MITRE ATT&CK SME Edition ● Live

MITRE-Lite Threat Dashboard

The full MITRE ATT&CK framework covers thousands of attack techniques used by nation-states and sophisticated criminal groups. This dashboard cuts it down to the techniques that are actually being used against UK SMEs and financial services firms — right now — in plain English.

█ Last updated: 21 July 2026  ·  Week 30 / 2026

NCSC feed: current CISA KEV: current Actor profiles: weekly review

Refreshed every Monday. Next update: 28 July 2026.

Active Threat Actors Targeting UK Financial Services

7
Active Threat Actor Groups
Confirmed targeting UK fin. services SMEs
14
Techniques in Active Use
From SME-relevant ATT&CK subset
2
New Techniques This Week
FortiSandbox OS injection + AD Federation Services privilege escalation added
7
CISA KEV Entries
SME-relevant this week — busiest CISA week since Week 23; two SharePoint, two Fortinet
What is MITRE ATT&CK? It's a publicly-maintained library of every known attack technique used by criminal groups and state-sponsored hackers — think of it as a documented playbook of everything attackers try. This dashboard filters it down to the techniques that realistically threaten businesses like yours: small financial services firms, insurance brokers, and professional services companies in the UK.
Actor / Group Origin Primary Method Active Techniques (ATT&CK IDs) SME Risk
Scattered Spider
aka UNC3944, Octo Tempest
CYBERCRIME SIM-swapping and social engineering to bypass MFA; targets IT helpdesks to gain access. T1078 T1566.001 T1621 HIGH
ALPHV / BlackCat
Ransomware-as-a-Service group
CYBERCRIME Ransomware deployment following stolen credentials and VPN exploitation. Known to target professional services firms. T1486 T1190 T1657 HIGH
APT29 / Cozy Bear
SVR, Russian Foreign Intelligence
RUSSIA / STATE Spearphishing and supply chain compromise. Primarily targets government and finance. Sophisticated, long-dwell operations. T1566.002 T1195 T1071.001 MEDIUM
APT40 / BRONZE MOHAWK
Chinese MSS-linked group
CHINA / STATE Exploitation of internet-facing services and VPNs. Actively targeting financial data and intellectual property. T1190 T1133 T1041 MEDIUM
MuddyWater
STATIC KITTEN, Iranian MOIS
IRAN / STATE Phishing and exploitation of web frameworks (Laravel, Zimbra). Targeting professional services and finance for espionage. T1566.001 T1190 T1059 MEDIUM
LockBit 3.0 Affiliates
Ransomware-as-a-Service network
CYBERCRIME Access brokers sell network entry to affiliates who then deploy LockBit ransomware. SMEs frequently targeted as easier entry points. T1486 T1078 T1083 HIGH
TA4903 (BEC Specialists)
Business Email Compromise group
CYBERCRIME Impersonation of senior staff, solicitors, and payment processors to redirect bank transfers. Primary threat vector for insurance brokers. T1566.002 T1534 T1078 HIGH

How Much of This Does GET-IT Cover?

9
Techniques Covered
GET-IT stack addresses these directly
64%
Coverage Rate
Of the 14 active techniques this week — unchanged
5
Uncovered Techniques
Honest gap — not covered by current stack
Partial
Exfiltration Coverage
Monitoring detects data movement; cannot always block it
We show you the gaps honestly. No security provider covers everything. The 5 uncovered techniques below include areas where mitigations depend on human behaviour (staff training) or third-party dependencies (your cloud provider, your line-of-business software vendor). We flag them so you know what to ask about — and so you can factor them into cyber insurance conversations.

Coverage by Tactic

Initial Access
75% 3 of 4 techs
Execution
80% 4 of 5 techs
Persistence
67% 2 of 3 techs
Lateral Movement
50% 1 of 2 techs
Exfiltration
33% 1 of 3 techs
Impact
100% 3 of 3 techs
Exfiltration gap — what this means for your insurance: If an attacker reaches your data and moves it slowly out via legitimate cloud services (Microsoft OneDrive, SharePoint, or email), detection requires behavioural monitoring that goes beyond standard endpoint protection. Many cyber insurance policies include data exfiltration in their coverage — but only where you can demonstrate attempted prevention. Speak to us if this concerns you.

