Two ransomware anchors landed on the same evening on Tuesday 28 July 2026, both naming UK victims. The Qilin ransomware group added a UK organisation listed only as Hoc to its leak site at just before 22:00 UK time, its second confirmed UK casualty inside four weeks and the first since Arctic Wolf Labs published the definitive attribution paper on Monday 21 July linking Qilin's initial-access chain to active exploitation of CVE-2026-0257, the PAN-OS GlobalProtect authentication-bypass flaw that Palo Alto Networks patched on Tuesday 13 May 2026 and that CISA added to its Known Exploited Vulnerabilities catalogue on Thursday 29 May. Coinbasecartel, an emerging financially-motivated extortion actor active since April 2026, added Accesso - the UK-headquartered ticketing, virtual-queuing and guest-experience technology provider whose platforms sit under a large fraction of UK theme parks, ski resorts, cultural venues, cathedrals, museums and school-trip attractions - to its leak site at just before 20:00 UK time. Day Forty-One of the DUAA Section 164A regime closes the first calendar month of the new data-protection complaints duty. Three jobs pinned to Friday 31 July (Palo Alto GlobalProtect verification), Monday 3 August (Accesso supplier-question note to ticketing, virtual-queuing and school-trip partners) and end of week (Section 164A first-month five numbers on one sheet).
Key takeaways
- The Qilin ransomware group added a UK organisation listed only as Hoc to its darknet leak site at just before 22:00 UK time on Tuesday 28 July 2026. This is Qilin's second confirmed UK casualty inside the four weeks between 1 July and 28 July, and the first since Arctic Wolf Labs published the definitive attribution paper on Monday 21 July linking Qilin's initial-access chain to active in-the-wild exploitation of CVE-2026-0257, the Palo Alto Networks PAN-OS GlobalProtect authentication-bypass flaw.
- CVE-2026-0257 is a CVSS 7.8 authentication-bypass vulnerability in the PAN-OS GlobalProtect portal and gateway that Palo Alto Networks patched on Tuesday 13 May 2026 for PAN-OS 12.1, 11.2, 11.1 and 10.2 and for Prisma Access. Rapid7 first reported in-the-wild exploitation on Saturday 17 May, and CISA added the flaw to its Known Exploited Vulnerabilities catalogue on Thursday 29 May with a three-day federal remediation deadline. The exploit chain is authentication-override cookie at the perimeter, credential harvesting from the compromised VPN session, PsExec for lateral movement, and Qilin ransomware for domain-wide encryption inside seventy-two hours.
- Coinbasecartel, an emerging financially-motivated extortion actor active on the darknet since April 2026, added Accesso to its leak site at just before 20:00 UK time on Tuesday 28 July 2026. Accesso is the UK-headquartered plc whose ticketing, virtual-queuing and guest-experience platforms (Passport, ShoWare, LoQueue and The Experience Engine) sit under a large fraction of the UK's theme parks, ski resorts, cultural venues, cathedrals, museums and school-trip attractions. On previous entries the group has published proof samples inside seventy-two hours of listing.
- Day Forty-One of the DUAA Section 164A complaints regime closes the first calendar month (19 June to 19 July) of the new duty for every UK controller. Every organisation should have five numbers written down on one sheet by the end of the working week commencing 29 July: total complaints received, median acknowledgement time inside the thirty-calendar-day window, slowest acknowledgement time, number of acknowledgements that went past thirty days, and number of complaints escalated to the ICO. The Deputy Commissioner's first Day-Thirty commentary is expected within the next fortnight and before the Cyber Security and Resilience Bill's Committee stage on Tuesday 1 September.
- Three jobs for UK schools, charities and small businesses in the week commencing 29 July 2026: by Friday 31 July, ask three written questions of the IT team or MSP on PAN-OS patch level, authentication-override configuration and anomalous VPN sessions since 13 May; by Monday 3 August, send a two-sentence, three-question supplier-verification note to any partner using Accesso platforms for ticketing, virtual queuing or school-trip bookings; and by end of week, sit down with the Section 164A complaints owner and write down the first-month five numbers on one sheet of paper before the Deputy Commissioner's commentary lands.
