Posts

UK Cybercrime Journal: Argos Account Takeover Fraud

Image
What Happened On 3 June 2026, the City of London Police issued a warning stating Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands. Report Fraud, which is run by the City of London Police, warned that cybercriminals are using leaked credentials from historical data breaches to hijack Argos user accounts. Once on the account, the fraudsters order and then collect the goods in-person at a physical store. In some instances, the goods are paid for using payment details not connected to the victim of the compromised account. Notably, the goods from fraudulent orders are often claimed via Click & Collect option that Argos allows, enabling the threat actors to retrieve goods in store. In May, Report Fraud received 652 reports which mention Argos, a 323% increase compared to April, when 154 reports mentioning the retailer were made. Since the start of 2026, there have been 1,175 reports mentioning th...

UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe

Image
What Happened Over the course of September 2025 to May 2026, Hargreaves Lansdown the UK-based investment platform has been the subject of IT glitches, hacker claims, and technical outages that have triggered rumours and customer concerns. On 11 September 2025, Hargreaves Lansdown customers reported discrepancies in the balances for their pension and ISA accounts, appearing as if huge sums had been mysteriously withdrawn. Customer began to fear they had been “hacked” after they logged onto their account and saw their life savings reduced. In less than 24 hours, Hargreaves Lansdown, however, swiftly responded that it was a temporary technical issue that only lasted 45 minutes and all client balances were restored. On 20 March 2026, Hargreaves Lansdown customers began experiencing technical issues that were affecting some parts of its website and app. The company apologised to customers over IT issues which left them unable to access their accounts during a period of heightened volatility...

UK Cybercrime Journal: Sustained DragonForce Campaign

Image
  What Happened Throughout May 2026, affiliates of the DragonForce ransomware-as-a-service (RaaS) platform claimed seven UK-based companies as its victims by posting them on their Tor data leak site. On 27 May 2026 alone, DragonForce ended the month by posting 22 victims from around the world, four of which were UK-based firms. DragonForce’s UK-based victims from May spanned a diverse range of industries: Professional Services & Talent:  Practicus (interim management/executive search) Financial & Tax Services:  WSM (UK tax advisory) Infrastructure & Logistics:  ERH (traffic management solutions) and Refreshment Systems (vending/logistics) Heavy Industry/Construction:  Arsenal Scaffold Technology & IT:  Helix International (managed enterprise software) Luxury Retail/Finance:  Cult Wines. Analyst Comment Active since late 2023, DragonForce remains a persistent cybercriminal threat particularly towards the UK. The recent flurry of disclosu...

Ransomware Tool Matrix Project Updates: Three Groups To Track

Image
  Introduction This blog is a focused update on the latest updates to the  Ransomware Tool Matrix (RTM)  and the  Ransomware Vulnerability Matrix (RVM)  covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock. Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them so defenders can pivot straight into hunting, detection engineering, and patch prioritisation. For anyone new to the projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at  BSides London . Why these three groups? Each of the three groups added in this update represents a different slice of the current ransomware ecosystem: TheGentlemen TheGentlemen is a newer operation that has matured quickly, with a large and...

UK Cybercrime Journal: Arup Group Breached by FulcrumSec

Image
  What Happened: On 10 May 2026, the UK-based firm Arup Group was listed as a victim on the Tor data leak site of FulcrumSec.   On their Tor data leak site, FulcrumSec stated that they have exposed 700GB of GitHub repos and 2TB of Azure and AWS S3 cloud, plus database backups. Other types of data the adversary claims to have stolen includes Neuron BMS client databases, Odoo ERP data, A66 landowner files, Apple code-signing certificates with plaintext passwords, a Google Cloud Platform (GCP) project with production payment gateway credentials, and the source code of ArupCompute and Oasys.   The FulcrumSec operators also claimed to have spent over half a year analysing the data and went through “email correspondence” with the company before publishing the stolen data. On the victim post, FulcrumSec wrote a detailed incident breakdown. In it, they stated they gained initial access in September 2025 via a GitHub personal access token found hardcoded in a JavaScript file on a ...