Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Tuesday, May 13, 2025

Cyberattack on Marks & Spencer: Customer Risks and the Broader Wave of Retail Hacks




In April 2025, Marks & Spencer (M&S), one of Britain’s most iconic high-street retailers, fell victim to a devastating cyberattack that disrupted its operations and compromised customer data. The incident, linked to the notorious hacking group Scattered Spider and the DragonForce ransomware, has not only cost M&S millions but also raised serious concerns about customer safety and the vulnerability of UK retailers to cybercrime. This attack is part of a broader wave of cyberattacks targeting major retailers like the Co-op and Harrods, signalling an alarming trend in the retail sector. This article explores the M&S hack, its risks to customers, and the implications of these ongoing cyber threats.
The M&S Cyberattack: What Happened?
The cyberattack on M&S began over the Easter weekend in April 2025, when customers reported issues with contactless payments and click-and-collect services. On April 25, M&S confirmed it was dealing with a “cyber incident” and suspended all online orders, a critical revenue stream accounting for roughly one-third of its clothing and home sales. The attack, believed to be a ransomware assault, encrypted M&S’s servers, halting online operations and disrupting in-store services. More than three weeks later, online ordering remains paused, and some in-store services, such as gift card acceptance, are still affected.
 
The hacking group Scattered Spider, also known as Octo Tempest, is suspected of orchestrating the attack using DragonForce ransomware. This group, comprising young, English-speaking hackers, employs sophisticated social engineering tactics, including phishing, SIM swapping, and impersonating IT help desk staff to gain access to systems. In the case of M&S, hackers reportedly tricked IT workers into resetting employee passwords, allowing them to breach the network. The attack has wiped over £700 million ($930 million) off M&S’s market value, with daily revenue losses estimated at £3.8 million ($5.05 million) due to the online shutdown.
 
On May 13, 2025, M&S confirmed that customer data, likely including names and addresses but not payment details or passwords, had been compromised. While the retailer stated there is no evidence the data has been shared, the breach poses significant risks to customers, as outlined below.
Risks to M&S Customers
The compromise of customer data, even without payment details, exposes M&S shoppers to several risks:
  1. Phishing and Social Engineering Attacks: Hackers with access to names and addresses can craft highly targeted phishing emails or text messages, posing as M&S or other trusted entities to trick customers into revealing sensitive information, such as login credentials or financial details. These attacks exploit trust in the brand and can lead to identity theft or financial fraud.
  2. Identity Theft: Personal information like names and addresses can be combined with other data available on the dark web to build comprehensive profiles for identity theft. Criminals may use this information to open fraudulent accounts, apply for credit, or commit other forms of fraud in victims’ names.
  3. Reputational Damage and Loss of Trust: The prolonged disruption and data breach risk eroding customer confidence in M&S. As consumer expert Kate Hardcastle noted, “In today’s hyper-connected world, silence can be unsettling, particularly when trust and transparency are the most valuable commodities a brand can offer.” Customers may hesitate to shop with M&S, fearing further breaches.
  4. Potential for Future Exploitation: Even if the stolen data hasn’t been shared yet, hackers may hold it for future ransom demands or sell it on the dark web. The DragonForce group has claimed to have stolen millions of customers’ data and is pressuring M&S to pay a ransom, potentially in the millions of pounds, to prevent its release.
M&S has advised customers to monitor their accounts and be vigilant for suspicious activity, but the lack of a clear timeline for full recovery and limited communication has fuelled concerns about transparency. The National Cyber Security Centre (NCSC) recommends that customers use strong, unique passwords across platforms and check for updates from M&S regarding the breach.
Other Ongoing Cyberattacks: Co-op and Harrods
The M&S attack is not an isolated incident but part of a broader wave of cyberattacks targeting UK retailers. In the same week, the Co-op and Harrods reported similar incidents, raising fears of a coordinated campaign or vulnerabilities in shared systems like SAP, widely used in the retail sector.
The Co-op Hack
The Co-op, a major UK supermarket chain, disclosed on April 30, 2025, that it had shut down parts of its IT systems to fend off an attempted hack. The attack, also linked to DragonForce, compromised a significant amount of customer and employee data, including names, contact details, and dates of birth. Unlike M&S, the Co-op’s stores and funeral homes continued trading as usual, but back-office and call centre services were disrupted. To prevent further breaches, Co-op staff were ordered to keep cameras on during remote meetings and verify all attendees, indicating concerns about hackers infiltrating virtual calls.
 
