What the M&S and Harrods Attacks Taught UK Tech

In spring 2025, a group of young English-speaking hackers, later linked to the Scattered Spider collective, brought Marks & Spencer to its knees. Online orders were paused for 46 days, and full recovery of services like Click & Collect stretched into the summer. Shelves sat empty.

Around £300 million was wiped from the company’s projected profits. Harrods and the Co-op were caught up in the same wave. These were not the kinds of startups that had a small team of people with the IT title. Some of the names on the British high street had been amongst the largest. That’s why it’s important. It’s time to examine the problem and what smaller firms can learn.

What the M&S and Harrods Attacks Taught UK Tech

A Phone Call Was All It Took

It wasn’t a sophisticated piece of malware or a zero-day exploit that caused the M&S breach; it was a simple piece of code. It all began with a call. The impersonators, who belonged to a group dubbed Scattered Spider, called the retailer’s outsourced IT helpdesk service, operated by Tata Consultancy Services (TCS), and claimed to be its employee. The helpdesk agent proceeded to reset the password, and once there, the attackers were able to gain a foothold in the network.

In just a few days, they compromised the AD database with the password hashes for all domain users; they hacked the hashes offline and installed the DragonForce ransomware in M&S’s infrastructure. It all started when someone took an approach and was helpful when answering the phone.

It’s the most effective way to do social engineering. It would have been impossible to block with any firewall. Any antivirus program would not have detected it. The attackers were able to speak fluent English and corporate jargon, and create urgency.

In the wake of those attacks, both Microsoft and the NCSC have warned of groups such as Scattered Spider starting to use AI to refine their scripts and to mimic accents and fake on-the-fly pretexts. It’ll make it even tougher to do a quick check on the calls to the helpdesk in the next wave. The NCA was to go on to arrest four suspects, ranging from 17 to 20 years old.

Big Budgets Don’t Mean Big Protection

Millions of pounds are being spent each year on the security of M&S computer systems. It is backed by teams, third-party partners, and has an established IT infrastructure. Yet, it was an interaction with a third-party provider that wasn’t properly verified that caused the breach.

The same trend will continue across the sector. Most of the founders and tech leaders think that the bigger the scale, the safer. More resources, more tools, more staff – larger companies. However, they also come with a larger attack surface.—more suppliers, more endpoints, more people that can be fooled.

Harrods prevented its incident early in May this year by limiting internet access to its stores. But even Harrods wasn’t spared from supply chain risk. An earlier hack, in September, via a third-party supplier, leaked approximately 430,000 customer records. The message is clear: If your security system is weak at any point, it’s weak at all points.

Third-Party Providers Are a Blind Spot

Possibly the most important lesson to be learned from the attack on M&S is that the company had very little control over its own front door. It doesn’t seem the attackers had to gain access to M&S itself. They only had to persuade someone at the contractors’ desk to reset a password, and then later reset the MFA on a privileged account.

This is becoming an increasing issue throughout the UK tech industry. Helpdesks, cloud management services, payroll systems, and development are outsourced. There are possible entry points in each of those relationships. And most of the companies do not inspect their partners’ identity verification or access request procedures.

If you work with external IT providers, you’ll want to ask a few direct questions:

  • Who can reset passwords or MFA tokens, and what verification will they require?
  • Are helpdesk staff trained to spot social engineering attempts?
  • How quickly will your provider notify you of a suspicious access request?

If the answers are vague, that’s a red flag.

How Pen Testing Exposes What You Can’t See

Technical audits and vulnerability scans can certainly be useful. Still, they won’t detect the kind of vulnerability that brought down M&S. A vulnerability scanner will not call your helpdesk and attempt to convince them to let itself in! This is where penetration testing can come in handy, especially when it includes both social and technical tests.

This is where UK pen testing companies that combine technical assessments with social engineering tests come in. These tests are being used by businesses across the UK to gain clarity on real business needs. A good test will determine whether your employees would give their credentials to a believable caller, whether third-party suppliers are taking the appropriate steps to verify them, and whether the network segmentation will stand up if someone gains access. The difference between knowing that you have a locked door and knowing if somebody could talk their way past it.

This type of testing need not be a giant-sized operation for startups and the expanding tech enterprises. Even if you examine your most important systems and access points, you’ll still have a much better sense of where you’re at.

What Smaller Companies Should Do Now

In a way, it’s easy to disregard the M&S breach and assume it could only happen to a large store. However, Scattered Spider’s tactics can be employed with companies of all sizes. Social engineering does not concern itself with revenue or number of employees. Smaller teams are even worse, as they tend to lack formal verification processes and are typically highly dependent on trust.

Strengthen identity authentication wherever individuals can request access or reset their identity. That will be an in-house team and external provider. Conduct social engineering exercises. Don’t think that your MFA setup is infallible. M&S attackers were not able to crack MFA, but did them a favor by getting the outsourced helpdesk to reset it on a privileged account.

Preparation Beats Reaction Every Time

The attacks on M&S and Harrods will be analyzed for years, but the bottom line is not rocket science. Nowadays, attackers are most likely to make their way in through social engineering. A significant problem is third-party providers. You’ll not be able to cover up chinks in human processes with big security budgets.

Those that emerged from the wave of 2025’s retail attack in good shape were the early-warning and quick-action takers, such as Harrods. Such a reaction won’t occur without a reason. It will be from testing your defenses BEFORE someone else does; it will be training your people to know how to detect manipulation; it will be treating the access requirements of every partner as if they were your own.

Popular on OTW Right Now!

Add a Comment

Your email address will not be published. Required fields are marked *