HomeBusinessM&S hackers tricked IT...

M&S hackers tricked IT help desk workers to access company systems, says report

Hackers who targeted Marks & Spencer and the Co-op tricked IT workers to gain access into their companies systems, according to a report.

The “social engineering” attack on the Co-op allowed cybercriminals to reset an employee’s password before breaching the network, with a similar tactic used against M&S, sources revealed to BleepingComputer website.

Hundreds of agency workers at Marks & Spencer were told not to come into work as the retailer dealt with the fallout of a cyberattack which saw the company lose £650m of value in a matter of days.

The disruption began in April when contactless payments and click-and-collect orders were affected, before M&S chief executive Stuart Machin wrote to customers confirming the problem, adding that the retailer would be implementing “minor, temporary changes” to in-store operations as the company manages the ongoing “cyber incident”.

The Co-op has apologised to customers after hackers were able to access customer data (Co-op/PA) (PA Media)

The National Cyber Security Centre (NCSC) has issued new guidance to combat the “social engineering” technique used against the UK supermarkets by the hackers from the Scattered Spider network.

“Criminal activity online — including, but not limited to, ransomware and data extortion — is rampant. Attacks like this are becoming more and more common. And all organisations, of all sizes, need to be prepared,” said Jonathon Ellison, NCSC’s national resilience director, and Ollie Whitehouse, its chief technology officer, in a blog post according to The Times.

They have advised organisations to “review help desk password reset processes” and pay particular attention to “admin” accounts, which generally have more access throughout a company’s network.

The Scattered Spider network is a group of young men in the UK and US who drew notoriety in September 2023 when members broke into and locked up the networks of casino operators Caesars Entertainment and MGM Resorts International, and demanded hefty ransoms. Caesars paid about $15 million to restore its network.

It specialises in “breaking down the front door” of networks before handing over to a “ransomware” gang who cripple the network and extort its owner, the Times reported.

Tyler Buchanan, a Scottish man accused of being a leading member of the group, was extradited to the United States from Spain last month after being charged with attempting to hack into dozens of companies, Bloomberg News reported, citing a US Justice Department official.

At the time of the attack, M&S said it is “working extremely hard to restart online and app shopping” and apologised again for the disruption to shoppers. It had already been unable to process click and collect orders in stores after being impacted by the “cyber incident”.

The company reported the incident to data protection supervisory authorities and the National Cyber Security Centre.

Source link

- A word from our sponsors -

spot_img

Most Popular

More from Author

- A word from our sponsors -

spot_img

Read Now

Compensation For Delay In Flat Possession Not Taxable Under Section 50C, Rules Mumbai ITAT | Tax News

Last Updated:November 09, 2025, 16:43 ISTMumbai ITAT rules compensation for flat delivery delays is not taxable under Section 50C. Experts say this offers relief to taxpayers facing project delays.Section 50C Can’t Apply Without Actual Property Transfer, Rules Mumbai ITATIn a significant ruling, the Mumbai bench of the...

Optical illusion: Only 1% of people can spot the hidden face in this burger. Can you?

Optical illusions have gained a lot of popularity recently, as they get our brain to exercise, and can be the perfect test of our observational skills and keen eye. They are also super fun to solve, and can be the perfect recipe for a bored...

Dolly Parton leans on music industry for support amid health scares: Source

Dolly Parton has reportedly been finding comfort in the company of fellow music artists during a challenging period for...

Rs 1 lakh Crore Fund To Mitigate R&D Risks, Spur Private Investment In Cutting-Edge Technologies: Secretary DST | Economy News

New Delhi: The recently launched Rs 1 lakh crore Research Development and Innovation (RDI) fund, particularly focused on India's private sector, aims to support the private research and innovation mindset among players and mitigate the financial risks associated with it.   Speaking at a workshop organised by the Department...

With presidents and royalty in attendance, Egypt unveils $1bn cultural ‘GEM’

Prime ministers, presidents and royalty descended on Cairo on Saturday to attend the spectacle-laden inauguration of a sprawling new...

Obituary: James Watson

Getty ImagesIn February 1953, two men walked into a pub in Cambridge and announced they had found "the secret of life". It was not an idle boast.One was James Watson, an American biologist from the Cavendish laboratory; the other was his British research partner, Francis Crick....

T Rabi Sankar: Frauds up since July, battle on

MUMBAI: RBI deputy governor T Rabi Sankar said the fight against digital fraud is far from over, noting that the decline seen earlier this year reversed in July, with cases rising again.He said fraud levels had been falling since the start of the year before...

iOS 26.1 update boosts iPhone security and performance improvements

NEWYou can now listen to Fox News articles! Apple's iOS 26.1 update is more than a standard patch. It boosts security, speeds up performance and adds practical upgrades to features you already use. The update fixes dozens of vulnerabilities that impact Safari, Photos and Apple...

Florence Welch opens up about ectopic pregnancy and doubts about releasing new music

Florence Welch opens up about ectopic pregnancy and doubts about releasing new music - CBS News ...