Active Threat Actors Targeting UK Financial Services
| Actor / Group | Origin | Primary Method | Active Techniques (ATT&CK IDs) | SME Risk |
|---|---|---|---|---|
|
Scattered Spider
aka UNC3944, Octo Tempest
|
CYBERCRIME | SIM-swapping and social engineering to bypass MFA; targets IT helpdesks to gain access. | T1078 T1566.001 T1621 | HIGH |
|
ALPHV / BlackCat
Ransomware-as-a-Service group
|
CYBERCRIME | Ransomware deployment following stolen credentials and VPN exploitation. Known to target professional services firms. | T1486 T1190 T1657 | HIGH |
|
APT29 / Cozy Bear
SVR, Russian Foreign Intelligence
|
RUSSIA / STATE | Spearphishing and supply chain compromise. Primarily targets government and finance. Sophisticated, long-dwell operations. | T1566.002 T1195 T1071.001 | MEDIUM |
|
APT40 / BRONZE MOHAWK
Chinese MSS-linked group
|
CHINA / STATE | Exploitation of internet-facing services and VPNs. Actively targeting financial data and intellectual property. | T1190 T1133 T1041 | MEDIUM |
|
MuddyWater
STATIC KITTEN, Iranian MOIS
|
IRAN / STATE | Phishing and exploitation of web frameworks (Laravel, Zimbra). Targeting professional services and finance for espionage. | T1566.001 T1190 T1059 | MEDIUM |
|
LockBit 3.0 Affiliates
Ransomware-as-a-Service network
|
CYBERCRIME | Access brokers sell network entry to affiliates who then deploy LockBit ransomware. SMEs frequently targeted as easier entry points. | T1486 T1078 T1083 | HIGH |
|
TA4903 (BEC Specialists)
Business Email Compromise group
|
CYBERCRIME | Impersonation of senior staff, solicitors, and payment processors to redirect bank transfers. Primary threat vector for insurance brokers. | T1566.002 T1534 T1078 | HIGH |
How Much of This Does GET-IT Cover?
Coverage by Tactic
Techniques in Use Against UK SMEs This Week
Current Risk Status for UK Financial Services SMEs
Raised to HIGH — 7 SME-Relevant CISA Entries, Fortinet and SharePoint Both Active
RAG status raised to HIGH this week. Seven SME-relevant CISA KEV entries in a single week is the highest volume since Week 23 and triggers the RAG escalation threshold. Two Fortinet FortiSandbox OS command injection vulnerabilities confirm the Fortinet attack surface remains actively exploited following FortiBleed. Two further Microsoft SharePoint entries this week — making SharePoint the most persistently targeted SME platform over the past four weeks. Microsoft Active Directory Federation Services privilege escalation (CVE-2026-56155) is particularly significant for organisations using Microsoft federated identity, which includes the majority of Microsoft 365 environments. NCSC separately confirmed this week that the UK and allies are urging critical sectors to improve defences against Russian intelligence targeting — and that hostile state activity against UK organisations continues to increase. The NCSC also published a free hands-on cyber consultancy programme for UK small businesses this week — details in the intelligence feed below.
Privilege Escalation via AD Federation Services (T1078 / T1484) — Microsoft ADFS CVE-2026-56155 and a 2008 CVE Still Being Exploited
CISA added CVE-2026-56155 on 14 July 2026 — an insufficient access control vulnerability in Microsoft Active Directory Federation Services (ADFS) that allows an authorised attacker to elevate privileges locally. ADFS is the identity federation layer used by the majority of Microsoft 365 environments to manage single sign-on and access control. Privilege escalation in ADFS means an attacker who already has standard user credentials can gain administrative access — potentially across every Microsoft service the organisation uses. This is the attack chain that makes credential compromise so damaging: access in → privileges elevated → full domain control. A second SharePoint vulnerability (CVE-2026-56164, missing authentication for critical function) was added the same day, allowing an unauthenticated network attacker to elevate privileges on SharePoint directly. Combined with the deserialization vulnerability from Week 28, SharePoint has now had three separate CISA KEV entries in four weeks. Two Fortinet FortiSandbox OS command injection vulnerabilities (CVE-2026-39808 and CVE-2026-25089) confirm Fortinet's attack surface remains active post-FortiBleed. The most striking editorial note this week: CVE-2008-4128, a Cisco IOS vulnerability from 2008, was added to CISA KEV on 13 July 2026 — meaning criminal groups are actively exploiting 18-year-old vulnerabilities in Cisco networking equipment that organisations have not patched. Legacy equipment running end-of-support Cisco IOS is a live attack surface today.
ACTIVE — LockBit 3.0 Affiliates and ALPHV/BlackCat Successors Operational
Both ransomware-as-a-service ecosystems remain active with affiliate networks continuing to acquire access from initial access brokers. UK professional services firms make up approximately 18% of confirmed UK ransomware victims in Q1 2026 (NCSC data). Offline backups, patching cadence, and tested recovery plans are the three most effective mitigations at this level.
Live Source Summary
Does Your Security Stack Cover These Techniques?
64% coverage of active techniques is a starting point. If you'd like to understand exactly where your gaps are — and what it would cost to close them — book a resilience scan.
Book a Resilience Scan →Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (licensed under CC BY 4.0). Technique descriptions are plain-English interpretations for SME audiences and are not verbatim reproductions of MITRE documentation. Coverage assessments reflect the GET-IT stack as configured for a typical SME client — actual coverage depends on your specific environment. This dashboard is updated weekly; data may not reflect events in the 24–48 hours prior to the last refresh date. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data.