HomeBusinessM&S hackers tricked IT...

M&S hackers tricked IT help desk workers to access company systems, says report

Hackers who targeted Marks & Spencer and the Co-op tricked IT workers to gain access into their companies systems, according to a report.

The “social engineering” attack on the Co-op allowed cybercriminals to reset an employee’s password before breaching the network, with a similar tactic used against M&S, sources revealed to BleepingComputer website.

Hundreds of agency workers at Marks & Spencer were told not to come into work as the retailer dealt with the fallout of a cyberattack which saw the company lose £650m of value in a matter of days.

The disruption began in April when contactless payments and click-and-collect orders were affected, before M&S chief executive Stuart Machin wrote to customers confirming the problem, adding that the retailer would be implementing “minor, temporary changes” to in-store operations as the company manages the ongoing “cyber incident”.

The Co-op has apologised to customers after hackers were able to access customer data (Co-op/PA) (PA Media)

The National Cyber Security Centre (NCSC) has issued new guidance to combat the “social engineering” technique used against the UK supermarkets by the hackers from the Scattered Spider network.

“Criminal activity online — including, but not limited to, ransomware and data extortion — is rampant. Attacks like this are becoming more and more common. And all organisations, of all sizes, need to be prepared,” said Jonathon Ellison, NCSC’s national resilience director, and Ollie Whitehouse, its chief technology officer, in a blog post according to The Times.

They have advised organisations to “review help desk password reset processes” and pay particular attention to “admin” accounts, which generally have more access throughout a company’s network.

The Scattered Spider network is a group of young men in the UK and US who drew notoriety in September 2023 when members broke into and locked up the networks of casino operators Caesars Entertainment and MGM Resorts International, and demanded hefty ransoms. Caesars paid about $15 million to restore its network.

It specialises in “breaking down the front door” of networks before handing over to a “ransomware” gang who cripple the network and extort its owner, the Times reported.

Tyler Buchanan, a Scottish man accused of being a leading member of the group, was extradited to the United States from Spain last month after being charged with attempting to hack into dozens of companies, Bloomberg News reported, citing a US Justice Department official.

At the time of the attack, M&S said it is “working extremely hard to restart online and app shopping” and apologised again for the disruption to shoppers. It had already been unable to process click and collect orders in stores after being impacted by the “cyber incident”.

The company reported the incident to data protection supervisory authorities and the National Cyber Security Centre.

Source link

- A word from our sponsors -

spot_img

Most Popular

More from Author

- A word from our sponsors -

spot_img

Read Now

H&M owners quietly buying its shares

Hennes & Mauritz (H&M), the fast-fashion retailer that's been listed on the Swedish stock market since 1974, is steadily moving back towards private ownership. The founding family has stepped up purchases of H&M shares, spending more than $6.6 billion since 2016 to amass nearly two-thirds...

Mars volcano twice as big as Earth’s tallest one seen poking through clouds in first-of-its-kind image

A dazzling image taken by NASA's 2001 Mars Odyssey orbiter shows an unprecedented view of a 12-mile-high volcano poking through clouds at dawn on the Red Planet. Arsia Mons, which dwarfs Earth's tallest volcanoes, and its two neighboring volcanoes are often surrounded by...

Passage: Joe Jackson – CBS News

Passage: Joe Jackson - CBS News ...

NatWest fixes app outage which left customers fuming

Tom GerkenTechnology reporterGetty ImagesNatWest says it has now fixed an issue which left customers unable to use the bank's mobile app, leaving some unable to access their accounts.Customers reported problems including being unable to make purchases or pay staff.NatWest apologised to customers "for any inconvenience caused", having...

This Button Can Make Your Flight Travel More Comfortable – And It’s Not The Recline One

Last Updated:June 06, 2025, 18:32 ISTThe video shows that passengers in aisle seats often struggle to get up or move due to people sitting in front or beside them, making movement difficult during the flightThis small but useful button is usually located under or on the side...

Meet Oldest Whale In The World: A 200-Year-Old Bowhead Still Swimming The Arctic Seas, Has Lived Through World Wars, Space Races And… | Science...

Just imagine this: deep beneath the icy, remote waters of the Arctic Ocean, a truly ancient Methuselah still glides fearlessly. This creatures has surprised a whole lot of scientists with them believing to have found the oldest living whale ever recorded, a bowhead estimated to be an...

Over 44% Pakistanis now below poverty line under new WB threshold

Over 107m Pakistnis are living below poverty line.Over 39m included in extreme poverty category.New figures reflect updated international thresholds.ISLAMABAD:...

Racing to Save California’s Elephant Seals From Bird Flu

During the breeding season, the center sees a lot of underweight, malnourished elephant seal pups, many of which are still too young to fend for themselves or even swim. Sometimes, they also see elephant seals with parasites or traumatic injuries, such as dog bites or blunt force...