Retail Times — UK Retail News
  • HOME
  • ABOUT
    • CONTACT & Press release submit page
    • ADVERTISING
  • PRODUCTS
  • TECH
  • DATA
    • Reports
    • Research
  • RETAILER
    • Manufacturer
    • Wholesaler
  • PEOPLE
  • SUSTAINABILITY
    • Fairtrade
    • Packaging
  • SERVICES
    • Events
    • Awards
    • Logistics
  • COMMENT
    • In My Opinion
    • Featured Article
    • Why It Works
  • RETAIL CATEGORIES
No Result
View All Result
Retail Times — UK Retail News
No Result
View All Result
  • HOME
  • ABOUT
    • CONTACT & Press release submit page
    • ADVERTISING
  • PRODUCTS
  • TECH
  • DATA
    • Reports
    • Research
  • RETAILER
    • Manufacturer
    • Wholesaler
  • PEOPLE
  • SUSTAINABILITY
    • Fairtrade
    • Packaging
  • SERVICES
    • Events
    • Awards
    • Logistics
  • COMMENT
    • In My Opinion
    • Featured Article
    • Why It Works
  • RETAIL CATEGORIES
Retail Times — UK Retail News
No Result
View All Result
Home Retail News Comment

What retailers must learn from the latest ransomware attacks

by Fiona Briggs
May 8, 2025
in Comment
Reading Time: 4 mins read

By Richard Ford, chief technology officer, at Integrity360

The recent wave of cyber attacks against UK based retailers including M&S, Co-op and Harrods has laid bare that social engineering is one of the most effective weapons in a threat actor’s arsenal. Currently, these attacks are attributed to the Scattered Spider group and signal just how vulnerable many retail organisations can be to such tactics. This is also not unique to Retail, and all organisations should be paying attention. Using the lessons learned to strengthen their security controls in order to withstand these types of attacks.

While the disruption to services at M&S and the confirmed data breach at Co-op rightly drew headlines, the deeper concern is the method of compromise. These were not cases of highly sophisticated attacks, exploiting zero-day vulnerabilities, but exploiting people and gaps in procedure and policy. In this case, specifically the successful impersonation of staff members to target IT helpdesks to gain credential resets. This was followed by remote access through legitimate tools, and finally, the deployment of DragonForce ransomware to encrypt systems and extract sensitive data for double extortion. Although not confirmed, it is likely SIM swapping would have been used to bypass multi-factor authentication.

This should serve as a wake-up call. Social engineering isn’t new, but it is evolving. Today’s threat actors are fluent in the processes and language of IT support teams, capable of replicating internal procedures convincingly. Scattered Spider is made up of US & UK hackers, so are also fluent in English to help impersonate employees. That said, advances in AI deepfakes can allow any attacker to fake a voice or language making the job of defending these attacks even more difficult. In many cases, their use of “living off the land” techniques, which is where threat actors use standard built-in administrative tools to carry out some or all of their attack, allows them to blend in with normal user activity allows and move undetected within an organisation to inflict damage.

In addition, at Integrity360, we are seeing a growing number of UK organisations that remain underprepared for these kinds of attacks, particularly when it comes to incident response maturity. In several cases, poor readiness and lack of incident response plans has significantly slowed recovery time and increased the impact of the breach. This has been claimed (but not confirmed) as to why the M&S breach has taken so long to recover from.

The retail sector is increasingly in the crosshairs. According to Google’s Threat Intelligence Group, 11% of all posts on ransomware data leak sites in 2025 so far have involved retail organisations, up from 8.6% in 2024. With rich customer data, large attack surfaces, and often complex IT estates, the sector presents a high-value target.

So how should retailers and other vulnerable sectors respond?

First, helpdesk procedures must be reviewed and hardened. Staff responsible for password resets or credential changes must follow strict verification protocols. These could include live on-camera verification or mandatory challenge/response questions. No reset should be issued based on a single vector of identity confirmation. Callbacks to known numbers (voice-based authentication) and SMS are the weakest forms of multi-factor authentication, so should be avoided or only used alongside other methods.

