Trade bodies and membership organisations threat intelligence report — 23–29 May 2026
Trade bodies and membership organisations sit at the intersection of three distinct threat pressures: criminal cyber operators attracted by the relatively high-value, low-friction donor and member personal-data holdings…
- Reference: TI-2026-0529-007 (public edition)
- Sector: Trade bodies and membership organisations
- Reporting period: 23–29 May 2026
- Issued: 29 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Trade Bodies and Membership Organisations vertical during the period 23 May 2026 to 29 May 2026. Trade bodies and membership organisations sit at the intersection of three distinct threat pressures: criminal cyber operators attracted by the relatively high-value, low-friction donor and member personal-data holdings; nation-state actors interested in the policy-influence and intelligence-collection opportunities the sector represents; and hacktivist activity tied to the political positions of individual organisations. The week's collection picture is shaped by edge-appliance exploitation pressure, sustained phishing and OAuth consent-phish activity against member-facing M365 tenants, and continued ransomware leak-site cadence from Qilin, Akira, DragonForce and TheGentlemen. The Instructure / Canvas breach affecting approximately 9,000 institutions in May 2026 is the most recent education-and-membership-adjacent supply-chain anchor. Sources are graded against the Admiralty System.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that phishing-driven account compromise against member-facing M365 tenants will continue to drive the highest-frequency category of incident against the vertical over the next reporting cycle, with credential-theft via AiTM phishing the dominant vector. (HIGH confidence)
- It is highly likely that ransomware operators — Qilin, Akira, DragonForce and TheGentlemen — will continue to target mid-tier UK and EU trade bodies and membership organisations over the next reporting cycle, with member-database and donor-data exposure the operational consequence. (HIGH confidence)
- It is likely that nation-state intelligence interest in trade bodies engaged in policy advocacy on sanctions, defence, technology export or strategic-resource positioning will continue, with China-, Russia- and Iran-nexus collection the most active. (MEDIUM confidence)
- It is likely that Russian-aligned hacktivist DDoS or defacement activity will continue to target UK trade bodies and membership organisations taking visible positions on Ukraine, sanctions or geopolitical alignment. (MEDIUM confidence)
- There is a realistic possibility that the Instructure / Canvas May 2026 breach pattern will produce additional follow-on supply-chain disclosures across membership-platform SaaS over the next two reporting cycles. (MEDIUM confidence)
2. Sector threat landscape
Trade bodies, professional institutes and membership organisations occupy a distinctive position in the threat landscape: they hold concentrated personal data (member directories, qualification records, donor records, voting and conference data), they frequently operate under-resourced IT functions relative to the value of the data they hold, and they take public positions on policy issues that occasionally attract hacktivist and state-aligned attention. The result is a sustained criminal and nation-state interest in the vertical that is rarely visible in the dominant ransomware-leak-site reporting but is operationally consequential nonetheless.
The phishing and account-compromise category dominates by frequency. ICAEW's May 2026 UK survey confirms phishing remains the most prevalent UK cyber-attack category, with 38% of businesses and 25% of charities reporting phishing attacks in the prior twelve months — and trade bodies and membership organisations typically operate under one or both of those categorisations. The Cybernews Centre 1 May coverage reaffirmed that phishing 'owns the breach economy' in the UK SME-and-charity segment. AiTM phishing pages mimicking M365 sign-in, OAuth consent-phishing against member-services mailboxes, and session-token theft leading to bulk-mailbox Graph-API download are the dominant operational patterns.
Ransomware leak-site activity continues at sustained Q1 2026 cadence. Qilin, Akira, DragonForce and TheGentlemen have each posted new victims in the week of 24 May, including Global Retool Group on the Qilin leak-site (24 May, Business Services) and Sunrise Company cross-posted to Akira and Qilin (week of 26 May). Mid-tier trade bodies sit in the same risk envelope as professional-services firms and small-to-medium businesses generally — the operational profile of member-portal compromise leading to ransomware deployment via IAB front-end is well-established.
Supply-chain exposure across membership-platform SaaS continues to be a significant theme. The Instructure / Canvas breach affecting approximately 9,000 institutions across the US, Canada, Australia and the UK in early May 2026 is the most recent education-and-membership-adjacent supply-chain anchor; trade bodies running educational or qualification-platform exposure to Canvas should have completed an impact-assessment and member-notification by the reporting date. Other membership-platform SaaS, donor-management and conference-platform tools should be reviewed against the same supply-chain pattern over the next reporting cycle.
