logo
How working from home made Britain a sitting duck for cyber attackers

How working from home made Britain a sitting duck for cyber attackers

Telegraph01-05-2025
Former M&S boss Lord Stuart Rose has long branded himself an 'unreconstructed get-back-to-work man', claiming the practice of working from home is damaging both the economy and employees' wellbeing.
Now, the 76-year-old businessman may have another reason to oppose remote working – with the arrangement possibly putting one of Britain's best-loved retailers, and his former employer, at the mercy of hackers.
Since Easter weekend, M&S has been reeling from a major cyber attack that has paralysed online orders, disabled contactless payments in-store, and wiped nearly £700 million off its market value.
And M&S is not the only retailer that has been subjected to such an attack. Earlier this week, the Co-op said it was having to fend off hackers and, on Thursday evening, luxury department store Harrods said they had 'recently experienced attempts to gain unauthorised access to some of their systems'. In a statement, the store added: 'Our seasoned IT security team immediately took proactive steps to keep systems safe and as a result we have restricted internet access at our sites.'
Harrods said all its stores remained open and it is unknown if the three attacks are related.
Though M&S bosses have yet to reveal the cause, questions are mounting over whether the hackers were able to penetrate the multibillion-pound firm's cyber defences through one of its remote workers.
It would not be a surprise as for years security experts and intelligence agencies have warned that hackers are targeting remote workers as the weakest link in the chain in a company's digital infrastructure.
Indeed, just last year the retailer – which is understood to allow staff to work two days a week at home – warned in its annual report that WFH was increasing its exposure to cyber attacks.
But why? The answer is simple – computers in most corporate offices have a vast array of tough defences installed to keep bad actors out, from firewalls to secure internet routers, all of which are kept under close watch by the on-site security team.
Yet such protection wanes as soon as staff are out the revolving doors. Suddenly, the onus falls instead on the employee, whether it's keeping their devices updated or being vigilant when using unsecured public WiFi while working in cafes.
A survey by Malwarebytes Lab, carried out around six months after the first Covid lockdown, found one in five businesses had faced a security breach as a result of a remote worker.
Four years later, a poll by Absolute Security in 2024 revealed three out of four bosses still believed staff working from home was their 'biggest weakness' when trying to defend against cyber attacks.
How do the hackers get in?
Experts believe M&S was infected by a ransomware called Dragonforce, a malicious software that locks a user out of their computer or network and scrambles the data – with the criminals demanding a fee to unlock it.
In its rush to contain the attack, M&S bosses quickly moved to lock remote-working staff out of the company's internal IT systems. But could these remote workers have also been the crucial weakness that let the hackers in?
To infect a computer, hackers need to find a chink in digital defences – and staff working from home can often be easy prey. A common target is through a virtual private network (VPN), used by remote employees to securely connect to their office networks.
Such software is only useful if it's kept up-to-date and uses multi-factor authentication, which requires several forms of verification to access. In 2021, investigators traced the huge ransomware attack that took down the Colonial Pipeline – which supplies 45 per cent of United States' fuel on the East Coast – to an old version of a VPN account commonly used by remote employees.
The same year, a hacker gained control of the Oldsmar water treatment plant in Florida, and tried to poison the supply by increasing the chemical content, through a remote access software called TeamViewer. All the plant's computers were using the same password for remote access, and were running on an outdated Windows operating system.
In other words, both were ripe for exploitation. In 2022, an alert by the Five Eyes intelligence alliance warned that the Microsoft software, Remote Desktop Protocol (RDP), that linked 'millions' of Britons to their company networks, was 'one of the top ways' Russian hackers could potentially gain a crucial foothold within critical infrastructure, from the NHS to nuclear power stations.
Yet often, the real weakness is not a system flaw but the people behind the systems – either the security team or the employees themselves. One of the most popular methods of gaining unauthorised access is 'social engineering', which involves tricking humans into compromising their security.
Such tactics were used in the attack on Twitter in July 2020 when a 17-year-old boy was able to gain access to 130 celebrity Twitter accounts – including Barack Obama, Kim Kardashian, and its future owner Elon Musk – to promote a Bitcoin scam.
