Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
Note The June 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of the sources, it is sometimes difficult to fully verify the accuracy of certain information, and this is noted accordingly. Major Issue On Hasan’s BreachForums, there was a series of […]
Over the course of September 2025 to May 2026, Hargreaves Lansdown the UK-based investment platform has been the subject of IT glitches, hacker claims, and technical outages that have triggered rumours and customer concerns.
On 11 September 2025, Hargreaves Lansdown customers reported discrepancies in the balances for their pension and ISA accounts, appearing as if huge sums had been mysteriously withdrawn. Customer began to fear they had been “hacked” after they logged onto their account and saw their life savings reduced. In less than 24 hours, Hargreaves Lansdown, however, swiftly responded that it was a temporary technical issue that only lasted 45 minutes and all client balances were restored.
On 20 March 2026, Hargreaves Lansdown customers began experiencing technical issues that were affecting some parts of its website and app. The company apologised to customers over IT issues which left them unable to access their accounts during a period of heightened volatility in the financial markets. The company also assured people that there was no evidence of a cyber incident or a data breach and that all customers’ assets and data was secure.
On 27 April 2026, Hargreaves Lansdown (hl.co.uk) was listed as a victim on the Bashe Tor data leak site. The attacker claimed that they allegedly stole their customer database of 658,259 unique users. They then shared five links to their other servers where other Tor users can download the alleged data.
On 8 May 2026, the alleged Hargreaves Lansdown data appeared on DarkForums, a cybercrime forum. From the sample posted, the database offered contains addresses, names, emails, phone numbers, and date of birth. However, no Hargreaves Lansdown customer account numbers or transaction details were included in the sample.
Analyst Comment
Hargreaves Lansdown is the UK's largest direct-to-consumer investment platform, allowing customers to buy and sell investments such as shares, as well as providing financial advice and offering accounts like cash ISAs.
Activesince April 2024, Bashe (aka APT73 or Eraleign) is a cybercriminal group that focuses on data-theft-extortion and ransomware. Analysts at CloudSEK found that APT73 fabricates attacks by falsely claiming responsibility for high-profile breaches, aiming to attract affiliates and bolster its credibility. They are known for taking credit for attacks that either weren’t committed or wasn’t done by them.
Analysis of the sample data posted to DarkForums and the Bashe Tor data leak site revealed it to be purposely selected UK-based user records. Using HaveIBeenPwned to check the email addresses, the DarkForums sample email all appeared inside the Verifications[.]io breach as well as the People Data Labs (PDL) customer breach. This is unusual for recently leaked data and likely points to both the Bashe and DarkForums sharing fake data.
Further, data from a financial trading platform such as Hargreaves Lansdown would be considered highly valuable on the cybercrime underground and could be sold for a high large amount of cryptocurrency. Therefore, it is again unusual for it to be dumped for free on a forum or Tor site. Based on the technical analysis of the leaked data sample and the established behavioural patterns of the threat actor, it is assessed with high confidence that the alleged data breach of Hargreaves Lansdown is entirely fabricated.
It appears Bashe opportunistically weaponised Hargreaves Lansdown’s recent, IT outages and glitches (in September 2025 and March 2026) to construct a plausible, but false, narrative of a successful hack. By capitalising on pre-existing customer anxieties regarding platform stability, these cybercriminals attempted to reinforce their claims and extort their target for a quick ransom.
This incident highlights an evolving trend where threat actors substitute complex technical exploits with psychological manipulation.
Defensive Takeaways
Counter Adversary Threats: To counter this trend, UK firms must integrate their public relations (PR), incident response, and threat intelligence teams. Quick, transparent communication that explicitly decouples internal IT glitches from external cyber threats remains an effective defence against brand-damaging, clout-chasing extortion tactics.
Precautionary Threat Hunting: Even in a fake breach scenario, it is still important to threat hunt for malicious and suspicious activities involved potentially targeted systems to help prove that the alleged data exfiltration never happened. In this scenario, the attacker claimed to have stolen customer database. Therefore, it would be prudent to hunt for any signs of data theft involving systems hosting customer data specifically.
Precautionary Password Resets: In a scenario like this, companies may want to trigger a precautionary customer password reset “just to be on the safe side”. However, credential rotation must be calculated, automated, and decoupled from any fear, uncertainty, and doubt (FUD). If an incident response includes this action, it must be a measured approach. Triggering a mass password reset without tailored communications can unintentionally support the cybercriminals fake breach narrative and could trigger mass panic.
Notes the May 2026 Dark Web Breach Incident Trend Report is organized around the major cases of Data Breaches posted on the deep web and dark web forums. due to the nature of the source, some of the information may not be fully verifiable as to whether it is true or not, and is therefore […]
Notes the April 2026 Dark Web Breach Incident Trend Report is compiled from data breach cases posted on the deep web and dark web forums. some information is included in cases where it is difficult to fully verify the factuality of the information due to the nature of the source. Major Issues data breaches and […]
Notes the April 2026 Dark Web Issue Trend Report summarizes the Major Issues that occurred on the deep web and dark web. due to the nature of the sources, some of the information is difficult to fully verify. Major Issues BreachForums continued its relaunch with a new domain and repeated operational update announcements. at the […]
Alerts this report is based on reports of data breaches and the sale of initial access rights posted on deep web-dark web forums. some parts of the report contain information that cannot be fully verified as factual due to the nature of the source. Major Issues Multiple breach claims by ShinyHunters. a wide range of […]