This page translates real, active cyber threat intelligence into plain English for UK business owners. No acronyms. No jargon. Just what you need to know and what you should do about it.
Last updated: 16 June 2026 · Week 25 / 2026 · Next update: 23 June 2026
Every week we assess the overall risk level for UK small businesses in financial services — insurance brokers, financial advisers, mortgage intermediaries, and professional services firms. This is based on real intelligence from the UK's National Cyber Security Centre (NCSC), US cyber agencies, and industry reporting.
Seven criminal and state-sponsored groups are currently running active operations targeting UK businesses in your sector. Attacks involving fake payment requests, account takeover, and ransomware are all running at higher-than-normal frequency. This does not mean an attack on your specific business is imminent — but it does mean your defences are more likely to be tested than they would be in a quieter period.
Each week we identify the single highest-risk attack technique that is seeing a spike in use against UK businesses. This week:
A serious vulnerability has been confirmed this week in Google Chrome, Microsoft Edge, and Opera — the three most widely used web browsers in UK businesses. The flaw sits inside the browser's core engine and allows an attacker to run malicious code on your computer simply by getting you to visit a webpage they control. You do not need to click a download link. You do not need to enter your details anywhere. Visiting the page is enough.
Attackers exploit this in two main ways. The first is by sending a link in an email — to a page that looks legitimate but is hosted on a server they control. The second is by compromising a legitimate website that you already trust and injecting malicious code into it — so even a site you visit regularly could briefly become dangerous if it is itself attacked.
This is not a theoretical risk. CISA — the US government's cybersecurity agency — added this to its confirmed exploited vulnerabilities list on 9 June 2026, meaning there is already evidence of real attacks using this method.
The fix is straightforward: make sure your browser is updated. Chrome and Edge update automatically in the background on most systems, but this only works if the browser is closed and reopened regularly. A browser that has been open for days or weeks without restarting will not have applied the latest patch.
These are confirmed, active criminal and state-sponsored groups currently running operations against UK financial services businesses. They are not hypothetical — these groups have successfully attacked businesses similar to yours in recent months.
This group specialises in one thing: intercepting payments. They break into a business email account — usually by phishing someone's password — then quietly read emails for days or weeks, learning how the business operates. When they see a payment being arranged — a solicitor's invoice, a supplier payment, a client refund — they step in at the right moment and change the bank account details to their own. The money lands in their account, not the intended recipient's. By the time anyone notices, it's gone.
Insurance brokers and financial services firms are their primary target because they handle client money, arrange regular payments, and deal with solicitors and other third parties who are also being impersonated.
LockBit is not a single group — it's a criminal franchise. The developers build and maintain the ransomware software, then rent it out to dozens of "affiliate" attackers who do the actual breaking-in. The affiliates keep most of the ransom money; LockBit takes a cut.
Ransomware means your files get encrypted — locked with a code only the attacker knows — and you cannot access anything: client records, accounts, emails, documents. You're handed a ransom demand, typically between £20,000 and £150,000, with a countdown timer. Pay, and you might get your files back. Don't pay, and your data may be published publicly.
SMEs are actively preferred targets because they typically have weaker defences than large corporations, but still have money and data worth holding to ransom.
Scattered Spider are unusually effective because they don't rely heavily on technical hacking — they manipulate people. They are known to call IT helpdesks pretending to be a staff member who has been locked out, convincing support teams to reset passwords and bypass security checks. They also use SIM swapping — convincing a mobile network to transfer someone's phone number to a SIM card they control, giving them access to SMS-based login codes.
Once they have account access, they move quickly to steal data, set up persistent access, and often deploy ransomware from other groups as a final step.
Similar to LockBit but with an additional pressure tactic — before encrypting your files, they first steal a copy of your data. This means even if you have backups and refuse to pay the ransom, they threaten to publish your client data, financial records, or confidential communications publicly unless you pay.
They target professional services firms specifically because client confidentiality is a regulatory requirement — making the threat of publication particularly damaging.
This group works for Russian foreign intelligence (SVR). They are sophisticated, patient, and specifically interested in financial sector data — transaction information, client lists, business communications, and anything that gives Russia economic intelligence about UK businesses and their clients.
They typically enter through carefully crafted phishing emails that look completely legitimate, then sit quietly inside a network for weeks or months gathering information before they're detected — if they're ever detected at all. The goal is intelligence gathering, not financial theft.
Linked to Iran's Ministry of Intelligence, MuddyWater targets professional services and financial firms primarily through phishing emails and by exploiting known security weaknesses in popular business software. Their goals are a mix of intelligence gathering and causing disruption to UK and Western business operations.
Linked to China's Ministry of State Security. APT40 focuses on stealing financial data and business intelligence. They primarily get in through unpatched software on internet-facing systems — VPNs, firewalls, and web applications that haven't been updated. Once in, they move systematically through the network looking for valuable data.