The Co-op hack highlights similar risks to customers, particularly phishing and identity theft, as the stolen data could be used to target members. The NCSC has urged firms to review IT help desk password reset processes, as hackers exploited this vulnerability by impersonating employees to gain access.
Harrods Cyberattack
On May 1, 2025, luxury department store Harrods confirmed it was targeted by a cyberattack, becoming the third major UK retailer hit within a week. The store restricted internet access across its sites, including its Knightsbridge flagship, as a precaution after detecting attempts to gain unauthorised access. Harrods’ IT security team acted swiftly, and the retailer reported no evidence of customer data being compromised. All stores and the Harrods website remained operational, but the incident underscores the growing threat to retailers handling vast amounts of customer data.
 
Harrods has not disclosed whether the attack was linked to DragonForce or Scattered Spider, but cybersecurity experts suggest the timing and nature of the attacks on M&S, Co-op, and Harrods may indicate a shared vulnerability, such as a compromised supplier or technology. Toby Lewis of Darktrace noted that the incidents could be coincidental, but a common entry point or heightened vigilance following the M&S attack may have prompted other retailers to detect breaches.
Broader Implications and Industry Response
The cyberattacks on M&S, Co-op, and Harrods expose systemic vulnerabilities in the retail sector, which processes over 48 billion payments annually and relies heavily on digital infrastructure. Cybersecurity experts warn that retailers are prime targets due to the volume of identity and payment data they hold and their expanding attack surfaces through e-commerce and mobile platforms. Xavier Sheikrojan of Signifyd emphasised, “Retailers are prime targets because of the volume of identity and payment data they hold,” while Anton Yunussov of Forvis Mazars called for cybersecurity to be treated as a “strategic business priority” rather than just an IT issue.
 
The UK government and NCSC have responded with urgency. Cabinet Office Minister Pat McFadden, speaking at the CyberUK conference, described the attacks as a “wake-up call” for companies to prioritise cybersecurity. The NCSC is working with affected retailers and has issued guidance on securing IT help desk processes and monitoring for “risky logins” to prevent social engineering attacks. The Metropolitan Police’s Cyber Crime Unit and the National Crime Agency are investigating the M&S attack, with six arrests of suspected Scattered Spider members in the UK and US over the past year.
 
Retailers are now on high alert, with many reviewing their cybersecurity defences. However, experts like Jordan Jewell of VTEX warn that “no company is immune” as complexity increases with more systems, vendors, and data. The food and beverage industry, in particular, has been criticised for weak defences, with an M&S employee telling Sky News that the retailer lacked a business continuity plan for such an attack.
What Can Customers Do?
Customers of M&S, Co-op, and Harrods can take proactive steps to protect themselves:
  • Monitor Accounts: Regularly check bank statements and accounts for unauthorised activity.
  • Use Strong Passwords: Create unique, complex passwords for each platform and avoid reusing them.
  • Enable Two-Factor Authentication: Add an extra layer of security to online accounts.
  • Be Wary of Phishing: Avoid clicking links or sharing personal information in unsolicited emails or texts claiming to be from these retailers.
  • Stay Informed: Check for updates from M&S, Co-op, or Harrods regarding the breaches and follow NCSC advice.
Looking Ahead
The cyberattacks on M&S, Co-op, and Harrods underscore the growing sophistication and audacity of cybercriminals, with groups like Scattered Spider and DragonForce exploiting human and technical vulnerabilities. For M&S, the financial toll—estimated at £30 million in initial profit losses and £15 million weekly—pales in comparison to the potential long-term loss of customer trust. While analysts like Adam Cochrane of Deutsche Bank believe M&S will recover due to strong consumer loyalty, the retailer must act swiftly to restore services and rebuild confidence.
 
The broader retail sector faces a critical juncture. As Helen Dickinson of the British Retail Consortium noted, cyberattacks are becoming “increasingly sophisticated,” requiring retailers to invest heavily in defences. The government, NCSC, and industry must collaborate to strengthen cybersecurity, address skill shortages (only 4% of UK firms are fully prepared for complex threats, per Cisco), and treat digital infrastructure as critical. Until then, customers and retailers alike remain vulnerable to the next wave of attacks, which DragonForce has ominously warned is “just the start.”