Two ransomware anchors landed on the same evening on Tuesday 28 July 2026, both of them naming UK victims and both of them sitting cleanly inside the running story ReadyToday has been walking through since June. The first was the Qilin ransomware group adding a UK organisation (listed only as "Hoc" on the leak site, sector not disclosed) to its darknet blog at just before 22:00 UK time — its second confirmed UK casualty inside the four weeks between 1 July and 28 July, and the first to be added since the Arctic Wolf Labs threat-research team published the definitive attribution paper on Monday 21 July linking Qilin's initial-access chain to active in-the-wild exploitation of CVE-2026-0257, the Palo Alto Networks PAN-OS GlobalProtect authentication-bypass flaw that Palo Alto quietly patched on Tuesday 13 May 2026 and that CISA added to its Known Exploited Vulnerabilities catalogue on Thursday 29 May with a three-day federal remediation deadline. The second was "coinbasecartel", an emerging extortion actor that has been active on the darknet since April 2026, adding Accesso — the UK-headquartered ticketing, virtual-queuing and guest-experience technology provider whose platforms sit under a large fraction of the UK's theme parks, ski resorts, cultural venues, cathedrals, museums and school-trip attractions — to its leak site at just before 20:00 UK time. That is two UK-adjacent ransomware drops in a two-hour window, both of them relevant to the ReadyToday audience for different reasons, and both of them landing on the same evening as Day Forty-One of the Data (Use and Access) Act Section 164A regime — the first calendar month of the new data-protection complaints duty, which switched on for every UK controller on Thursday 19 June, has now closed as of Sunday 19 July, and the ICO's first Day-Thirty commentary from the new Deputy Commissioner remains the piece of official-source guidance ReadyToday's audience has been waiting for. This post walks through both anchors in the shape UK schools, charities and small businesses need to act on them inside the working week commencing Wednesday 29 July.
For the audience that reads this newsletter — UK schools and multi-academy trusts, UK charities and museums, and UK small and medium businesses that either sit behind a Palo Alto firewall or that sell tickets, book school trips, run visitor days or use a queuing / event / attractions platform — both anchors matter for a slightly different reason. Qilin is now the number-one financially-motivated ransomware operator in Europe by leak-site volume and its move onto PAN-OS GlobalProtect gives it a shortcut into any organisation still running unpatched Palo Alto edge devices, exactly the same mundane-fundamentals shape that FortiBleed and its INC/Lynx escalation took on the Fortinet side of the same problem last month. Accesso is a UK-registered plc, headquartered in Twyford and listed on the Alternative Investment Market of the London Stock Exchange, whose customer roster is not a matter of public speculation — Merlin Entertainments, Historic Royal Palaces, the Church of England cathedrals scheme, several US theme-park operators and a long list of UK cultural venues and school-trip attractions run their ticketing and virtual-queuing on Accesso platforms. If any organisation in this audience buys tickets or books school trips through an attractions supplier, has an events subsidiary, or runs a museum shop or visitor-experience venue of its own, Accesso is either directly in the third-party stack or one layer behind it. This is the same supplier-side shape that post #28 walked through when Qantas confirmed the 5.7-million-record breach through a third-party Salesforce platform, and the same shape that post #33 walked through when the DfE ExfilSquad leak of six hundred thousand parent and staff records turned a supplier-portal compromise into a UK-education-sector story overnight.
Take the Qilin anchor first because it is the one that carries the technical remediation. Arctic Wolf Labs published the definitive attribution on 21 July after observing multiple ransomware deployments through June and early July in which the same operator chain — CVE-2026-0257 authentication bypass at the perimeter to establish a legitimate-looking VPN session, credential harvesting from the compromised session, PsExec for lateral movement, and Qilin (also tracked as Agenda) ransomware for domain-wide encryption inside seventy-two hours — has been used against organisations in the healthcare, professional-services, manufacturing and public-sector verticals across Europe and North America. CVE-2026-0257 is a CVSS 7.8 authentication-bypass flaw in the PAN-OS GlobalProtect portal and gateway; it is exploitable only when authentication-override cookies are enabled alongside a specific certificate configuration, but Rapid7's telemetry from May and June showed that combination is present on a non-trivial percentage of the internet-facing GlobalProtect estate. Palo Alto Networks issued the patch on 13 May 2026 for PAN-OS 12.1, 11.2, 11.1 and 10.2, and for Prisma Access, alongside a customer advisory that recommended disabling the vulnerable configuration if patching could not be scheduled the same day. Rapid7 first reported in-the-wild exploitation on Saturday 17 May, four days after the patch. CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalogue on Thursday 29 May and set the same three-day federal remediation deadline for all Federal Civilian Executive Branch agencies that it used on the SharePoint ToolShell zero-day covered in post #32. Arctic Wolf's Monday 21 July research paper closed the loop on attribution: the initial-access broker chain that had been observed against European targets since May is the same chain that has produced the Qilin deployments. Yesterday's Hoc leak-site drop is the first named UK victim inside that chain to hit the leak site since attribution was confirmed, and it comes eight days after Arctic Wolf published — the standard delay between initial compromise and public leak-site posting when negotiation windows close without payment.
