
Reasons M&S and Co-op were hacked - and why more retailers might be next
Marks & Spencer (M&S). Co-op. Harrods. Dior. A government legal aid office. A food distributor that supplies Tesco, Sainsbury's and Aldi.
A raft of retailers and suppliers have been the targets of cyber incidents in recent weeks.
Today alone, it has emerged that the logistics firm Peter Green Chilled and the Danish food giant Arla Foods have been hit by cyber crooks.
Hackers wriggled into computer systems and stole some customer data, like dates of birth and addresses.
Co-op shut down its IT system to prevent hackers from snatching personal and financial information like shopper passwords or bank details.
The cyber incidents caused company stocks to tumble, and shoppers were contending with empty shelves and deliveries being paused.
But why are these retailers being targeted?
Joe Jones, CEO of the cybersecurity attack simulation company Pistachio, said that while the upmarket retailer seems like a rogue choice for hackers to go for, it makes a lot of sense.
'M&S is a household name with a vast and loyal customer base, which makes it a high-value target for cybercriminals,' he told Metro.
'Large retailers hold enormous amounts of personal data, everything from names and addresses to detailed purchase histories. That kind of data is gold dust for attackers running social engineering scams or looking to sell verified profiles on the dark web.'
M&S, like many retailers, isn't just a brick-and-mortar store. It's websites, mobile apps, marketing emails and delivery services that amount to more 'digital touchpoints that can be exploited'.
'It's not necessarily that M&S was uniquely vulnerable; rather, it's a classic case of 'big brand, big data, big target',' he added.
James Hadley, the founder of the Bristol-based cybersecurity firm Immersive, said M&S isn't alone.
'Retail isn't as heavily regulated as, say, financial services, so the burden of proof is lower on how you demonstrate and prove cyber security,' he told Metro.
'It's impossible to be 100% secure and all it needs is one supplier, one connection, one partner, one employee, one misconfiguration, and the attackers can get in and detonate the malware,' he added, referring to malicious software.
Hackers who claim to be behind the cyber attack on Co-op said they infected the grocer's IT systems with ransomware, which involves breaking into a computer network and locking up information until the victim pays.
Hadley added: 'You could have 1,000 technical controls and, if one person gets in, it's all over.'
In other words, retailers are easy targets. M&S, founded in 1884, has had decades to build a 'sprawling IT estate'.
Stressing that he's speaking 'hypothetically', Hadley said: 'You have all this breadth and depth… that is a much harder thing to prove security compared to an organisation that is only five years old and doesn't have this legacy IT estate.'
None of the victims of the breach has revealed the details of how crooks jimmied open their systems. The National Cyber Security Centre said that officials aren't sure if the attacks are linked.
But Hadley believes, as other analysts have said, that the hijackers used 'social-engineering attacks on service desks' to gain initial access.
A social-engineering attack is the practice of deceiving someone, often with email but also with phone calls, to get information.
'Someone calling and saying, 'Hey, it's the service desk here, you need to reset your password',' Hadley said.
'That person is tricked by someone impersonating M&S into giving details, enough to open the door into someone getting access and, from there, deploy their ransomware.'
As ominous as this sounds, this cyber attack wasn't 'sophisticated', said Jones.
'It came down to human error,' he said.
'According to reports, the attackers gained access through a third-party contractor, then spent more than two days inside M&S's systems before anyone noticed. That kind of dwell time is concerning, but unfortunately, not uncommon.
'We see this pattern time and time again. Most breaches don't start with Hollywood-style hacking.'
The attacks have been linked to a loose hacking collective called Scattered Spider. DragonForce, a 'ransomware cartel' whose previous targets include Coca-Cola, Yakult and the government of Palau, is believed to have made the ransomware.
Both M&S and Co-op are working to restore their systems, 'working around the clock to get things back to normal', M&S said in an Instagram post.
From phoney emails saying our parcel has been delayed to texts claiming to be from your mum, scams come in many forms these days.
And the reason, more often than that, that you receive these dodgy messages is because a hacker snatched your data.
'M&S has a very diverse range of customers and ages, and technical abilities,' explained Hadley.
'They can then pretend to potentially be M&S by telephone and email, and then share some information with the individual that would make them believe it is M&S.
All customers should be 'hyper-aware' over the coming months, warned Jones, even though no financial data was swiped.
Jones recommended people: Change their passwords – and don't, as one expert recently told Metro , don't have your password be '123456'.
, don't have your password be '123456'. Enable 'stronger security where possible, think two-factor authentication that involves an app or use a physical authenticator called a hardware key.
'Adopt a zero-trust mindset.' Be wary of any unexpected communication from M&S, like an email about a delivery, and try to verify it by going directly to the M&S website.
'So, 'hey, this is Marks and Spencer. Can you confirm an order you placed with this in the past six months?''
But don't expect these cyber-incidents to stop anytime soon, he warned: 'When we look at the retail supply chain, we can see more of this happening now,
'Now this particular one has been impacted, when the attackers might start surging into retail, recognising that it might be an unprotected space.'
And don't expect them to only happen to supermarkets, warned Robert Cottrill, a technology director at the digital transformation company, ANS.
M&S and Co-op are 'merely the incidents that made headlines', he said.
'In reality, organisations across all sectors and geographies are at risk,' Cottrill added.
'Cybersecurity must be a priority, because cyber criminals aren't waiting, and neither should you.'
Get in touch with our news team by emailing us at webnews@metro.co.uk.
For more stories like this, check our news page.
MORE: These are the 9 best (and most comfortable!) ballet flats to wear this summer
MORE: The unhealthiest supermarket sandwiches with more calories than a Big Mac
MORE: I rarely buy drinks from Co-op — but £7.35 bottle blew me away

