Active Threat Actors Targeting UK Financial Services
| Actor / Group | Origin | Primary Method | Active Techniques (ATT&CK IDs) | SME Risk |
|---|---|---|---|---|
|
Scattered Spider
aka UNC3944, Octo Tempest
|
CYBERCRIME | SIM-swapping and social engineering to bypass MFA; targets IT helpdesks to gain access. | T1078 T1566.001 T1621 | HIGH |
|
ALPHV / BlackCat
Ransomware-as-a-Service group
|
CYBERCRIME | Ransomware deployment following stolen credentials and VPN exploitation. Known to target professional services firms. | T1486 T1190 T1657 | HIGH |
|
APT29 / Cozy Bear
SVR, Russian Foreign Intelligence
|
RUSSIA / STATE | Spearphishing and supply chain compromise. Primarily targets government and finance. Sophisticated, long-dwell operations. | T1566.002 T1195 T1071.001 | MEDIUM |
|
APT40 / BRONZE MOHAWK
Chinese MSS-linked group
|
CHINA / STATE | Exploitation of internet-facing services and VPNs. Actively targeting financial data and intellectual property. | T1190 T1133 T1041 | MEDIUM |
|
MuddyWater
STATIC KITTEN, Iranian MOIS
|
IRAN / STATE | Phishing and exploitation of web frameworks (Laravel, Zimbra). Targeting professional services and finance for espionage. | T1566.001 T1190 T1059 | MEDIUM |
|
LockBit 3.0 Affiliates
Ransomware-as-a-Service network
|
CYBERCRIME | Access brokers sell network entry to affiliates who then deploy LockBit ransomware. SMEs frequently targeted as easier entry points. | T1486 T1078 T1083 | HIGH |
|
TA4903 (BEC Specialists)
Business Email Compromise group
|
CYBERCRIME | Impersonation of senior staff, solicitors, and payment processors to redirect bank transfers. Primary threat vector for insurance brokers. | T1566.002 T1534 T1078 | HIGH |
How Much of This Does GET-IT Cover?
Coverage by Tactic
Techniques in Use Against UK SMEs This Week
Current Risk Status for UK Financial Services SMEs
Elevated — Agentic AI Risk Formalised by NCSC, SharePoint Pattern Continues, macOS Attack Surface Opens
RAG status Elevated/Amber for the August edition. The NCSC published formal guidance this month on managing the cyber risk of agentic AI (20 August 2026) — the first time the UK's national cybersecurity agency has published dedicated guidance on AI agents as a threat vector, confirming that agentic AI risk has moved from theoretical concern to operational priority. Microsoft SharePoint has its fourth confirmed exploited vulnerability in five months (CVE-2026-55040, authentication bypass) — the persistence of this pattern across consecutive CISA KEV cycles makes SharePoint the most consistently targeted SME platform of 2026. Apple macOS has a newly confirmed Screen Sharing authentication bypass (CVE-2026-65400), allowing unauthenticated network access — relevant for any business running Macs alongside Windows infrastructure. Microsoft IKE (Internet Key Exchange) remote code execution (CVE-2026-33824) is a VPN-layer vulnerability with significant implications for organisations using Microsoft's built-in VPN services. MITRE-Lite moves to monthly updates from this edition — content will be refreshed at the end of each month.
Authentication Bypass at Multiple Layers (T1078 / T1190) — macOS Screen Sharing, SharePoint, and Microsoft IKE All Confirmed Exploited
Three distinct authentication-layer vulnerabilities were confirmed exploited in August 2026 across products common in UK SME environments. CVE-2026-65400 (Apple macOS, added 18 August 2026) allows an unauthenticated attacker on the same network to authenticate to Screen Sharing without valid credentials — opening remote desktop access to any Mac without a password. This is particularly relevant for businesses running mixed Mac/Windows environments where Macs may be less tightly managed than Windows devices. CVE-2026-55040 (Microsoft SharePoint, added 18 August 2026) is the fourth SharePoint vulnerability confirmed exploited since April 2026 — this one a weak authentication flaw allowing unauthenticated network attackers to bypass security features. The SharePoint pattern across five months now represents the most persistent single-platform exploitation campaign in the SME-relevant CISA KEV data for 2026. CVE-2026-33824 (Microsoft IKE, added 18 August 2026) is a double-free vulnerability enabling remote code execution in Microsoft's Internet Key Exchange service — the component underpinning Windows VPN and IPSec connections. Remote code execution via the VPN layer is a high-severity finding for any organisation using Windows-native VPN. The NCSC published dedicated guidance on managing the cyber risk of agentic AI on 20 August 2026 — the first formal NCSC publication treating AI agents as an operational cyber risk rather than a future concern, and worth reading alongside the Jadepuffer agentic ransomware case documented in the Week 28 edition. VMware vCenter also appeared in CISA KEV this month (CVE-2026-59310), relevant for any organisation running VMware virtualisation infrastructure.
ACTIVE — LockBit 3.0 Affiliates and ALPHV/BlackCat Successors Operational
Both ransomware-as-a-service ecosystems remain active with affiliate networks continuing to acquire access from initial access brokers. UK professional services firms make up approximately 18% of confirmed UK ransomware victims in Q1 2026 (NCSC data). Offline backups, patching cadence, and tested recovery plans are the three most effective mitigations at this level.
Live Source Summary
Does Your Security Stack Cover These Techniques?
64% coverage of active techniques is a starting point. If you'd like to understand exactly where your gaps are — and what it would cost to close them — book a resilience scan.
Book a Resilience Scan →Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (licensed under CC BY 4.0). Technique descriptions are plain-English interpretations for SME audiences and are not verbatim reproductions of MITRE documentation. Coverage assessments reflect the GET-IT stack as configured for a typical SME client — actual coverage depends on your specific environment. This dashboard is updated weekly; data may not reflect events in the 24–48 hours prior to the last refresh date. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data.