The Accesso anchor sits in a different layer of the stack but reaches into a wider slice of the audience. coinbasecartel is an emerging financially-motivated actor — not to be confused with the FSB-linked state actors covered in post #33 — that has been active on the darknet since April 2026 and that has a preference for smaller, high-visibility SaaS and technology vendors whose customer bases include recognisable enterprise names. The Accesso leak-site entry contains file-tree screenshots but the group has not yet published a sample dump; Accesso has not confirmed or denied the claim, and there is no LSE filing yet. On previous entries the group has published proof samples inside seventy-two hours of listing, so the audience should treat the initial listing as a genuine claim rather than a bluff and act accordingly. The specific concern for UK schools, charities and small businesses is that Accesso's platforms — Accesso Passport for ticketing, Accesso ShoWare for entertainment venues, Accesso LoQueue and Accesso The Experience Engine for virtual queuing and guest experience — sit under the ticketing and booking flows of a significant fraction of the UK visitor-experience economy. A school booking a Y6 trip to a Merlin park, a charity running a visitor centre with an Accesso ShoWare backend, or a SMB events business selling through an Accesso Passport reseller is all-of-them one integration layer away from whatever coinbasecartel dumps if a payment window closes without agreement. The audience action is not to panic-cancel bookings; it is to write a supplier-verification note to any partner using Accesso platforms and to plan for possible identifier-set exposure (customer names, email addresses, booking references, ticket bar-code payloads, and — importantly — the free-text booking-notes fields that carry medical, dietary and accessibility information for school parties).
Alongside those two anchors, Day Forty-One of the Section 164A regime lands today. That first calendar month is the natural moment to write down the five numbers ReadyToday flagged in post #21 when the complaints duty first switched on, walked through again in post #24's Day-Four pairing and in post #25's Week-One close: the number of Section 164A complaints received, the median and slowest acknowledgement time inside the thirty-calendar-day window, the number where the acknowledgement went over thirty days, the number resolved and the number escalated to the ICO. Post #33 pinned Day-Forty on Monday 28 July; today is Day-Forty-One and the first calendar month of the regime (19 June to 19 July) is now behind the audience. The Deputy Commissioner's Day-Thirty commentary has still not landed at the time of writing — it will land inside the next fortnight and probably before the Bill's Committee stage on Tuesday 1 September (as flagged in post #33's framing note) — and the audience will be in a much better position to read it against their own numbers than against no numbers at all.
Three jobs sit inside the working week commencing Wednesday 29 July, one derived from each anchor.
Job One (Palo Alto GlobalProtect verification, closing Friday 31 July). Ask the IT team or managed service provider three questions in writing and get the answers on the same page. First: is every PAN-OS device on the estate patched to at least the May 2026 fixed builds (PAN-OS 12.1.5-h1, 11.2.7-h1, 11.1.10-h4, 10.2.15-h1) and, if not, on what date is the patch scheduled? Second: is authentication-override enabled on any of the GlobalProtect portals or gateways in the estate, and if so has that configuration been reviewed against the Palo Alto customer advisory of 13 May 2026? Third: has the SSL VPN session log been reviewed for anomalous session establishment in the window since 13 May 2026 and, if so, have any sessions been flagged for investigation? This is the same shape as the four-supplier-questions frame ReadyToday walked through on the Fortinet side in post #24 and post #31, applied to the Palo Alto side of the same question. If the answer to any question is unclear, the NCSC Early Warning service will surface exposed GlobalProtect fingerprints against the estate for free.
