Back

[Analysis]

M&S and Co-op cyber attacks: social engineering of IT help desks

The attacks on Britain's high street in spring 2025 teach the least technical lesson of all: the process that resets a password matters as much as the password. How to make sure yours can say no.

A large dark grey M&S store with the M&S logo in white, a glass entrance and cars parked in front.
The M&S store at Cyfarthfa Retail Park, Merthyr Tydfil, in October 2024. After the April 2025 attack, M&S stopped taking online clothing and home orders for 46 days. Cropped from the original. Photo by Sionk, CC BY-SA 4.0.

In spring 2025 three of the best-known names on the British high street were hit by cyber attacks within a few weeks of each other. Marks & Spencer suspended online clothing and home orders on 25 April and did not resume them for around 46 days. It put the cost at about £300 million of lost operating profit, and customers’ personal data (names, contact details, dates of birth and order histories, though not card details or passwords) was taken. The Co-op shut down parts of its IT to contain its own incident and confirmed that data about a significant number of current and past members had been taken. Harrods reported an attempt to get into its systems too.

What we know about how it happened

Press reporting linked the attacks to the group known as Scattered Spider, and to the DragonForce ransomware operation. The National Cyber Security Centre (NCSC) was careful here: in its blog of 4 May 2025 it noted the speculation but said it could not yet confirm whether the incidents were linked or were a concerted campaign by a single actor. We’ll follow that lead, and not treat attribution as settled. In July 2025 the National Crime Agency arrested four people in connection with the attacks; an arrest is not a conviction.

What the NCSC did highlight is the technique Scattered Spider is known for: social engineering of IT help desks. The attacker phones the service desk, claims to be an employee who is locked out, and talks the operator into resetting the password and the multi-factor authentication (MFA) on that account. No malware or clever exploit is needed at that stage. The attacker is simply handed a working login.

Why this matters to small organisations

It’s tempting to read this as a big-company problem. It isn’t. A five-person business may not have a “help desk”, but somebody is the person you ring when you’re locked out. That might be the office manager, an outsourced IT provider, or whoever set up the Microsoft 365 tenant. If a convincing phone call or email can get that person to reset an account, your MFA is only as strong as their willingness to say no.

What the NCSC recommends

The NCSC’s recommendations after these incidents are short and worth quoting almost in full. Organisations should:

For a small business, the fourth point is the one we would act on first.

[A reset process that can say no]

  1. "I'm locked out, and it's urgent"
  2. Call back on the number already on file
  3. A manager or colleague confirms separately
  4. Reset, and log it

Resetting the password and MFA together should be the exception: it's exactly what an attacker on the phone is asking for.

If any step fails, stop and escalate. Nobody is in trouble for saying no.

In practice that means:

The wider picture

The NCSC’s Annual Review 2025 reported 204 nationally significant incidents in the year to August 2025, up from 89 the year before. The retail attacks were among the most visible, but the lesson is ordinary: attackers go for the easiest route in, and a helpful person under pressure is often easier than any firewall.


Sources

Back