An investigation by the New York State Department of Financial Services found the teen had 'directly exploited Twitter's shift to remote working' by calling up employees and pretending to be from the IT department to get access to the internal systems.
Who carried out the M&S attack?
Earlier this week it was revealed the Met Police are investigating whether the M&S attack was carried out by a hacking collective called Scattered Spider. The group first appeared in 2022 and have already been linked to more than 100 targeted attacks, including US casino operator Caesars, which paid over £11 million to restore its network.
Unlike the majority of such gangs, who are generally based in places such as Russia, the group are English-speaking and known to include UK and US citizens, some as young as 16. Their motivation is said to be as much about bragging rights as money.
According to the FBI, the group's modus operandi is tricking people into letting them into their systems, from impersonating IT staff to 'sim swapping', a tactic in which a fraudster persuades their victim's mobile provider to transfer the phone number to a sim card under their control.
'Scattered Spider have been linked to dozens of attacks over the last few years and their clever tactics often target the human element,' Jake Moore, global security advisor at cybersecurity software company ESET, tells The Telegraph. Moore points to remote workers in particular as a potential target. 'Working from home adds yet another attack entry point which has limited control.'
'Hybrid work has made enforcing security standards a minefield'
He reveals how, as a test, he once hacked into the work account of a superintendent simply by calling the Police HQ help desk. 'They asked me two security questions, which were easy to find out the answers to online – vehicle registration and shoulder number – and then I was able to convince them I was the superintendent and had forgotten my password after being on holiday for two weeks.
'They reset the password to a new string of text and gave me the password over the phone. I then logged in and had full access to the police networks. At this point I made the chief constable aware of this vulnerability.'
The heightened danger of WFH on M&S's cybersecurity is not a view shared by all however. 'That's total BS as far as I'm concerned,' says Ciaran Martin, ex-chief executive of the UK's National Cyber Security Centre (NCSC). 'I don't have a strong view on either side of the culture war, but it's not a thing, so far as I understand the details in this incident specifically.
'I was head of the NCSC when lockdown one happened, and I was stunned at how little rise there was in cyber harm when we went on an unplanned, short-notice experiment in home working. Turns out the bring your own device security and other remote working things we'd been doing for years before 2020 worked pretty well. We have many systemic problems in cyber security but remote working isn't on my list!'
But the NCSC is clearly aware of the vulnerabilities, saying in an advisory note published in April 2020 that 'the surge in home working has increased the use of potentially vulnerable services… amplifying the threat to individuals and organisations'.
Often, remote workers are the first in line to have their access removed from internal systems when there is an attack – suggesting security teams are wary of the threat. As it battled to contain damage from its cyber attack, on Wednesday, Co-op told staff they could no longer log on to the company's IT system from home, a 'proactive measure' it explained after detecting 'third parties' trying to break in over the weekend.
Indeed, experts warn the threat to companies from remote work is only rising with the advent of generative AI, the technology behind chatbots. Not only is it making social engineering easier, both in terms of scale and its believability, but it is also inadvertently giving away vast swathes of confidential company data to third parties that in-house security teams have no ability to protect.
'Hybrid work has made enforcing security standards a minefield,' says Arkadiy Ukolov, co-founder of Ulla Technology. 'Employees increasingly rely on AI-powered tools such as ChatGPT – often outside corporate oversight – unaware that these systems may quietly harvest client data to train their models. This opens doors to data leakages where third parties gain access to very sensitive information.'
'The risk isn't theoretical – it's happening in the background, right now,' he adds. In response, the London-based firm has developed an AI-powered assistant that can be integrated into a company's infrastructure to keep the data private. 'The most vulnerable industries are the legal sector, government departments and the NHS.
'Their employees manage highly sensitive information such as intellectual property, corporate secrets and medical documents on a daily basis. For them, poorly managed hybrid working systems pose an existential security threat.'
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Aggressive job cuts fuelled by Reeves £25bn NI tax raid: Employers cut staff for 11 months in a row
Aggressive job cuts fuelled by Reeves £25bn NI tax raid: Employers cut staff for 11 months in a row

