Recent Activity: MOVEit Automation CVE-2026-4670 active-exploitation reporting realigns operator signature with charity / trade-body trust platforms
- Assessed Threat to Vertical: MEDIUM-HIGH — disproportionate impact-per-campaign for orgs with shared CRM / member SaaS
- Analytic Confidence: MEDIUM-HIGH
Russian state-aligned hacktivist clusters
- Aliases: NoName057(16), Killnet successors, various
- Suspected Origin: Russia-aligned
- Suspected Sponsor: State-aligned hacktivist; mixed with criminal infrastructure
- Primary Motivation: Disruption — political signalling
- Sector Targeting: Government, representative bodies, charities aligned with Ukraine support / Russia-sanctions enforcement
- Geographic Focus: UK, EU, NATO-aligned
- Signature TTPs: DDoS against public-facing portals; web-defacement; opportunistic compromise
- Tooling / Malware Families: Open-source DDoS tooling; commodity loaders
- Recent Activity: Sustained DDoS activity against UK and EU representative-body portals during the reporting period
- Assessed Threat to Vertical: MEDIUM
- Analytic Confidence: MEDIUM
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1199 | Trusted Relationship | Kokoro / About Loyalty supplier-mediated breach affecting RSPCA, Shelter, Dogs Trust, Battersea, Friends of the Earth — operational reference case. | H |
| Initial Access | T1566.002 | Spearphishing Link | Sustained AI-assisted phishing tradecraft against member-services and fundraising inboxes. | H |
| Initial Access | T1133 | External Remote Services | Citrix NetScaler / Ivanti EPMM / PAN-OS additions to KEV expose any trade body running its own remote-access infrastructure. | M |
| Initial Access | T1190 | Exploit Public-Facing Application | MOVEit Automation CVE-2026-4670 of relevance to charities and trade bodies running CRM / member-engagement integrations. | M |
| Collection | T1213.002 | Data from Information Repositories: SharePoint | Member-PII collection from cloud-collaboration platforms — recurring sector-specific risk. | M |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Cl0p / ShinyHunters pattern of bulk exfiltration prior to leak-site posting. | M |
| Impact | T1486 | Data Encrypted for Impact | Akira, Qilin affiliates continue to deploy encryptors against charity / trade-body estates at scale. | M |
| Impact | T1499 | Endpoint Denial of Service | Russian state-aligned hacktivist DDoS against UK representative-body portals. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Sustained 2026 | Kokoro / About Loyalty supplier breach | Unattributed (criminal) | RSPCA, Shelter, Dogs Trust, Battersea, Friends of the Earth and others affected; supporter names, email addresses, historic donation data exposed; ICO investigating; About Loyalty works with 40+ UK charities | Civil Society; ICO |
| June 2025 (active investigation) | Prospect trade union (UK) | Unattributed (criminal) | 160,000 members; financial, sensitive and trade-union-membership data; joint ICO / Jersey / Guernsey / Isle of Man investigation announced | ICO |
| May 2026 | Vulnerability patch wave (sector-wide) | Multiple | NCSC 4 May 2026 blog warns AI-accelerated vulnerability discovery is shrinking time-to-weaponisation | NCSC; CISA |
| May 2026 | Multiple charity / trade-body leak-site listings (global) | Akira, Qilin, Cl0p | Charity / trade-body subset of the 772 April leak-site victims; consistent with mid-market baseline | Ransomware.live; Breachsense |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline 10 May; rotate admin sessions |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation | 9.8 | Pending | Yes | Patch; audit CRM / member-engagement MFT operator authentication |
| CVE-2026-22679 | Weaver E-Cology | 9.8 | — | Yes | Patch; restrict OA platform to internal networks |
| CVE-2026-41940 | WebPros cPanel / WP Squared / WHM | 9.8 | — | Yes | Patch; audit panel admin auth events on hosted-website estates |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 87[.]103[.]126[.]54 | 30 Apr 2026 | H | SSH brute-force — Vodafone PT (AS12353); IP Insights threat 100/critical, 6 active blacklists |
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 6 active blacklists |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298); cross-tenant scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net); 7 active blacklists |
| ASN | AS200651 | Ongoing | H | FlokiNET — 110/132 known IPs blacklisted; bulletproof-style hosting consistently observed in charity-themed phishing infrastructure |
| Pattern | Supplier-mediated supporter-PII exfiltration | Sustained 2026 | H | Kokoro / About Loyalty reference case — supplier-management is the highest-leverage control |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Supplier-mediated member-PII compromise (Kokoro pattern) | H | H | CRITICAL |
| Ransomware deployment via stolen-credential access against CRM / member-engagement estate | M | H | HIGH |
| Pure data extortion via shared CRM / member SaaS platform compromise (MOVEit pattern) | M | H | HIGH |
| AI-assisted phishing of fundraising and member-services inboxes leading to BEC | H | M | HIGH |
| DDoS / web-defacement from state-aligned hacktivist clusters against politically-sensitive representative bodies | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on two concurrent themes. First, supplier-management telemetry — outbound CRM / member-engagement platform integration logs, supplier-system identity drift, and behavioural anomaly detection on supplier-mediated bulk data access (the Kokoro reference case). Second, cloud-platform identity controls — anomalous login geolocation, MFA-bypass attempts, and OAuth-grant drift across Microsoft 365 / Google Workspace tenancies. The Charity Commission's Cyber Security Toolkit and the National Council for Voluntary Organisations (NCVO) sector guidance remain the highest-value sector references.
