Posts

UK Cybercrime Journal: ACRO Breach Report

Image
What Happened On 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO Criminal Records Office suffered three separate compromises involving its customer portal website (acro.police.uk). ACRO is a national police unit providing public services such as issuing Police Certificates, International Child Protection Certificates, and processing Subject Access Requests. In March 2023, ACRO was notified about an SQL injection attack that reportedly exposed 15 sets of credentials, the majority of which belonged to its employees. A subsequent forensic investigation uncovered long-term threat actor activity within the website's environment, spanning from 9 July 2021 to 22 June 2023. The website was built on the Kentico CMS and was running version 12.0.0 between September 2019 and March 2023. This version had multiple known vulnerabilities at the time of the incident, but suffered from ambiguity around who was accountable fo...

UK Cybercrime Journal: Carding Tactics & Youth Money Muling

Image
What Happened Recent operational successes by UK law enforcement have exposed sophisticated domestic carding networks and the growing threat of youth-targeted money muling syndicates. In June 2026, a major cross-border investigation concluded with the sentencing of a serial fraudster who targeted small businesses, including veterinary clinics and hotels, across 22 different counties in England and Wales. The individual executed over 64 frauds and two thefts, accumulating losses totalling £462,000. The threat actor utilised stolen payment card details to buy goods and explicitly manipulating transaction values to inflate the amounts charged before requesting rapid refunds directly into bank accounts under his control. Following his arrest, investigators seized an array of high-value items, including designer clothing and mobile devices. Financial telemetry revealed the illicit proceeds were being spent on luxury goods, gambling, hotels, and vehicle hire. Crucially, investigators uncover...

UK Cybercrime Journal: Evolution of Courier Fraud Campaigns

Image
What Happened New data published by the City of London Police in June 2026  reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties. Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to messaging platforms like WhatsApp to contact their victims and remotely paying for third-party courier services to facilitate physical collections. UK law enforcement also highlighted a dangerous shift in 2025 toward high-value physical goods. Victims are being systematically manipulated into visiting multiple jewellers over an extended period to purchase gold and expensive jewellery, which they then hand directly to fraud couriers. Recent operational crackdowns by UK Regional Organised Crime Units (ROCUs) showcase the nationwide scale of these networks: North West ROCU Operations (July 2026): ...

UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026

Image
  What Happened Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed. The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well.  On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated and took over a year to analyse what information was related to which patient. The breached data includes patient name and number, date of birth, postcode, and test results. In H1 2026, Qilin averaged between seven and nine published UK victims per month. For the entries listing an estimated attack date, there was a roughly six-week extortion lifecycle on average, from initial intrusion to ...

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

Image
What Happened HMRC Issues Warning to TikTok Users On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok. The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward. Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC. The warning comes after two Romanian men, aged 22 and 25, were apprehended by HMRC officers in east London on 23 April 2026 in connection with the alleged fraud. Lloyds Bank found Two Thirds of Fraud Cases Started on Meta  On 6 June 2026, Liz Ziegler, the Lloyds fraud prevention director disclosed that 68% of fraud reports from their customers started on a Meta platform, including Facebook, Instagram, and WhatsApp. The average claim value submitted to Lloyds Bank is now above £500, an incre...