Second, authentication methods need to evolve. Phishing-resistant MFA, such as hardware tokens or biometric systems, should replace less secure methods. Passwordless authentication, while not yet universally adopted, offers a significant reduction in risk. Ultimately, to implement their attack, threat actors need to elevate their access and compromise an administrative level attack, Privileged Access Management (PAM) solutions should be deployed to limit exposure of high-value credentials.

Third, incident response plans must be tested, not just written. A plan is only as good as the last time it was rehearsed. Regular tabletop exercises, including simulated social engineering attacks, can expose weak points before adversaries do. Often, the successful recovery is dependant on the availability of backups, and how quickly they can be restored. Backups are targeted by attackers to prevent this so should be stored offline, so called immutable backups.

Finally, organisations must accept that social engineering is not a technical flaw, it’s a human one. That means culture, training and vigilance are just as vital as firewalls and endpoint detection tools. Staff must be aware that oversharing on social media platforms can aid an attacker. Technical teams must be trained to spot subtle warning signs. And leadership must invest not only in protection, but in preparation.

The DragonForce campaign is unlikely to be the last of its kind. But future incidents do not have to be successful. With the right strategy and security measures in place organisations can build resilience against even the most deceptive adversaries.

 

Share This Article

Similar Retail News Articles:

  1. Staying ahead of cyber attacks – the best defences for retailers
  2. 10 lessons retailers can learn from other industries
  3. What can retailers learn from the simplicity of Slingo?
Tags: ransomware attacks

Related Posts

Eight ways retail founders can protect business continuity during divorce

September 17, 2026

For a retail founder, divorce can affect much more than personal savings or the family...

Why the modern dream home is designed to make life easier

September 15, 2026

The idea of a dream home used to come with plenty of extras: sprawling gardens,...

private accommodation for students

Top five platforms to find private accommodation for students

September 14, 2026

Finding the right place to live can be one of the most challenging parts of...

real estate career

How to balance university studies and a real estate career

September 14, 2026

Building a real estate career while attending university can be an exciting way to gain...

Food and drink manufacturers lead push for world-first healthy food sales reporting

September 14, 2026

Five leading UK food and drink manufacturers have stepped up to introduce healthy food sales...

Looking for ways to maintain your kid’s new school shoes? Kickers share top tips for polishing

September 11, 2026

Mikki Phillips, e-commerce manager at Kickers, reveals top tips for keeping your children’s leather school...

Load More

Popular Posts

  • Ferrero Wonka rangeFerrero Wonka range launches in Morrisons and Asda today (249)
  • WALKERS SALT & PEPPER CHICKENMeet the two finalists fighting for £500k in Walkers’ Do Us A Flavour (178)
  • ClarksClarks challenges consumers to rethink what’s on their feet (89)
  • unnamedBarbour reimagines its unique tartan heritage for AW26 (60)
  • VeryVery launches Michelle Keegan’s first installment for the AW Season – City Edge (17)
  • Sainsbury’sSainsbury’s reveals the festive food set to shape celebrations in 2026 (1,183)

FEATURED ARTICLES

The invisible shelf: why retailers and consumer packaged goods brands need to win the algorithm to win the customer

The invisible shelf: why retailers and consumer packaged goods brands need to win the algorithm to win the customer

August 12, 2026
How Catalina helps smaller fuel retailers win loyalty

How Catalina helps smaller fuel retailers win loyalty

April 27, 2026
Retail crime must be challenged, says top security specialist

Retail crime must be challenged, says top security specialist

April 21, 2026
Design Matters: why Lefties tech-based approach could be the future of value retail

Design Matters: why Lefties tech-based approach could be the future of value retail

August 28, 2026
ADVERTISEMENT

Find the Story You Need

No Result
View All Result
  • Home Page
  • Editorial – Contact
  • Advertising
  • Copyright
  • Privacy & Cookie Policy
  • Retailer News
  • Products
  • Data
  • Technology
  • Events
  • People
  • Comment
  • Sustainability
  • Awards
  • Research
No Result
View All Result
  • HOME
  • Featured Articles
  • Retail News Categories
  • About us
  • Advertising
  • Contact / Press release submit page
  • Privacy policy