Daily Mail​

time3 hours ago

  • Daily Mail​

Aggressive job cuts fuelled by Reeves £25bn NI tax raid: Employers cut staff for 11 months in a row

Britain's private sector employers have been cutting jobs for 11 months in a row in the latest evidence of the damaging impact of Labour's £25billion employer national insurance raid. A closely-watched business survey by financial firm S&P Global showed job numbers were being reduced 'at an aggressive rate' in August. 'Employment was again a weak spot as total workforce numbers decreased for the 11th month running and at a marked pace,' the report said. Separate data showed the number of new job postings fell in July after firms 'took a kicking' from last autumn's Budget. Businesses are still counting the cost of the rate of employer National Insurance (NI) rising from 13.8p per cent to 15 per cent and the cut in salary threshold for paying it from £9,100 to £5,000. The move has sharply raised the cost of hiring staff and particularly damaged sectors such as retail and hospitality that are more reliant on lower-paid and part-time workers. It has been largely blamed for the sharp rise in unemployment since the general election, with more than 200,000 people joining the dole queue. S&P's findings were revealed as part of a wider purchasing managers' index (PMI) survey of the private sector which showed business activity growing at the fastest pace in a year. The findings will be welcomed by Rachel Reeves as she hopes for a turnaround after a growth slowdown in the second quarter. But they showed a contrast between accelerating growth in the services sector, which ranges from bars and hotels to accountants and solicitors, and contraction for manufacturers battered by tariff uncertainty. The report also outlined the continuing pain being caused by the Chancellor's NI hike. It resulted in 'another robust rise in prices charged by private sector firms' this month – with inflation at an 18-month high. 'Payroll numbers... continue to be cut at an aggressive rate by historical standards as firms cite weak order books and concerns over rising staff costs due to the policies announced in the autumn Budget,' said Chris Williamson, the chief business economist at S&P Global. Separately, the Recruitment and Employment Confederation, said a 'summer slowdown' had hit new job postings which fell 9.2 per cent last month compared to June, to 652,733. Chief executive Neil Carberry said: 'Business optimism took a kicking after last autumn's Budget, with spring tax rises in particular weighing on employers thinking. 'The fear of further costs, worries about the impact of the Employment Rights Bill and new tax rules are all on employers' minds. 'If ministers want growth, they must deliver stability and backing for businesses.' On a brighter note, a monthly consumer confidence reading published by market research firm GfK ticked higher following this month's Bank of England interest rate cut. Neil Bellamy, consumer insights director at GfK, said: 'The improved sentiment on personal finances is welcome, but there are many clouds on the horizon in the form of inflation and rising unemployment. 'There's no shortage of speculation, too, about what the autumn Budget will bring in terms of tax rises.'

Speciality Steel UK plunges into administration putting 1,500 jobs at risk as Government takes control
Speciality Steel UK plunges into administration putting 1,500 jobs at risk as Government takes control

Scottish Sun

time4 hours ago

  • Scottish Sun

Speciality Steel UK plunges into administration putting 1,500 jobs at risk as Government takes control