Edge-appliance exploitation pressure applies acutely to the vertical because mid-tier membership organisations frequently operate small but materially-exposed on-prem estates with limited patching cadence. Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Microsoft Exchange OWA CVE-2026-42897, Trend Micro Apex One CVE-2026-34926 and Citrix NetScaler CVE-2026-3055/4368 all carry critical or high-impact risk in this segment. Exchange OWA is particularly relevant because trade bodies have historically been slow to migrate fully to Exchange Online and frequently retain OWA exposure for member-services and board correspondence.
Nation-state intelligence collection against the vertical is harder to characterise precisely but persists. Trade bodies engaged in policy advocacy on sanctions, defence, technology export controls, strategic-resource positioning, or membership-aligned international campaigns frequently surface in vendor reporting as collection targets. The CISA / FBI / NSA May 2026 advisory on Russian state-sponsored campaigns against technology and logistics entities, ESET's 28 May APT activity report, and the persistent China-nexus reporting from Mandiant, Microsoft and CrowdStrike collectively place a sustained collection-effort baseline against the vertical that would be imprudent to discount.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial — extortion / data theft
- Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential initial access via IABs; rapid DCSync; ESXi-aware encryptor; double-extortion with leak-site countdown
- Tooling / Malware Families: Qilin.B encryptor (Rust/Go), SystemBC, AnyDesk, Cobalt Strike, mimikatz, rclone
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
- Analytic Confidence: HIGH — multiply sourced (Check Point Research, FS-ISAC exchange, Ransomware.live)
Akira
- Aliases: —
- Suspected Origin: Russia-aligned criminal milieu
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial — encryption + extortion
- Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
- Geographic Focus: Global; SMB and mid-market heavy
- Signature TTPs: Cisco VPN account abuse without MFA; rapid AD reconnaissance; ESXi targeting; brand-pressure leak-site
- Tooling / Malware Families: Akira encryptor (Rust); RustDesk; AnyDesk; rclone; PCHunter; Mimikatz
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
- Analytic Confidence: HIGH
Russian-aligned hacktivist (NoName057(16) / Killnet successor clusters)
- Aliases: NoName057(16), Killnet successors, Cyber Army of Russia
- Suspected Origin: Russian-speaking volunteer milieu
- Suspected Sponsor: Hacktivist — aligned with Russian strategic interest
- Primary Motivation: Disruption; brand-damage; ideological
- Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
- Geographic Focus: UK, EU, NATO members supporting Ukraine
- Signature TTPs: Volumetric DDoS against public-facing services; defacement; leak claims of dubious provenance
- Tooling / Malware Families: DDoSia and similar booter ecosystems; Telegram coordination
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. HIGH
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
- Analytic Confidence: HIGH
TheGentlemen
- Aliases: —
- Suspected Origin: Unattributed (likely Russian-speaking criminal milieu)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial — extortion
- Sector Targeting: Cross-sector with sustained Trade Bodies, Membership Organisations relevance.
- Geographic Focus: Cross-sector, global
- Signature TTPs: Rapid affiliate onboarding; multi-platform encryptor (Windows/Linux/BSD/NAS); SystemBC C2
- Tooling / Malware Families: Go-based encryptor; SystemBC; partner-supplied IAB access
- Recent Activity: Reporting cycle: see Section 5 incidents and Section 2 landscape paragraphs. MEDIUM-HIGH
- Assessed Threat to Vertical: HIGH — actor's pattern is materially relevant to the named vertical in the reporting period. Admiralty B2.