Defend
Supplier-management controls and identity controls are the two highest-leverage defensive priorities. Supplier-management should require ICO breach-notification clauses, supplier-side MFA on all administrator and engineering accounts, and contractually-anchored incident-response cooperation — all reinforced by the Kokoro reference case. MFA on every privileged identity, with phishing-resistant assurance for fundraising and member-services accounts, is non-negotiable. The Citrix NetScaler / Ivanti EPMM / PAN-OS patch-wave should be circulated to all clients running their own remote-access infrastructure. ISO/IEC 27001 Annex A 5.18, 5.19 (information security in supplier relationships), 8.5 and 8.7 are the relevant references; in the UK the Charity Commission's published cybersecurity guidance and the Fundraising Regulator's Code of Fundraising Practice provide authoritative sector-specific references.
Disrupt
Disruption priorities are concentrated in three areas. First, indicator sharing within CiSP and any sector-specific trust group (NCVO, Fundraising Regulator, Charity Finance Group). Second, takedown coordination on phishing infrastructure attributable to AS200651 (FlokiNET), particularly any charity-impersonation kits used in the post-Kokoro environment. Third, tabletop exercise activity covering the supplier-mediated breach scenario at member-PII scope, with explicit ICO breach-notification timing rehearsal.
10. Forward outlook
It is highly likely that supplier-mediated member-PII compromise will continue to be the principal material-risk scenario for the vertical over the next reporting cycle, with the Kokoro / About Loyalty pattern likely to be replicated against other charity / membership data-processing suppliers within the next two reporting cycles. It is likely that AI-assisted phishing tradecraft will materially improve the success rate of member-impersonation attacks against the customer-services / member-engagement functions of larger trade bodies.
Trigger conditions warranting forecast revision: emergence of a new state-aligned hacktivist cluster with explicit UK-charity victimology; ICO action against a major UK charity or trade body for breach-notification failure; or material change in the Cl0p / ShinyHunters operational tempo against charity / trade-body trust platforms. Intelligence gaps to close: independent corroboration of the wider Kokoro / About Loyalty exposure footprint, and identification of additional shared-supplier dependencies across the UK charity sector.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Preparing for a vulnerability patch wave (4 May 2026 blog) | NCSC | A2 |
| 2 | NCSC Annual Review 2025 – ransomware and nationally significant incidents | NCSC | A1 |
| 3 | UK Cyber Security Breaches Survey 2025/2026 (DSIT) | GOV.UK | A1 |
| 4 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 5 | CISA Alert – Ivanti EPMM CVE-2026-6973 added to KEV (1 May 2026) | CISA | A1 |
| 6 | CISA Alert – Palo Alto PAN-OS CVE-2026-0300 added to KEV (6 May 2026) | CISA | A1 |
| 7 | Breachsense – April 2026 Ransomware Report (772 victims, 70 groups) | Breachsense | B2 |
| 8 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 9 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
| 11 | Civil Society – Major charities reassure supporters as regulators assess data breach (Kokoro / About Loyalty) | Civil Society | B2 |
| 12 | ICO – Joint investigation into Prospect trade union breach (160,000 members) | ICO | A1 |
| 13 | ICO – Charity fines and breach data | ICO | A1 |
| 14 | GOV.UK – Cyber Security Breaches Survey 2025/2026 (charity statistics) | DSIT | A1 |
| 15 | Cyber News Centre – UK Survey Shows Phishing Still Owns the Breach Economy (May 2026) | Cyber News Centre | C2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Trade bodies and membership organisations threat intelligence report — 11–17 July 2026
The trade body and membership organisation vertical continues to be shaped by three structural characteristics that shape the threat picture: (i) the sector holds sensitive membership registers, financial information (dues, event bookings…
Trade bodies and membership organisations threat intelligence report — 27 April – 3 May 2026
The trade-body and membership-organisation threat picture for the reporting period is dominated by phishing and ransomware against organisations holding member-PII at scale, augmented by Russian state-aligned hacktivist activity targeting representative bodies for political signalling.
Trade bodies and membership organisations threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the trade-body and membership-organisation threat picture remained dominated by data-extortion incidents against organisations holding large volumes of personal data on members, including financial, ethnicity, sexual-orientation…