Judge Edward Mellor deemed it 'hopelessly insolvent' with just £600,000 in the bank STEEL SETBACK Speciality Steel UK plunges into administration putting 1,500 jobs at risk as Government takes control Click to share on X/Twitter (Opens in new window) Click to share on Facebook (Opens in new window) THE Government yesterday took control of Britain's third largest steelworks — putting 1,500 jobs at risk. Speciality Steel UK, pictured above, collapsed into administration as the High Court granted a ­compulsory winding-up order. Sign up for Scottish Sun newsletter Sign up It owes creditors hundreds of ­millions of pounds. The company is part of the Liberty Steel Group founded by controversial tycoon Sanjeev Gupta. Judge Edward Mellor deemed it 'hopelessly insolvent' with just £600,000 in the bank — and a monthly wage bill of £3.7million. The steelworks employs 1,450 people in Rotherham and Sheffield, South Yorks. It will be taken over by the Official Receiver and special managers from consultancy firm Teneo — appointed to run it on behalf of the liquidator. But Speciality Steel bosses slammed the move to wind up the business. Its chief transformation officer Jeffrey Kabel claimed a plan by Mr Gupta's parent business GFG — presented to the court — would have secured new investment. Mr Kabel said: 'The decision to push Speciality Steel UK into compulsory liquidation is irrational — especially when we have support from the world's largest asset manager to resume operations and facilitate creditor recovery. 'Instead, liquidation will impose prolonged uncertainty and significant costs on UK taxpayers for settlements and expenses.' 1 Speciality Steel UK collapsed into administration putting 1,500 jobs at risk Credit: AFP M&S JOBS LIFT MARKS & SPENCER is planning to build a huge automated distribution centre which will create 3,000 jobs — as it aims to double the size of its food business become a 'destination for the weekly shop'. M&S — recently crippled by a cyber attack — is investing £340million in the Northants warehouse, opening in 2029. MD Alex Freudmann said it would boost product availability and lower long-term costs. Scottish firm goes bust after plunging into administration SMITH'S SLIPS WH SMITH saw its share price plunge as it revealed an accounting error in the US means its yearly profits will be lower than expected. Shares in the London-listed retailer were down by about a third in early trading. The firm discovered its North America trading profit had been overstated by about £30million — meaning it now expects it to be about £25million for the year to August.

Toronto stocks subdued amid caution ahead of Jackson Hole meet
Toronto stocks subdued amid caution ahead of Jackson Hole meet

Reuters

time10 hours ago

  • Reuters

Toronto stocks subdued amid caution ahead of Jackson Hole meet

Aug 21 (Reuters) - Canada's main stock index was subdued on Thursday, as investors awaited news from the U.S. Federal Reserve's three-day Jackson Hole symposium that could offer more clarity on monetary policy in the world's biggest economy. At 9:50 a.m. ET (1350 GMT), the Toronto Stock Exchange's S&P/TSX composite index (.GSPTSE), opens new tab was up 0.02% at 27,883.78 points. Resource-driven stocks remained one of the biggest supports for the main index. TSX's materials sector (.GSPTTMT), opens new tab gained 0.8%. The technology sector (.SPTTTK), opens new tab restrained overall gains, down 0.4%, tracking losses in Wall Street's tech-heavy Nasdaq (.IXIC), opens new tab. The Fed's annual conference begins on Thursday, with the spotlight on Chair Jerome Powell's speech on Friday to gauge the likelihood of a rate cut at the central bank's upcoming meeting. "Markets are somewhat on hold ... Investors and market participants want to wait and see what's going to come out of that symposium," Chris McHaney, executive vice president and head of investment management and strategy at Global X. According to the CME Group's FedWatch tool, the odds of a 25-basis-point cut at the September 16–17 meeting are 79.2%. Additionally, a weekly U.S. labor report showed that the number of jobless claims rose by the most in about three months last week. In Canada, producer prices unexpectedly rose by 0.7% in July from June on higher prices for energy and petroleum products, as well as primary non-ferrous metal products The data contrasts this week's softer consumer inflation report, which had bolstered expectations that the Bank of Canada could resume its rate-cutting cycle. "It complicates it (rate cut path) for Canada.... It's still to be seen how much these producer prices are going to feed through," Global X's McHaney added. Traders expect at least one rate cut later this year, as the Canadian central bank has kept the benchmark rate unchanged at 2.75% since March.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store