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Metro
2 hours ago
- Metro
Vicki takes action to keep EastEnders abuser Joel out of jail after assault
Vicki Fowler (Alice Haig) makes it her mission to protect Joel Marshall (Max Murray) after his commits another sex offence in EastEnders next week. As viewers of the BBC One soap have seen, Joel is deeply troubled, and is the reason his family were forced to flee from Australia. After upskirting a school mate, his dad Ross (Alex Walkinshaw) coughed up a whopping $50,000 to keep the girl's silence, but her family also demanded that they leave the country. Since settling in Walford, it seems that his behaviour hasn't changed. Not only has he introduced naïve Tommy Moon (Sonny Kendall) to pornography, but he also decided to record sexual content of his own. Growing closer to Avani Nandra-Hart (Aaliyah James), he secretly filmed them having sex – a video which a horrified Ross later discovered on his son's phone. In upcoming scenes, his behaviour worsens, despite demands from both Ross and Vicki for him to change his ways. Having spent the day with Tommy, the lads board an underground train and Joel decides to entwine him further into a web of misbehaviour. He pulls out his phone, and instructs Tommy to start recording. Stumbling through the carriage, he pretends to fall on a fellow passenger named Isla, who he goes onto touch inappropriately. Tommy is stunned by what he sees, as a terrified Isla rushes to report him to the police that are present in the tube station. Joel is apprehended and hauled in for questioning – just as Ross and Vicki witness what is happening. Down at the cop shop, Ross demands answers from the teen, as Vicki corners Isla and tries to comfort her. Vicki is supportive of the girl's decision to report Joel, and hopes that it will be the kick he needs to stop his alarming behaviour patterns. She then passes on her number in case she needs anything further from the family. Later that night, she comes up with a cunning plan, inspired by Ross' actions Down Under. Want to be the first to hear shocking EastEnders spoilers? Who's leaving Coronation Street? The latest gossip from Emmerdale? Join 10,000 soaps fans on Metro's WhatsApp Soaps community and get access to spoiler galleries, must-watch videos, and exclusive interviews. Simply click on this link, select 'Join Chat' and you're in! Don't forget to turn on notifications so you can see when we've just dropped the latest spoilers! She offers Isla a sum of cash in exchange for her silence and withdrawal of the complaint, promising to make sure that Joel doesn't land himself in anymore hot water. More Trending Tommy's mum Kat Slater (Jessie Wallace) has her own concerns about Joel's influence over her son, but it soon becomes clear that Vicki is the one who she should be worried about. When Joel makes attempts at reconciling with his mate, Tommy is left shaken by an ultimatum from Vicki. She warns that unless he keeps his mouth shut, she will implicate him in the crime. View More » What will Tommy do? If you've got a soap or TV story, video or pictures get in touch by emailing us soaps@ – we'd love to hear from you. Join the community by leaving a comment below and stay updated on all things soaps on our homepage. MORE: EastEnders' Vicki is disturbed as shocking new secret about Joel is revealed MORE: All 46 EastEnders pictures for next week as cheating crisis strikes MORE: Dark EastEnders scenes as Joel makes horror move in story with Tommy


Belfast Telegraph
3 hours ago
- Belfast Telegraph
Disney and Universal sue AI firm Midjourney for copyright infringement
Filed in federal district court in Los Angeles, the complaint claims Midjourney pirated the libraries of the two Hollywood studios to generate and distribute 'endless unauthorised copies' of their famed characters, such as Darth Vader from Star Wars and the Minions from Despicable Me. 'Midjourney is the quintessential copyright free-rider and a bottomless pit of plagiarism. Piracy is piracy, and whether an infringing image or video is made with AI or another technology does not make it any less infringing,' the companies state in the complaint. The studios also claimed the San Francisco-based AI company ignored their requests to stop infringing on their copyrighted works and to take technological measures to halt such image generation. Midjourney did not immediately respond to a request for comment Wednesday. In a 2023 interview with The Associated Press, Midjourney CEO David Holz described his image-making service as 'kind of like a search engine' pulling in a wide swath of images from across the internet. He compared copyright concerns about the technology with how such laws have adapted to human creativity. 'Can a person look at somebody else's picture and learn from it and make a similar picture?' Mr Holz said. 'Obviously, it's allowed for people and if it wasn't, then it would destroy the whole professional art industry, probably the nonprofessional industry too. 'To the extent that AIs are learning like people, it's sort of the same thing and if the images come out differently then it seems like it's fine.' Major AI developers do not typically disclose their data sources, but have argued that taking troves of publicly accessible online text, images and other media to train their AI systems is protected by the 'fair use' doctrine of American copyright law. The case joins a growing number of lawsuits filed against developers of AI platforms — such as OpenAI, Anthropic — in San Francisco and New York. Meanwhile, the first major copyright trial of the generative AI industry is under way in London, pitting Getty Images against artificial intelligence company Stability AI.


Channel 4
3 hours ago
- Channel 4
Spending Review: voters react to Labour plans for the UK economy
We've been to Barnsley – a seat long held by Labour – but in some nearby constituencies Reform UK has been gaining ground. We've been asking people there what they make of the Chancellor's Spending Review and wider plans for the UK economy.