HomeBusinessM&S hackers tricked IT...

M&S hackers tricked IT help desk workers to access company systems, says report

Hackers who targeted Marks & Spencer and the Co-op tricked IT workers to gain access into their companies systems, according to a report.

The “social engineering” attack on the Co-op allowed cybercriminals to reset an employee’s password before breaching the network, with a similar tactic used against M&S, sources revealed to BleepingComputer website.

Hundreds of agency workers at Marks & Spencer were told not to come into work as the retailer dealt with the fallout of a cyberattack which saw the company lose £650m of value in a matter of days.

The disruption began in April when contactless payments and click-and-collect orders were affected, before M&S chief executive Stuart Machin wrote to customers confirming the problem, adding that the retailer would be implementing “minor, temporary changes” to in-store operations as the company manages the ongoing “cyber incident”.

The Co-op has apologised to customers after hackers were able to access customer data (Co-op/PA) (PA Media)

The National Cyber Security Centre (NCSC) has issued new guidance to combat the “social engineering” technique used against the UK supermarkets by the hackers from the Scattered Spider network.

“Criminal activity online — including, but not limited to, ransomware and data extortion — is rampant. Attacks like this are becoming more and more common. And all organisations, of all sizes, need to be prepared,” said Jonathon Ellison, NCSC’s national resilience director, and Ollie Whitehouse, its chief technology officer, in a blog post according to The Times.

They have advised organisations to “review help desk password reset processes” and pay particular attention to “admin” accounts, which generally have more access throughout a company’s network.

The Scattered Spider network is a group of young men in the UK and US who drew notoriety in September 2023 when members broke into and locked up the networks of casino operators Caesars Entertainment and MGM Resorts International, and demanded hefty ransoms. Caesars paid about $15 million to restore its network.

It specialises in “breaking down the front door” of networks before handing over to a “ransomware” gang who cripple the network and extort its owner, the Times reported.

Tyler Buchanan, a Scottish man accused of being a leading member of the group, was extradited to the United States from Spain last month after being charged with attempting to hack into dozens of companies, Bloomberg News reported, citing a US Justice Department official.

At the time of the attack, M&S said it is “working extremely hard to restart online and app shopping” and apologised again for the disruption to shoppers. It had already been unable to process click and collect orders in stores after being impacted by the “cyber incident”.

The company reported the incident to data protection supervisory authorities and the National Cyber Security Centre.

Source link

- A word from our sponsors -

spot_img

Most Popular

More from Author

- A word from our sponsors -

spot_img

Read Now

Bengaluru CA explains why she quit her Rs 28 LPA job for ‘unstable income’ freelance career | Personal Finance News

New Delhi: Job security and worrying about job is a natural thought that keeps crossing the minds of salaried individuals. While, on one hand several people have posted about the difficult times being faced by them in their respective carriers on account of job loss, a Chartered...

Valentine’s Day romance scams target widowed, divorced Americans in 2026

NEWYou can now listen to Fox News articles! Valentine's Day should be about connection. However, every February also becomes the busiest season of the year for romance scammers. In 2026, that risk is higher than ever.These scams are no longer simple "lonely hearts" schemes. Instead,...

Chappell Roan leaves Wasserman talent agency after his mentions in Epstein files

Chappell Roan announced Monday that she's left her talent agency after its CEO was named in files related to late convicted sex offender Jeffrey Epstein released by...

Social media ads for prescription-only weight-loss medicines banned

Your support helps us to tell the storyFrom reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines...

A pulmonary embolism tied to colorectal cancer killed Catherine O’Hara. Here’s how common the event is among cancer patients

Your support helps us to tell the storyFrom reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines...

Nucleus Genomics CEO explains how “genetic optimization” tools help parents select traits they desire in babies

Big leaps in science have made a once-impossible, much-debated question come to life: Would you design your unborn child?Kian Sadeghi, the 25-year-old founder and CEO at Nucleus Genomics, believes every parent has a right to do just that, selecting qualities they desire –...

Jake Paul cries as fiancée Jutta Leerdam breaks an Olympic record

Jake Paul’s Dutch fiancee Jutta Leerdam won Olympic gold on Monday in speed skating. She broke the Olympic record...

US and Bangladesh strike new trade deal — key terms of the agreement

The United States and Bangladesh on Monday finalised the United States–Bangladesh Agreement on Reciprocal Trade, wrapping up negotiations as both countries stepped in to strengthen bilateral economic ties. Under the revised framework, Bangladeshi exports to the American market will attract a 19% tariff, marginally lower...

Parenting quote of the day: “Parents can only give good advice or put them on the right paths, but the final forming of a...

Anne Frank's insights remind us that, although parental guidance is crucial, a child's true character develops through their own experiences. Trusting them to learn from real - life consequences and instilling values they can internalize are vital. Genuine maturity is born in quiet moments of decision-making,...