Posts

UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026

Image
  What Happened Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed. The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well.  On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated and took over a year to analyse what information was related to which patient. The breached data includes patient name and number, date of birth, postcode, and test results. In H1 2026, Qilin averaged between seven and nine published UK victims per month. For the entries listing an estimated attack date, there was a roughly six-week extortion lifecycle on average, from initial intrusion to ...

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

Image
What Happened HMRC Issues Warning to TikTok Users On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok. The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward. Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC. The warning comes after two Romanian men, aged 22 and 25, were apprehended by HMRC officers in east London on 23 April 2026 in connection with the alleged fraud. Lloyds Bank found Two Thirds of Fraud Cases Started on Meta  On 6 June 2026, Liz Ziegler, the Lloyds fraud prevention director disclosed that 68% of fraud reports from their customers started on a Meta platform, including Facebook, Instagram, and WhatsApp. The average claim value submitted to Lloyds Bank is now above £500, an incre...

Project ORBITAL

Image
Introduction The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks.  Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure. To construct these networks, adversaries systematically compromise unpatched, end-of-life devices. By targeting legacy, unpatched Small Office/Home Office (SOHO) router and Internet-of-Things (IoT) devices attackers can create a sprawling, decentralised mesh of proxy nodes. By routing their operations through layers of compromised devices, adversaries mask their true origins, making malic...

UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests

Image
What Happened Nemesis Dark Web Drug Dealers Arrested On 14 May 2026, two Cambridgeshire drug dealers were sentenced after being arrested in July 2024 by the Eastern Region Special Operations Unit (ERSOU). ERSOU officers recovered Royal Mail parcel labels, order lists, Gorgonites-branded packaging, and a USB memory stick containing login credentials for multiple dark web marketplace accounts. The dealers reportedly used the dark web to supply heroin, cocaine, and amphetamine to hundreds of users across the UK. The drug deals were initially arranged via a Telegram channel under the handle Gorgonites, which was linked to at least 570 individual sales on Nemesis Market since September 2023. AEGIS Dark Web Drug Market Seizure On 17 March 2026, the London Metropolitan Police’s Cyber Crime Unit announced the seizure of AEGIS Marketplace. In June 2025, the Met Cyber Crime Unit became aware of AEGIS Marketplace, which was a site where individual sellers could market drugs for sale to users who...

UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters

Image
What Happened On 9 June 2026, the University of Nottingham was listed as a victim on the ShinyHunters Tor data leak site. The attackers leaked over 40GB of billing and payment records, student finance data, and campus portal exports from the University of Nottingham and its Malaysia and China campuses. The data stolen includes contact information, transaction amounts, IP addresses, full names, home addresses, postcodes, email addresses, phone numbers, dates of birth, and other internal campus data. Further analysis of the leaked data by Have I Been Pwned revealed it also contained over 455,000 unique email addresses along with extensive personal information including ethnicities, disabilities, and passport numbers. On 10 June 2026, security researcher @nahamike01 uncovered an exposed server belonging to ShinyHunters and found them targeting Oracle PeopleSoft servers using MeshCentral agents. Plus, analysis the bash_history logs on the server uncovered SSH connections to the IP addre...