Active Threat Actors Targeting UK Financial Services
| Actor / Group | Origin | Primary Method | Active Techniques (ATT&CK IDs) | SME Risk |
|---|---|---|---|---|
|
Scattered Spider
aka UNC3944, Octo Tempest
|
CYBERCRIME | SIM-swapping and social engineering to bypass MFA; targets IT helpdesks to gain access. | T1078 T1566.001 T1621 | HIGH |
|
ALPHV / BlackCat
Ransomware-as-a-Service group
|
CYBERCRIME | Ransomware deployment following stolen credentials and VPN exploitation. Known to target professional services firms. | T1486 T1190 T1657 | HIGH |
|
APT29 / Cozy Bear
SVR, Russian Foreign Intelligence
|
RUSSIA / STATE | Spearphishing and supply chain compromise. Primarily targets government and finance. Sophisticated, long-dwell operations. | T1566.002 T1195 T1071.001 | MEDIUM |
|
APT40 / BRONZE MOHAWK
Chinese MSS-linked group
|
CHINA / STATE | Exploitation of internet-facing services and VPNs. Actively targeting financial data and intellectual property. | T1190 T1133 T1041 | MEDIUM |
|
MuddyWater
STATIC KITTEN, Iranian MOIS
|
IRAN / STATE | Phishing and exploitation of web frameworks (Laravel, Zimbra). Targeting professional services and finance for espionage. NCSC and allies confirmed Iranian state spyware campaigns this month. | T1566.001 T1190 T1059 | MEDIUM |
|
LockBit 3.0 Affiliates
Ransomware-as-a-Service network
|
CYBERCRIME | Access brokers sell network entry to affiliates who then deploy LockBit ransomware. SMEs frequently targeted as easier entry points. | T1486 T1078 T1083 | HIGH |
|
TA4903 (BEC Specialists)
Business Email Compromise group
|
CYBERCRIME | Impersonation of senior staff, solicitors, and payment processors to redirect bank transfers. Primary threat vector for insurance brokers. | T1566.002 T1534 T1078 | HIGH |
How Much of This Does GET-IT Cover?
Coverage by Tactic
Techniques in Use Against UK SMEs This Month
Current Risk Status for UK Financial Services SMEs
Elevated Maintained — Edge Devices and Remote-Access Appliances Under Coordinated Pressure, WordPress and SharePoint Both Add Fresh Exploits, Two Browser Zero-Days Confirmed
RAG status remains Elevated/Amber for the September edition. Seventeen SME-relevant vulnerabilities were added to CISA KEV this month — the highest monthly total MITRE-Lite has tracked since moving to a monthly cadence — with a clear pattern across internet-facing and remote-access infrastructure. Citrix NetScaler ADC/Gateway picked up two separate confirmed-exploited flaws in the same week (CVE-2026-88771, an unauthenticated command-execution bug, and CVE-2026-88772, a buffer overflow), while Cisco added three: an authentication bypass in Identity Services Engine (CVE-2026-76460), a root-level SQL injection in Secure Email Gateway (CVE-2026-76461), and an authentication bypass with root access in Firewall Management Center (CVE-2026-20079). F5 BIG-IP APM (CVE-2026-94127) and Fortinet's FortiOS/FortiSwitchManager/FortiSASE stack (CVE-2025-25249) round out the remote-access picture. NCSC's 27 August advisory on the risk from internet-exposed systems and edge devices reads, in hindsight, as a direct preview of this month's KEV additions. Away from the network perimeter, WordPress Core picked up an unauthenticated remote file inclusion vulnerability (CVE-2026-87902) — relevant to a large proportion of UK SME websites — and Microsoft SharePoint added a fifth confirmed-exploited vulnerability of 2026 (CVE-2026-65660, code injection), extending the pattern flagged in previous editions. Google Chromium's V8 engine had two separate zero-days confirmed exploited this month (CVE-2026-87491, CVE-2026-85046), both allowing remote code execution inside the browser sandbox via a crafted web page — relevant to every business regardless of platform, since Chrome, Edge and Opera all share the affected engine. NCSC also published three further pieces on AI-related risk this month (adversary simulation scheme documents, defending against agentic threats, and the risks of unsanctioned "shadow AI" use) and, jointly with allied agencies, confirmed Iranian state-linked spyware campaigns targeting UK-based activists and journalists.
Exploit Public-Facing Application (T1190) — Citrix, Cisco and F5 Remote-Access Appliances Confirmed Exploited Alongside WordPress and SharePoint
Seven confirmed-exploited vulnerabilities this month share the same underlying technique: an attacker exploiting a flaw in software your business exposes to the internet, without needing valid credentials first. Citrix NetScaler ADC and Gateway — used by many UK SMEs for VPN and remote access — picked up two separate confirmed-exploited flaws in the same week (CVE-2026-88771, added 27 September 2026, which allows an unauthenticated attacker to execute arbitrary commands, and CVE-2026-88772, a buffer overflow enabling code execution or denial of service). Cisco contributed three: an authentication bypass in Identity Services Engine allowing unauthorised access to the management interface (CVE-2026-76460), a SQL injection in Secure Email Gateway that gives an unauthenticated attacker root access (CVE-2026-76461), and an authentication bypass in Firewall Management Center that also yields root access (CVE-2026-20079). F5 BIG-IP APM (CVE-2026-94127, unauthenticated remote code execution via a heap overflow) and Fortinet's FortiOS/FortiSwitchManager/FortiSASE line (CVE-2025-25249, unauthorised code execution via crafted packets) extend the same pattern across the remote-access and VPN layer. NCSC's 27 August advisory on the risk from internet-exposed systems and edge devices now reads as an accurate preview of this month's KEV additions. Outside the network perimeter, WordPress Core — the platform behind a very large share of UK SME websites — added an unauthenticated remote file inclusion vulnerability that can lead to full remote code execution (CVE-2026-87902, added 25 September 2026), and Microsoft SharePoint picked up its fifth confirmed-exploited vulnerability of 2026 (CVE-2026-65660, code injection via an authorised network attacker), continuing the most persistent single-platform pattern in this year's SME-relevant CISA KEV data. Separately, Google Chromium's V8 engine had two zero-days confirmed exploited within the same month (CVE-2026-87491 and CVE-2026-85046), both allowing sandbox escape via a crafted web page — relevant to Chrome, Edge and Opera users alike, which in practice means almost every employee's browser.
ACTIVE — LockBit 3.0 Affiliates and ALPHV/BlackCat Successors Operational
Both ransomware-as-a-service ecosystems remain active with affiliate networks continuing to acquire access from initial access brokers. UK professional services firms make up approximately 18% of confirmed UK ransomware victims in Q1 2026 (NCSC data). Offline backups, patching cadence, and tested recovery plans are the three most effective mitigations at this level.
Live Source Summary
Does Your Security Stack Cover These Techniques?
64% coverage of active techniques is a starting point. If you'd like to understand exactly where your gaps are — and what it would cost to close them — book a resilience scan.
Book a Resilience Scan →Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (licensed under CC BY 4.0). Technique descriptions are plain-English interpretations for SME audiences and are not verbatim reproductions of MITRE documentation. Coverage assessments reflect the GET-IT stack as configured for a typical SME client — actual coverage depends on your specific environment. This dashboard is updated monthly; data may not reflect events in the days immediately prior to the last refresh date. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data.