Most people imagine a cyber attack as a sudden dramatic event — a hacker hammering at a keyboard and then everything goes dark. The reality is more like a quiet burglary. Here is what actually happens, step by step, in most attacks on businesses like yours.
Attackers don't usually "break in" dramatically — they find something that's already open. The three most common entry points are: a phishing email that tricks someone into entering their password on a fake website; software on your systems that hasn't been updated and has a known security hole; or a password that was stolen in a previous data breach somewhere else and is still being used.
Once in, most attackers don't immediately do anything visible. They explore — looking at what files exist, what systems are connected, who has what level of access, and what data is valuable. They may try to gain higher levels of access — moving from a junior staff member's account towards an administrator account that can access everything. This phase can last days, weeks, or even months.
Many attackers create a secondary way back in — a hidden account, a remote access tool, or a piece of software that gives them a persistent foothold. This means that even if you change the password that was compromised, they may still have access. It's the equivalent of a burglar making a copy of your key before leaving.
The final stage depends on who the attacker is and what they want. Criminal groups typically either deploy ransomware (locking you out of everything and demanding payment), commit financial fraud (intercepting payments or making fraudulent transactions), or steal and sell your data. State-sponsored groups usually take data quietly without ever revealing they were there.
Understanding the attacker's goal helps you understand what you're protecting against. These are the three primary outcomes attackers are working towards when they target UK financial services SMEs.
All your files, emails, and systems are encrypted. You cannot access anything. A ransom demand arrives — typically between £20,000 and £150,000 — with a deadline. Even if you pay, recovery is not guaranteed. Even if you have backups, restoring everything takes weeks.
An attacker with access to your email intercepts a payment at the right moment, swapping legitimate bank details for their own. The money arrives in their account. Bank reversals succeed in fewer than 40% of cases. This is the number one financial loss vector for UK financial services SMEs.
Client records, financial data, confidential communications, and personal information are copied and taken. The attacker either sells this data, uses it for further fraud, or threatens to publish it unless you pay. Publishing client data may trigger ICO investigation and FCA scrutiny.
No security provider covers everything — and we think it's important to be honest about that. Here is a plain English summary of what the GET-IT stack addresses, where it partially helps, and where there are genuine gaps that we would want to discuss with you.
MITRE-Lite draws on three public intelligence sources, all updated regularly by government cybersecurity agencies. We filter and translate them so you don't have to read them yourself.
Based on the current threat picture, these are the three highest-value actions for a UK financial services business right now. You do not need a technical background to do any of them.
A confirmed vulnerability in Chrome, Edge, and Opera means that visiting a malicious webpage — without clicking anything or downloading anything — is enough for an attacker to run code on that device. The patch already exists and is included in the latest browser version, but it only applies once the browser is fully closed and reopened. Many business computers run with the same browser session open for days or weeks, meaning the update sits waiting but never installs. Send a message to your team now: close your browser completely and reopen it. In Chrome or Edge, check for updates via the Help menu — it takes two minutes. Ask your IT provider to confirm automatic browser updates are active on all managed devices.
Why now: CISA confirmed active exploitation of this vulnerability on 9 June 2026. The fix exists — it just needs to be applied.
A UK police officer is under criminal investigation for allegedly using AI to fabricate evidence — confirmed as the first known case of its kind in the UK. The same AI tools are accessible to anyone. For businesses in financial services and insurance, this has a direct implication: documents that arrive from clients, claimants, or counterparties — loss reports, incident summaries, financial records, identity documents — can now be generated convincingly by AI in minutes. There is currently no reliable automated method to detect AI-generated documents. The practical response is process-based: does your business have a verification step for key documents? Is there a secondary check before a claim is processed or a payment is made based on a submitted document? If not, this week is a good time to introduce one.
Why now: AI document fabrication has moved from theoretical concern to confirmed UK criminal activity. Insurance and financial services firms are a primary target for this type of fraud.
A secondary school in Buckinghamshire was forced to close this week after a malware attack took down its computer systems and communications. Staff could not email parents. Teachers could not set work. Examinations were postponed. The school remained closed to most students for two days while specialists worked to restore systems. Replace "school" with "insurance broker" or "financial adviser" and the scenario is identical. Your client records, your email, your compliance documents, your policy management system — if any of these became inaccessible tomorrow, what is your plan? The GCHQ Director confirmed this week that organisations which had thought through how to operate manually, identified their most critical systems, and had a recovery plan recovered significantly faster than those that had not. You do not need a complex technical plan. You need a simple written answer to: what do we do, who do we call, and what can we do on paper if we have to?
Why now: GCHQ's Director confirmed the NCSC handles approximately four nationally significant cyber incidents every week. Operational resilience planning is the difference between a recoverable incident and a business-threatening one.
A GET-IT resilience scan maps your current defences against the active threat techniques on this page and tells you exactly where your gaps are — in plain English, with costs to fix them.
Book a Free Resilience Scan → View Technical Version