- Analytic Confidence: MEDIUM-HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1566.002 | Spear-phishing Link | AiTM phishing pages mimicking M365 sign-in against member-services mailboxes; OAuth consent-phishing. | HIGH |
| Initial Access | T1566.001 | Spear-phishing Attachment | Donor-, membership- and conference-themed phishing with weaponised PDF / DOCX attachments. | HIGH |
| Initial Access | T1190 | Exploit Public-Facing Application | Cisco SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973, Exchange OWA CVE-2026-42897, Apex One CVE-2026-34926, Citrix NetScaler CVE-2026-3055/4368 against unpatched internet-facing tiers. | HIGH |
| Initial Access | T1199 | Trusted Relationship | Membership-platform SaaS supplier compromise (Canvas / member-management SaaS pattern). | MEDIUM |
| Credential Access | T1539 | Steal Web Session Cookie | Session-token theft from AiTM phishing; reuse against M365 / SharePoint / OneDrive. | HIGH |
| Persistence | T1098.002 | Account Manipulation: Additional Email Delegate Permissions | Attacker-controlled mailbox-delegate grants to maintain access in member-services mailbox. | HIGH |
| Collection | T1114.002 | Email Collection: Remote Email Collection | Bulk-download of member correspondence and donor data via Graph API. | MEDIUM |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGA / AzCopy egress of member and donor data prior to ransomware stage. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin.B / Akira / DragonForce ESXi-aware encryption of small-to-mid-tier hypervisor estates. | HIGH |
| Impact | T1498 | Network Denial of Service | Russian-aligned hacktivist DDoS against UK trade-body and membership-organisation public-facing services taking visible positions on Ukraine or sanctions. | MEDIUM |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Early May 2026 | Instructure / Canvas — supply-chain breach affecting ~9,000 institutions | Unattributed | Approximately 9,000 educational and membership institutions affected across US, Canada, Australia and UK; supply-chain anchor for the vertical. | ANY.RUN / Hackmageddon |
| 24 May 2026 | Global Retool Group (Business Services, trade-body-adjacent) | Qilin | Posted to Qilin leak-site 24 May; data-extortion ongoing. | Ransomware.live |
| Week of 26 May 2026 | Sunrise / Toscana / Andalusia Country Club (membership organisations, US) | Qilin | Multiple membership-club victims posted to Qilin leak-site week of 26 May; operational case study. | Ransomware.live |
| Ongoing | ICAEW May 2026 UK phishing survey | Multiple criminal | 38% of UK businesses and 25% of charities reported phishing attacks in prior twelve months; sector baseline. | ICAEW |
| 28 May 2026 | ESET APT Activity Report | Multiple — Russian, Chinese, North Korean and Iranian APTs | Sustained policy- and influence-targeted intrusions where the underlying organisation has political or advocacy exposure. | ESET / Help Net Security |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager (auth bypass; UAT-8616 in-the-wild) | 10.0 | Yes | Yes | Patch immediately; rotate SSH keys; review NETCONF logs |
| CVE-2026-6973 | Ivanti EPMM (post-CVE-2026-1340 credential reuse chain) | 7.2 | Yes | Yes | Patch and rotate any admin credential issued before 1 Feb 2026 |
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) — directory traversal | 9.4 | Yes | Yes | Patch to build ≥17079; treat as EDR-control-plane exposure until verified |
| CVE-2026-42897 | Microsoft Exchange Server (Subscription Edition / 2019 / 2016) — XSS via crafted email | 8.1 | Yes | Yes | Apply 14 May 2026 OOB update; disable OWA externally pending patch |
| CVE-2025-34291 | Langflow — origin validation error (added KEV 21 May 2026) | 9.1 | Yes | Suspected | Patch and restrict admin endpoints to trusted networks |
| CVE-2026-8398 / CVE-2026-45321 / CVE-2026-48027 | DAEMON Tools Lite / TanStack packages / Nx Console developer extension (supply-chain trio added KEV 27 May) | 8.0–8.8 | Yes | Yes | Audit developer endpoints; remove compromised package versions |
| CVE-2026-3055 / CVE-2026-4368 | Citrix NetScaler ADC and Gateway (NCSC alert week of 24 May) | 9.0 / 7.5 | No | Suspected | Apply Citrix advisory updates; review session tokens |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]101[.]5 | ongoing | M | TOR exit node — Network Attack + tor_exit categories, IP Insights suggestion: block |
| IP | 193[.]32[.]162[.]157 | ongoing | M | Brute-force / malware family — listed on 6 blacklists per IP Insights |
| Domain | global-retool-leaks[.]onion | 24 May 2026 | M | Qilin leak-site post — Global Retool Group disclosure |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Phishing / OAuth-consent-phish against member-services mailbox → bulk member-data exposure | HIGH | HIGH | CRITICAL |
