Daily intelligence briefing: 12 July 2026
The United Kingdom holds at SEVERE, Iranian missile and drone attacks on the United Arab Emirates overnight have moved the Gulf corridor from strained to acute, and fresh litigation against breached wealth managers underlines how much family data now sits in systems that families do not control.
United Kingdom and London
The national terrorism threat level remains at SEVERE, meaning an attack is highly likely. The Joint Terrorism Analysis Centre raised the level from SUBSTANTIAL on 30 April 2026, citing a rising threat from Islamist and extreme right-wing individuals and small groups based in the UK, alongside state-linked activity directed at specific communities. Nothing in the past twenty-four hours changes that baseline, and it should continue to frame protective planning through the summer.
Metropolitan Police reporting into the weekend reflects a steady level of serious violence and acquisitive crime: three men have been charged over the murder of Matheus Dos Santos Mori in Thornton Heath, a separate murder investigation is under way after a fatal stabbing in Croydon on Thursday evening, and detectives have seized £500,000 of suspected stolen goods from an organised handling network. In central London, the BST Hyde Park concert series concludes on Sunday 12 July, with Park Lane traffic closures from 9pm to 11.45pm and diversions on multiple bus routes. Looking ahead, Saturday 18 July brings a National March for Palestine in central London and a separate notified march from Trafalgar Square to Hyde Park via Marble Arch; movements through Mayfair, Westminster and Park Lane that day should be planned around significant crowds and rolling road closures.
Travel corridors
The Gulf corridor deteriorated sharply overnight. Iranian ballistic missiles, cruise missiles and drones were launched at the United Arab Emirates in the early hours of 12 July; the UAE Ministry of Defence confirmed that air defences intercepted the incoming threats, and residents were told by mobile alert to remain in safe locations before an all-clear was issued. Live reporting also indicates that Iran has declared the Strait of Hormuz closed to shipping. Dubai International continues to operate, but capacity at both Dubai airports has been cut, Qatar Airways has suspended services to thirteen destinations, and a lengthening list of European carriers including British Airways, KLM, Air France and Finnair has withdrawn Dubai routes for the season. FCDO advice for the UAE, last updated on 18 June, does not yet advise against travel, but it predates this escalation and could change at short notice. Our position is that non-essential travel to the Gulf should be deferred; where travel is unavoidable, itineraries must be refundable, flexible and backed by a tested contingency for extended disruption.
In Europe, the investigation into the 29 June Monaco bombing, which seriously injured Ukrainian businessman Vadym Yermolaiev, his son and his partner, has taken a darker turn: the named suspect was found shot dead in Ukraine, and a Kyiv court has now detained two men over her killing, one of them a serving military intelligence officer. The Monaco prosecutor says the motive remains unknown. The episode is a pointed reminder that state-linked and commercially motivated violence can reach even the most densely policed jurisdictions, and principals on the Riviera should expect a visible security uplift through the season. Paris remains in a sustained wave of high-value acquisitive crime following the Lalique museum theft and the Louvre case; profiles should stay low and valuables out of sight. Geneva and Zurich report no acute incidents beyond routine seasonal pickpocketing advisories. In New York, the extreme heat emergency of early July has eased, and movements this week can be planned around ordinary summer conditions.
Digital and privacy exposure
The legal consequences of this year’s attacks on wealth managers are now arriving. Mercer Advisors, a large United States registered investment adviser, faces a second class action after the ShinyHunters group compromised client records held in its systems, with filings alleging millions of exposed records including identity and account data. The claimed breach at family office group Pathstone, reported last week, remains unconfirmed by the firm. Alongside earlier incidents at Beacon Pointe, the pattern is unambiguous: organised criminal groups are working through the wealth management sector deliberately, because adviser systems concentrate exactly the personal, financial and legal detail that makes wealthy families targetable.
The wider July breach flow reinforces the point. ShinyHunters is claiming further large thefts of Salesforce-linked records, including some twenty-one million records from an industrial group, and a separate actor claims to have taken source code and access keys from a major consultancy. Families and family offices should assume that some adviser-held data is already circulating, insist on call-back verification for any change to payment instructions or contact details, and keep the family’s findable footprint under regular independent review.
Today’s picture divides into the sudden and the structural. The sudden is the Gulf: overnight attacks on the UAE and a declared closure of the Strait of Hormuz mean travel to the region should now be deferred unless essential, and existing itineraries reviewed today rather than at departure. The structural is data: litigation against breached advisers confirms that family exposure increasingly lives in third-party systems, and it should be audited with the same rigour as physical security. London’s SEVERE posture and next Saturday’s large demonstrations round out the planning picture for the week ahead.
Speak with us in confidence.
Tell us, in outline, what you need to protect. We reply promptly and privately, and only ever hold the detail you are comfortable sharing.