Techniques in Use Against UK SMEs This Week

T1566.001 · T1566.002
Phishing — Email & Link-based
Attackers send fake emails pretending to be HMRC, your bank, a solicitor, or a trusted supplier. The email contains a malicious attachment or a link to a fake login page designed to steal your password.
T1190
Exploit Public-Facing Application
Attackers search for unpatched software on your internet-facing systems — VPNs, firewalls, web apps — and exploit known security holes to get in. This is the entry point for many ransomware campaigns. This week: Palo Alto PAN-OS VPN bypass (CVE-2026-0257) confirmed actively exploited.
T1078
Valid Accounts (Stolen Credentials)
An attacker who has obtained a username and password (from a previous breach, phishing, or the dark web) simply logs in using legitimate credentials. No hacking required — they look like a real user.
T1059
Command-Line Scripting (PowerShell / cmd)
Once inside, attackers use built-in Windows tools (PowerShell, command prompt) to run malicious commands without installing suspicious software. This makes them harder to detect because they're using your own tools against you.
T1621
MFA Fatigue Attack
An attacker who has your password sends dozens of multi-factor authentication (MFA) push notifications to your phone, hoping you'll accidentally approve one — or approve it just to make the alerts stop. This bypasses MFA entirely.
T1598.003
Messaging App Targeting (Spearphishing via Service)
Attackers harvest WhatsApp, Signal, and LinkedIn accounts of senior staff to build social engineering profiles — then impersonate trusted contacts to extract credentials or authorise fraudulent payments. NCSC issued a specific warning this week.
T1133
External Remote Services (VPN Abuse)
Attackers exploit or abuse your VPN, remote desktop (RDP), or remote access tools to maintain persistent access — often long after the initial breach is discovered. They effectively install a back door.
T1534
Internal Spearphishing
Having compromised one email account, attackers use it to send convincing phishing emails to other staff internally. A message appearing to come from your MD or finance director asking to approve an urgent payment.
T1041 · T1567
Data Exfiltration via Cloud Services
Attackers copy your files out through legitimate cloud services — SharePoint, OneDrive, Dropbox, Google Drive — because this traffic looks normal to most security tools. Data is gone before anyone notices.
T1486
Data Encryption for Ransom
The final step in most ransomware attacks — all your files are encrypted and you're locked out of your own systems. A ransom demand follows. UK SMEs paid an average of £47,000 per incident in 2025, with recovery taking 3–4 weeks.
T1657
Financial Theft (Business Email Compromise)
An attacker with access to a business email account monitors payment conversations and intercepts at the right moment — substituting their own bank account details. The #1 financial loss vector for UK insurance brokers and professional services firms.

Current Risk Status for UK Financial Services SMEs

█ THREAT LEVEL: HIGH

Raised to HIGH — 7 SME-Relevant CISA Entries, Fortinet and SharePoint Both Active

RAG status raised to HIGH this week. Seven SME-relevant CISA KEV entries in a single week is the highest volume since Week 23 and triggers the RAG escalation threshold. Two Fortinet FortiSandbox OS command injection vulnerabilities confirm the Fortinet attack surface remains actively exploited following FortiBleed. Two further Microsoft SharePoint entries this week — making SharePoint the most persistently targeted SME platform over the past four weeks. Microsoft Active Directory Federation Services privilege escalation (CVE-2026-56155) is particularly significant for organisations using Microsoft federated identity, which includes the majority of Microsoft 365 environments. NCSC separately confirmed this week that the UK and allies are urging critical sectors to improve defences against Russian intelligence targeting — and that hostile state activity against UK organisations continues to increase. The NCSC also published a free hands-on cyber consultancy programme for UK small businesses this week — details in the intelligence feed below.

