[Analysis]
M&S and Co-op cyber attacks: social engineering of IT help desks
The attacks on Britain's high street in spring 2025 teach the least technical lesson of all: the process that resets a password matters as much as the password. How to make sure yours can say no.

In spring 2025 three of the best-known names on the British high street were hit by cyber attacks within a few weeks of each other. Marks & Spencer suspended online clothing and home orders on 25 April and did not resume them for around 46 days. It put the cost at about £300 million of lost operating profit, and customers’ personal data (names, contact details, dates of birth and order histories, though not card details or passwords) was taken. The Co-op shut down parts of its IT to contain its own incident and confirmed that data about a significant number of current and past members had been taken. Harrods reported an attempt to get into its systems too.
What we know about how it happened
Press reporting linked the attacks to the group known as Scattered Spider, and to the DragonForce ransomware operation. The National Cyber Security Centre (NCSC) was careful here: in its blog of 4 May 2025 it noted the speculation but said it could not yet confirm whether the incidents were linked or were a concerted campaign by a single actor. We’ll follow that lead, and not treat attribution as settled. In July 2025 the National Crime Agency arrested four people in connection with the attacks; an arrest is not a conviction.
What the NCSC did highlight is the technique Scattered Spider is known for: social engineering of IT help desks. The attacker phones the service desk, claims to be an employee who is locked out, and talks the operator into resetting the password and the multi-factor authentication (MFA) on that account. No malware or clever exploit is needed at that stage. The attacker is simply handed a working login.
Why this matters to small organisations
It’s tempting to read this as a big-company problem. It isn’t. A five-person business may not have a “help desk”, but somebody is the person you ring when you’re locked out. That might be the office manager, an outsourced IT provider, or whoever set up the Microsoft 365 tenant. If a convincing phone call or email can get that person to reset an account, your MFA is only as strong as their willingness to say no.
What the NCSC recommends
The NCSC’s recommendations after these incidents are short and worth quoting almost in full. Organisations should:
- use 2-step verification (MFA) comprehensively, across all their systems;
- watch for unauthorised account misuse, such as “risky logins” flagged by Microsoft Entra ID Protection;
- pay particular attention to Domain Admin, Enterprise Admin and Cloud Admin accounts, and check that their access is legitimate;
- review help desk password reset processes, including how the help desk authenticates staff before resetting their credentials;
- make sure they can spot logins from unusual sources, such as VPN services in residential IP ranges;
- follow the existing NCSC guidance on mitigating malware and ransomware.
For a small business, the fourth point is the one we would act on first.
[A reset process that can say no]
- "I'm locked out, and it's urgent"
- Call back on the number already on file
- A manager or colleague confirms separately
- Reset, and log it
Resetting the password and MFA together should be the exception: it's exactly what an attacker on the phone is asking for.
If any step fails, stop and escalate. Nobody is in trouble for saying no.
In practice that means:
- Decide in advance how someone proves who they are before a reset, and write it down. A name, job title and a plausible story is not proof: those are exactly what an attacker will have researched.
- Call back on a number you already hold, not one the caller gives you. Better still, have a manager or colleague confirm the request in person or through a separate channel.
- Treat an MFA reset as more sensitive than a password reset. Resetting both at once should be rare, and should trigger a second check.
- Tell your IT provider what your process is, and ask them what theirs is. If they will reset your accounts on the strength of a phone call, you have inherited their weakest process.
- Give the person on the phone permission to say no. Attackers use urgency and seniority (“I’m the finance director, I need this now”). A written process protects staff as much as it protects systems.
The wider picture
The NCSC’s Annual Review 2025 reported 204 nationally significant incidents in the year to August 2025, up from 89 the year before. The retail attacks were among the most visible, but the lesson is ordinary: attackers go for the easiest route in, and a helpful person under pressure is often easier than any firewall.
Sources
- NCSC, Incidents impacting retailers: recommendations from the NCSC (4 May 2025)
- NCSC, Statement: incident impacting retailers
- National Crime Agency, Retail cyber attacks: NCA arrest four (July 2025)
- Insurance Journal, After 46-day cyberattack pause, M&S resumes online orders (June 2025)
- NCSC, Annual Review 2025