Thursday, February 15, 2024

Southern Water Hacked

Southern Water are sending out emails to customers wrt a recent hack of their database.

"Cyber attack: important information about your personal data  

I am very sorry to inform you that Southern Water has been the target of an illegal cyber attack, which has unfortunately affected the security of some of your personal data, as one of our customers.

We are currently conducting an intensive investigation into this, supported by industry experts and following guidance from our regulators together with the National Cyber Security Centre. Our operations and services have not been impacted and your water supply is unaffected.

As a result of this investigation, we have reason to believe that the data stolen and at risk, and which relates to you, may include:

  • Basic personal details for administering your account and identifying you, such as your name and contact details. This may include your national insurance number and date of birth if you have provided these details to us.

  • Financial information including your sort code, bank account number and payment reference number.

What we are doing to reduce the risk to you  

Southern Water takes its data protection and information security responsibilities to you seriously, and so we are bringing this to your attention as soon as we can. We are working closely with the regulatory authorities. We have notified the Information Commissioner’s Office and are in regular contact with the National Cyber Security Centre. In addition, we have taken further steps, with support from independent cybersecurity experts, to enhance the security monitoring of our IT infrastructure.

We have also engaged a reputable third party to monitor the dark web on our behalf. They report that, since we were named on the cyber criminals’ site on 22 January 2024, they have found no new evidence of data potentially compromised by this cyber incident being published online. They will continue to carry out these checks for as long as necessary.

To ensure that we’re doing everything we can to look after you, we are offering you a 12-month, free-of-charge, enhanced Experian credit monitoring membership. This service provides identity monitoring and helps detect possible misuse of your personal information. It also supports identification and resolution of identity theft incidents....

What is the background?  

On 22 January 2024 we became aware that a cyber criminal organisation was claiming on its website to have stolen data from some of our IT systems.

We had previously detected suspicious activity and launched an investigation, as well as enhanced monitoring and other precautionary measures. Our independent cyber security specialists continue to investigate.

What happens next?  

The information we have provided is based on what we know at this time. Our investigation remains active, and should we receive any additional material information, we will contact you.

Once again, I am very sorry that this has happened and for any inconvenience this illegal breach of data may cause you. We are working closely with the authorities and industry experts, to do everything possible to manage the situation and support you at this time.

Please call our dedicated customer service team on 0330 303 0025 if you have any questions.

FURTHER INFORMATION  

The National Cyber Security Centre, the Financial Conduct Authority and the Information Commissioners Office all provide helpful information to help protect your data and prevent fraud. This is summarised below with some useful links.

- Stay alert against any suspicious calls, texts or emails which could be a scam. If you receive any suspicious messages or calls, do not hand over any information such as your bank account details. Instead, hang up, or delete any worrying texts or emails and then contact your bank to report the suspicious activity. The FCA has some useful information on how to spot the warning signs of financial scams at www.fca.org.uk/consumers/protect-yourself-scams.

- Cyber criminals commonly use a scam technique called “phishing”, which is mostly email-based but can also be via telephone calls, to lure victims under false pretences to websites which appear legitimate to get them to provide information including bank account and credit card details. These emails/phone calls appear to be from recognisable sources such as banks but actually link to fraudulent websites. To help prevent phishing:

  • Protect your email with a strong password.

  • Do not share your password with anyone.

  • Install the latest security updates to your browser software and personal computing devices.

  • If in doubt, do not open emails from senders you do not recognise.

  • Check links look correct before you click on them.

  • Be suspicious of anyone who asks for your bank account or credit card details.

  • If the email contains spelling mistakes, this can be a sign that this is a phishing scam. Do not open the email or attachments.

- More helpful information on how to protect your data can be found on the National Cyber Security Centre’s website - www.ncsc.gov.uk/guidance/data-breaches and the Information Commissioner’s Office website – www.ico.org.uk/for-the-public/identity-theft and www.ico.org.uk/for-the-public/online."

Summary

  • Southern Water, a UK water utility company, confirmed that their IT systems were compromised in a cyberattack in January 2024.
  • Hackers stole data from a "limited portion" of their server infrastructure, affecting potentially hundreds of thousands of customers.
  • The data breach was claimed by the Black Basta ransomware group, who threatened to release the stolen information unless a ransom was paid.
  • Southern Water has not confirmed the extent of the data stolen, but reports suggest it may include names, addresses, and contact information.