► Highest Severity Active Technique — Week 30 / 2026

Privilege Escalation via AD Federation Services (T1078 / T1484) — Microsoft ADFS CVE-2026-56155 and a 2008 CVE Still Being Exploited

CISA added CVE-2026-56155 on 14 July 2026 — an insufficient access control vulnerability in Microsoft Active Directory Federation Services (ADFS) that allows an authorised attacker to elevate privileges locally. ADFS is the identity federation layer used by the majority of Microsoft 365 environments to manage single sign-on and access control. Privilege escalation in ADFS means an attacker who already has standard user credentials can gain administrative access — potentially across every Microsoft service the organisation uses. This is the attack chain that makes credential compromise so damaging: access in → privileges elevated → full domain control. A second SharePoint vulnerability (CVE-2026-56164, missing authentication for critical function) was added the same day, allowing an unauthenticated network attacker to elevate privileges on SharePoint directly. Combined with the deserialization vulnerability from Week 28, SharePoint has now had three separate CISA KEV entries in four weeks. Two Fortinet FortiSandbox OS command injection vulnerabilities (CVE-2026-39808 and CVE-2026-25089) confirm Fortinet's attack surface remains active post-FortiBleed. The most striking editorial note this week: CVE-2008-4128, a Cisco IOS vulnerability from 2008, was added to CISA KEV on 13 July 2026 — meaning criminal groups are actively exploiting 18-year-old vulnerabilities in Cisco networking equipment that organisations have not patched. Legacy equipment running end-of-support Cisco IOS is a live attack surface today.

🔒
█ Ransomware Activity Indicator

ACTIVE — LockBit 3.0 Affiliates and ALPHV/BlackCat Successors Operational

Both ransomware-as-a-service ecosystems remain active with affiliate networks continuing to acquire access from initial access brokers. UK professional services firms make up approximately 18% of confirmed UK ransomware victims in Q1 2026 (NCSC data). Offline backups, patching cadence, and tested recovery plans are the three most effective mitigations at this level.

Live Source Summary

■ NCSC UK Alerts
2
Two NCSC advisories this week. Key: UK and allies urge critical sectors to strengthen defences against Russian intelligence targeting (13 July 2026). Also: NCSC launches free hands-on cyber consultancy for UK small businesses — direct referral opportunity for your clients.
Latest: 15 July 2026  →  NCSC SME Consultancy →
■ CISA KEV Entries (SME-Relevant)
7
Highest SME-relevant count since Week 23. Two Fortinet FortiSandbox OS injection (CVE-2026-39808, CVE-2026-25089); two Microsoft SharePoint (CVE-2026-58644, CVE-2026-56164); Microsoft ADFS privilege escalation (CVE-2026-56155); Oracle E-Business Suite payments takeover (CVE-2026-46817); Cisco IOS 2008 CVE now actively exploited (CVE-2008-4128).
Latest: 16 July 2026  →  View CISA KEV →
■ Top Sector Affected This Week
Finance & Insurance
FCA, ASA, SRA and ICO joint taskforce continues crackdown on misleading car finance claims adverts. For regulated firms: multi-regulator coordination on financial promotions signals increasing scrutiny of how financial services are marketed and what consumer harm controls are in place.
FCA joint action: 17 July 2026  →  FCA →
Full Advisory Detail
For full advisory detail, vulnerability write-ups, and CISA KEV entries see the Threat Advisory page →
Has Your Email Been Breached?
Check whether your business email appears in known breach databases — Free check →

Does Your Security Stack Cover These Techniques?

64% coverage of active techniques is a starting point. If you'd like to understand exactly where your gaps are — and what it would cost to close them — book a resilience scan.

Book a Resilience Scan →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (licensed under CC BY 4.0). Technique descriptions are plain-English interpretations for SME audiences and are not verbatim reproductions of MITRE documentation. Coverage assessments reflect the GET-IT stack as configured for a typical SME client — actual coverage depends on your specific environment. This dashboard is updated weekly; data may not reflect events in the 24–48 hours prior to the last refresh date. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data.