| Ransomware deployment via IAB front-end against small-to-mid-tier hypervisor estate | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation against on-prem estate (Cisco SD-WAN / EPMM / NetScaler / Exchange / Apex One) | MEDIUM | HIGH | HIGH |
| Supply-chain compromise via membership-platform SaaS (Canvas pattern) | MEDIUM | HIGH | HIGH |
| Russian-aligned hacktivist DDoS / defacement against politically-exposed trade body | MEDIUM | MEDIUM | MEDIUM |
| Nation-state collection against policy-advocacy trade body engaged in sanctions / defence / technology-export work | LOW | HIGH | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection engineering should treat the Cisco Catalyst SD-WAN compromise pattern as the highest-priority hunting hypothesis for the next reporting cycle. Cross-walk EPMM admin logins against the documented CVE-2026-1340 / CVE-2026-6973 credential set, rotating any admin token issued before 1 February 2026 as untrusted. For Microsoft Exchange tenants still on-prem, instrument OWA crafted-email telemetry against CVE-2026-42897 — IIS access logs paired with mailbox event 41 should surface the exploitation primitive. Trend Micro Apex One administrators should monitor for directory-traversal probes against the ApexOne web-admin endpoint and treat any EDR-control-plane configuration change without a corresponding change-management record as a P1 trigger. For trade-body / membership tenants specifically, instrument M365 OAuth consent grants against the organisation-allow-listed enterprise application set; any consent grant outside the allow-list should generate a P2. Hunt for Graph-API bulk-mailbox or bulk-SharePoint download following session-token theft, and treat any cross-tenant sharing-grant of member-data folders to external tenants as a P1 trigger. Watch for spike patterns on public-facing interfaces correlating with public-policy announcements from the organisation.
Defend
Preventive priorities follow Section 6 directly: patch Cisco Catalyst SD-WAN Controller and Manager out of band as the single highest-value action of the reporting cycle, treat any pre-patch SD-WAN admin credential as untrusted, and rotate. EPMM tenants should rotate all admin credentials issued before 1 February 2026 and apply the CVE-2026-6973 patch. Trend Micro Apex One should be patched to build 17079 or later; until then, isolate the Apex web-admin interface behind a management VPN. Microsoft Exchange tenants should apply the OOB update for CVE-2026-42897, and restrict OWA external exposure to MFA-protected paths only. Hardening should follow ISO/IEC 27001 Annex A controls A.5.7 (threat intelligence), A.5.23 (information security for cloud services), A.8.8 (management of technical vulnerabilities), A.8.16 (monitoring activities) and A.8.23 (web filtering); under the NIST CSF mapping, the bulk of these controls land under Identify-AM, Protect-AC and Detect-CM. Helpdesk identity-verification scripts should be exercised against an explicit Scattered Spider / DragonForce voice-phishing scenario before the next quarter close. Trade-body / membership clients should map controls onto the Charity Commission cyber guidance (where applicable), the NCSC Small Charity Guide and Small Organisation Guide, Cyber Essentials Plus, and ICO data-protection guidance for membership data. Where the organisation accepts charitable donations or processes payment data, PCI-DSS v4.0 controls apply. Conditional-access policies should enforce phishing-resistant MFA across member-services and finance mailboxes.
Disrupt
Disruption activity within client lawful authority should focus on: (i) participation in the relevant ISAC indicator-exchange channel — FS-ISAC, H-ISAC, RH-ISAC, Aviation-ISAC, MTS-ISAC and the National Council of ISACs aggregator each provide indicator-sharing forums whose value compounds with active participation; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through the registrar-abuse channel and Cloudflare / Microsoft / Google trust-and-safety forms where attribution is sufficient; (iii) deception deployment in the helpdesk-identity-verification path — honey-identities seeded with watch-listed credential signatures will surface IAB front-end activity early; and (iv) tabletop exercise of the Scattered Spider / DragonForce playbook against the inbound helpdesk channel, scoped to a realistic voice-phishing-to-encryption window of 4 to 12 hours. The vertical lacks a dedicated ISAC, but NCSC's CiSP small-organisation trust groups, the Charity Sector Cyber Resilience Forum and the Association of British Insurers / Confederation of British Industry-aligned trust groups provide UK-anchored indicator sharing. International trade-body and association management peer-exchanges via the American Society of Association Executives (ASAE) Cyber Working Group provide complementary fora.
