Daily intelligence briefing: 18 July 2026
American strikes on Iran have entered a seventh consecutive night and Iranian retaliation has now reached military facilities in Kuwait and Jordan, hardening the case against any Gulf travel while airline schedules across Dubai, Abu Dhabi and Doha continue to thin. In London, the National March for Palestine moves from Russell Square to Whitehall this afternoon under Public Order Act conditions, and on the digital side a class action against the law firm WilmerHale and a widening set of Salesforce extortion claims keep the supplier route into private wealth firmly in view.
United Kingdom and London
The national terrorism threat level remains at SEVERE, meaning an attack is highly likely. Counter Terrorism Policing has now confirmed a total of twelve arrests in the investigation into a suspected extreme right-wing threat against a large Islamic gathering at Shrubland Hall in Suffolk, which was attended by some fifteen thousand people earlier this month and closed a day early as a precaution. Eight men were detained under the Terrorism Act, three men were arrested on suspicion of conspiracy to murder and a woman was arrested on suspicion of assisting an offender, with ages ranging from 27 to 82 and arrests spread across Surrey, Greater Manchester, London, Essex and Ipswich. Seven remain in custody and searches at linked addresses continue. Police state there is no evidence of a wider threat to the public, but the scale of the operation underlines the extreme right-wing component of the threat picture that sits behind the current national level.
Today’s National March for Palestine is the principal movement consideration in central London. The Metropolitan Police has imposed conditions under the Public Order Act: assembly is confined to Russell Square, the procession must not begin before 12.45pm, the route runs through Holborn and the Strand to a rally at Whitehall, and the event must conclude by 5.30pm. Rolling closures should be expected across Bloomsbury, Holborn, the Strand and Westminster into the early evening, and movements across the West End this afternoon should be settled in advance. Crowd concentrations continue into Sunday, when the World Cup final between Argentina and Spain kicks off at 8pm UK time with large screenings across hospitality venues, alongside the London Craft Beer Festival at Southwark Park, the Somerset House Summer Series and the LatinoLife festival in Ealing. The yellow heat health alert for London has now lapsed as the heatwave eases, although hosepipe bans remain in force and wildfire risk stays elevated until conditions fully break.
Travel corridors
The United States carried out a seventh consecutive night of strikes on Iran, with explosions reported at Bandar Abbas and Sirik and road infrastructure in Hormozgan province damaged, where authorities report civilian casualties and are advising against non-essential travel. Iranian retaliation has widened in reach: drone and missile strikes were directed at ammunition storage at the Al-Adairi camp and command buildings at Ali Al Salem air base in Kuwait, and at fuel storage at Al-Azraq in Jordan, injuring several American service members, while the Revolutionary Guard claims to have downed an American MQ-9 over Bushehr province. Sirens sounded again in Bahrain and, for the first time in this phase, at Yanbu and Al-Kharj in Saudi Arabia. In the Strait of Hormuz the Revolutionary Guard navy stopped four vessels and fired on a Thai-flagged ship it says ignored warnings. The Foreign Office position is unchanged: against all but essential travel to Bahrain, Kuwait, Qatar and the United Arab Emirates, with British nationals told to shelter during attacks and register with the FCDO. Aviation disruption is now material, with rolling cancellations and hundreds of daily delays across Dubai, Abu Dhabi, Sharjah and Doha as carriers work around closed airspace. Our position stands: all Gulf travel, including Dubai, should be deferred; principals already in the region should hold refundable departure options and expect longer, less predictable routings out.
In Monaco, the investigation into the June explosion has identified the main suspect as a 39 year old Ukrainian national believed to be resident in Germany, and an international arrest warrant and Interpol red notice are in force. German police have searched a rented apartment and vehicle in Hesse, the suspect remains at large, and prosecutors assess that she did not act alone, so the visible uplift on the Riviera should be expected to persist through the season. France reported no fresh high-value theft overnight, although the run that includes the Lalique museum burglary, which cost around four million euros in jewellery earlier this month, continues to justify a low profile with valuables out of sight. Geneva and Zurich remain routine, with Swiss airports still warning of extended queues through the summer peak. In New York, Sunday’s final weekend measures stand: 42nd Street closes to traffic from First to 12th Avenue between 8am and 11pm, a truck ban covers Midtown from 30th to 60th Street, NJ Transit services from Penn Station are restricted to match ticket holders from 11am, and a fifty thousand person watch party occupies the Great Lawn in Central Park with the Rockefeller Center fan village running through Sunday. Midtown Manhattan should be avoided by vehicle on Sunday and long transfer times assumed across the Meadowlands corridor all weekend.
Digital and privacy exposure
A class action filed on 15 July against the law firm WilmerHale, over a breach said to have exposed client and employee social security numbers, is the clearest new example of the theme this briefing has carried for weeks: the professional advisers who surround wealth are the route attackers now take to it. Law firms hold identity documents, trust structures, property records and dispute papers, and a compromise there exposes clients who have done nothing wrong themselves. The Accenture incident confirmed on Thursday continues to work through, with the exposure sitting with clients whose environments the stolen credentials and keys could reach. Families should know which firms hold their material, in what form, and under what notification obligations.
The campaign against Salesforce environments continues to widen. ShinyHunters now claims more than 21 million records from the test and measurement firm Fluke and a smaller but sensitive set from Ingram Content Group that is said to include social security numbers, while a separate actor using the name Gehenna claims some 23 million records taken from Coca-Cola Europacific Partners through the same route, a claim that remains unverified. A ransomware incident at the Coca-Cola subsidiary fairlife has meanwhile halted production, a reminder that these groups disrupt operations as readily as they steal data. Separately, the ModHeader browser extension, installed on some 1.6 million devices, was removed from the Chrome and Edge stores after researchers found a dormant collection capability in a store-signed version able to capture browsing data, session cookies and API keys; extensions on staff and household devices deserve the same scrutiny as any other software supplier. The controls are unchanged: assume accurate personal data is circulating, insist on call-back verification for any change to payment instructions or contact details, review which third parties hold live access to family systems, and treat unsolicited approaches that quote accurate personal detail as hostile until verified.
London is manageable today provided routes around the march footprint are settled before midday, with the event required to conclude by 5.30pm and Sunday’s final adding dense crowds around hospitality districts. The Gulf remains closed to discretionary travel, Dubai included; Iranian strikes on Kuwait and Jordan confirm the conflict is widening rather than settling, and thinning airline schedules mean principals still in the region should leave early on refundable routings rather than wait for conditions to force the decision. On the digital side, WilmerHale, Accenture and the Salesforce claims describe a single pattern: the suppliers and advisers around a family are the attack surface. Verification discipline, an independent review of third-party access and a check of browser extensions on family and staff devices remain the controls that matter.
Speak with us in confidence.
Tell us, in outline, what you need to protect. We reply promptly and privately, and only ever hold the detail you are comfortable sharing.