Current situation:

  • Southern Water is working with cybersecurity experts to investigate the breach and monitor the dark web for any signs of leaked data.
  • No evidence of the stolen data being published online has been found so far.
  • The incident has been reported to the UK's Information Commissioner's Office.

Impact:

  • The affected customers have been notified and are advised to be cautious of phishing attempts or suspicious activity.
  • The full impact of the breach is still being assessed, but it could potentially lead to identity theft, financial fraud, or other forms of harm.

Additional resources:

 

Tax Investigation Insurance

Market leading tax fee protection insurance for businesses, sole traders and individuals. Protect yourself from accountancy fees in the event of an HMRC enquiry.

Having a Solar Protect Tax Investigation Insurance policy at your disposal means that should you be one of the many 1000's of businesses or individuals that are selected by HMRC each year to look into your tax affairs your own accountant (your tax return agent) can get on and defend you robustly.

You have the peace of mind knowing that your accountant's (your tax return agent) fees will be paid by the insurance without any Excess for you to find.

Tax Investigation Insurance is an insurance policy that will fully reimburse your accountant's (your tax return agent) fees up to £100,000 if you are subject to enquiry by or dispute with HMRC.

A Solar Protect policy will enable your accountant (your tax return agent) to:

  • Deal with any correspondence from HMRC
  • Attend any meeting with HMRC
  • Appeal to the First-tier Tribunal or Upper Tribunal
  • Having the security of knowing that fees will be met in full will enable your Accountant (your tax return agent) to defend your position robustly

Please click here for details.

Wednesday, June 07, 2023

Clop Hacks BBC, Boots and BA



A Russian cybercriminal group called Clop has hacked into the payroll service provider Zellis, which provides payroll services to a number of large British companies, including British Airways, Boots, and the BBC. The hackers stole the personal data of tens of thousands of employees at these companies, including names, addresses, Social Security numbers, and dates of birth.

Clop is a ransomware group operating in Russia, that has been active since 2019. Ransomware is a type of malware that encrypts a victim's files and demands a ransom payment in order to decrypt them. Clop is known for using a variety of techniques to infiltrate victim networks, including phishing emails, exploiting vulnerabilities in software, and using brute force attacks.

The BBC has said that the hack will not impact its programming or operations. However, the hack is a reminder of the growing threat of cyberattacks. Businesses of all sizes need to take steps to protect their data from cybercriminals. These steps include:

  • Implementing strong security measures: This includes using firewalls, antivirus software, and intrusion detection systems.
  • Educating employees about cybersecurity risks: This includes teaching employees how to spot phishing emails and how to create strong passwords.
  • Regularly backing up data: This will help to minimize the damage if a cyberattack does occur.
  • Having a plan in place to respond to a cyberattack: This plan should include steps for notifying employees, restoring data, and investigating the incident.

Conclusion:

The Clop hack of BA, Boots, and the BBC is a serious incident that highlights the importance of cybersecurity. Businesses need to take steps to protect their data from cybercriminals. By implementing the steps outlined in this blog post, businesses can help to mitigate the risk of a cyberattack.

Call to action:

If you are a business owner, I encourage you to take steps to protect your data from cybercriminals. By implementing the steps outlined in this blog post, you can help to mitigate the risk of a cyberattack.

This is a serious hack that could have a significant impact on the affected companies. It's important for businesses to take cybersecurity seriously and to implement strong security measures to protect their data.

Tax Investigation Insurance

Market leading tax fee protection insurance for businesses, sole traders and individuals. Protect yourself from accountancy fees in the event of an HMRC enquiry.

Having a Solar Protect Tax Investigation Insurance policy at your disposal means that should you be one of the many 1000's of businesses or individuals that are selected by HMRC each year to look into your tax affairs your own accountant (your tax return agent) can get on and defend you robustly.

You have the peace of mind knowing that your accountant's (your tax return agent) fees will be paid by the insurance without any Excess for you to find.

Tax Investigation Insurance is an insurance policy that will fully reimburse your accountant's (your tax return agent) fees up to £100,000 if you are subject to enquiry by or dispute with HMRC.

A Solar Protect policy will enable your accountant (your tax return agent) to:

  • Deal with any correspondence from HMRC
  • Attend any meeting with HMRC
  • Appeal to the First-tier Tribunal or Upper Tribunal
  • Having the security of knowing that fees will be met in full will enable your Accountant (your tax return agent) to defend your position robustly

Please click here for details.