10. Forward outlook
Looking forward to the next reporting period (30 May – 5 June 2026), it is highly likely that phishing-driven account compromise will remain the highest-frequency category of incident against the vertical, and that Qilin, Akira, DragonForce and TheGentlemen will continue at the current leak-site cadence with mid-tier membership-organisation victims appearing each week. It is likely that one or more UK trade bodies with on-prem Exchange will be identified as exposed to CVE-2026-42897 through CiSP or ICO MROS reporting. There is a realistic possibility that the Instructure / Canvas supply-chain pattern will produce additional follow-on disclosures across membership-platform SaaS over the next two cycles.
*Trigger conditions that would prompt revision of this outlook include: (a) a UK trade body or membership organisation publicly disclosing a ransomware incident or data-breach, which would warrant an immediate client advisory; (b) any NCSC TLP:CLEAR advisory pointing to a sector-wide credential-stuffing or OAuth-consent-phishing campaign; (c) a fresh membership-platform SaaS supply-chain breach; or (d) a publicly-attributed hacktivist campaign against a UK trade body.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | CISA KEV Catalog updates — 15, 20, 21, 27 May 2026 — https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA | A1 |
| 2 | Cisco Catalyst SD-WAN Auth Bypass (CVE-2026-20182) — joint advisory CISA / NSA / FBI / NCSC-UK / ACSC / CCCS / NCSC-NZ | CISA et al. | A1 |
| 3 | Talos Intelligence — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616) | Cisco Talos | B2 |
| 4 | Trend Micro Apex One CVE-2026-34926 — CISA KEV addition 21 May 2026 | CISA / Trend Micro | A1 |
| 5 | Microsoft Exchange Server CVE-2026-42897 — active exploitation confirmed by Microsoft | Microsoft / Help Net Security | B1 |
| 6 | NCSC weekly threat reports and advisory feed (NCSC-UK) | NCSC | A1 |
| 7 | ESET APT Activity Report — Oct 2025 to Mar 2026 | ESET | B2 |
| 8 | Check Point Research — The State of Ransomware Q1 2026 | Check Point Research | B2 |
| 9 | Ransomware.live — leak-site tracker (Qilin / Akira / DragonForce / TheGentlemen postings, week ending 28 May 2026) | Ransomware.live | C2 |
| 10 | IP Insights — IP reputation enrichment (https://www.ipinsights.io) | UK Cyber Defence Ltd | B2 |
| 11 | FS-ISAC — sector resilience and AI-fraud advisories (subscription) | FS-ISAC | A2 |
| 12 | NCSC alert — Citrix NetScaler ADC / Gateway CVE-2026-3055 and CVE-2026-4368 | NCSC | A1 |
| 13 | ICAEW — Phishing most prevalent cyber attack confirms UK survey (May 2026) | ICAEW | B2 |
| 14 | Cybernews Centre — UK survey shows phishing still owns the breach economy (1 May 2026) | Cybernews Centre | C2 |
| 15 | ANY.RUN — Major Cyber Attacks in May 2026 (incident timeline) | ANY.RUN | C2 |
| 16 | Hackmageddon — 1-15 May 2026 Cyber Attacks Timeline | Hackmageddon | C2 |
| 17 | NCSC — Small Charity Guide and Small Organisation Guide | NCSC | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Trade bodies and membership organisations threat intelligence report — 11–17 July 2026
The trade body and membership organisation vertical continues to be shaped by three structural characteristics that shape the threat picture: (i) the sector holds sensitive membership registers, financial information (dues, event bookings…
Trade bodies and membership organisations threat intelligence report — 27 April – 3 May 2026
The trade-body and membership-organisation threat picture for the reporting period is dominated by phishing and ransomware against organisations holding member-PII at scale, augmented by Russian state-aligned hacktivist activity targeting representative bodies for political signalling.
Trade bodies and membership organisations threat intelligence report — 4–8 May 2026
The trade-body and membership-organisation threat picture for the reporting period continues to be dominated by phishing and ransomware against organisations holding member-PII at scale, augmented by Russian state-aligned hacktivist activity targeting representative bodies for political signalling.