Job Two (Accesso supplier-question note, closing Monday 3 August). Send a short note — two sentences and three questions is enough — to any commercial partner whose contract involves ticketing, virtual queuing, guest experience, school-trip bookings, museum shop or events. The two sentences: "We have seen the coinbasecartel leak-site listing for Accesso dated 28 July 2026. We are writing to confirm the position on any Accesso platforms that sit in your integration with our organisation." The three questions: "First, does your service or supplier chain use Accesso Passport, ShoWare, LoQueue or The Experience Engine (or any Accesso-branded platform) at any layer? Second, if yes, what customer identifiers of ours are held on those platforms (names, emails, phone numbers, booking notes, medical or dietary declarations, safeguarding-related free text)? Third, if any data of ours is confirmed exposed, on what date will you notify us and by what channel?" That note takes twenty minutes to write and takes any organisation from "we might be affected" to "we have a paper trail on the assumption we might be affected" — and the paper trail is what the ICO's post-incident complaint-handling assessment will look at first when the Section 164A regime bites. If you are a school running Y5 or Y6 trips this September, put this note in front of the trip provider before the bookings are re-confirmed at end of August.
Job Three (Section 164A first-month numbers written down, end of week). Sit down for thirty minutes with the person named as the Section 164A complaints owner on Day One (see post #21) and write down five numbers on one sheet. Number one: total Section 164A complaints received between 19 June and 28 July. Number two: median acknowledgement time inside the thirty-day window. Number three: slowest acknowledgement time inside the thirty-day window. Number four: number of acknowledgements that went past thirty days (this is the ICO's first natural enforcement lever under Section 164A, and the number the Deputy Commissioner's Day-Thirty commentary will speak to first). Number five: number of complaints escalated to the ICO. If any of the numbers are "zero" that is a real and valid answer and it should be written down as zero rather than left blank. The purpose of the exercise is to have something in your hand when the Deputy Commissioner's commentary lands, and to know before the Committee stage on Tuesday 1 September what the first-month complaints load actually looks like across the organisation.
What is not in this post. The 8 July NHS England "don't let curiosity kill your career" campaign against staff snooping on patient records (Sir Jim Mackey's statement, the new NHS England guidance for organisations, the Cambridge University Hospitals forty-staff self-referral to the ICO after the 18 June crocodile-attack case in Huntingdonshire) is a substantial audience-relevant story that will be picked up in a dedicated post the moment either the ICO publishes a decision or a UK school or trust runs into the same situation with its own safeguarding data. The Craneware LSE notice of 20 July confirming a data breach at the Edinburgh-headquartered healthtech firm that supports around two thousand US hospitals is not in this post because the Craneware data set is primarily US-hospital-facing, but it is worth reading on its own if any organisation in the audience is a Craneware customer through a partner. The scheduled Committee stage of the Cyber Security and Resilience (Network and Information Systems) Bill on Tuesday 1 September is now the calendar-bracket peg for posts #35 onwards (as flagged in the framing note of post #33) and will not be re-walked here. Similarly the ongoing LAUNDRY BEAR/Zimbra story, the DfE ExfilSquad situation (still no official DfE statement at time of writing), the Committee-stage amendments (still not published) and the DCMS response to the PAC's six museums-cyber recommendations (statutory response window puts it in late August) are all held for the post that treats them together once new material lands.
The takeaway is smaller than usual because the week is smaller than usual: check that the Palo Alto GlobalProtect estate is patched to the May 2026 fixed builds and that authentication-override is not silently enabled, write the twenty-minute Accesso supplier-note to any ticketing, virtual-queuing or school-trip partner, and put the Day-Forty-One Section 164A numbers on one sheet of paper before the Deputy Commissioner's commentary lands. If any of the three feels unclear, ReadyToday is running free thirty-minute discovery calls through the rest of July and August specifically for organisations that want to walk through the Palo Alto verification, the Accesso supplier-note wording, or the DUAA Section 164A five-numbers exercise on their own estate — book one and we will talk you through the specifics for your setup.