HomeBusinessM&S hackers tricked IT...

M&S hackers tricked IT help desk workers to access company systems, says report

Hackers who targeted Marks & Spencer and the Co-op tricked IT workers to gain access into their companies systems, according to a report.

The “social engineering” attack on the Co-op allowed cybercriminals to reset an employee’s password before breaching the network, with a similar tactic used against M&S, sources revealed to BleepingComputer website.

Hundreds of agency workers at Marks & Spencer were told not to come into work as the retailer dealt with the fallout of a cyberattack which saw the company lose £650m of value in a matter of days.

The disruption began in April when contactless payments and click-and-collect orders were affected, before M&S chief executive Stuart Machin wrote to customers confirming the problem, adding that the retailer would be implementing “minor, temporary changes” to in-store operations as the company manages the ongoing “cyber incident”.

The Co-op has apologised to customers after hackers were able to access customer data (Co-op/PA) (PA Media)

The National Cyber Security Centre (NCSC) has issued new guidance to combat the “social engineering” technique used against the UK supermarkets by the hackers from the Scattered Spider network.

“Criminal activity online — including, but not limited to, ransomware and data extortion — is rampant. Attacks like this are becoming more and more common. And all organisations, of all sizes, need to be prepared,” said Jonathon Ellison, NCSC’s national resilience director, and Ollie Whitehouse, its chief technology officer, in a blog post according to The Times.

They have advised organisations to “review help desk password reset processes” and pay particular attention to “admin” accounts, which generally have more access throughout a company’s network.

The Scattered Spider network is a group of young men in the UK and US who drew notoriety in September 2023 when members broke into and locked up the networks of casino operators Caesars Entertainment and MGM Resorts International, and demanded hefty ransoms. Caesars paid about $15 million to restore its network.

It specialises in “breaking down the front door” of networks before handing over to a “ransomware” gang who cripple the network and extort its owner, the Times reported.

Tyler Buchanan, a Scottish man accused of being a leading member of the group, was extradited to the United States from Spain last month after being charged with attempting to hack into dozens of companies, Bloomberg News reported, citing a US Justice Department official.

At the time of the attack, M&S said it is “working extremely hard to restart online and app shopping” and apologised again for the disruption to shoppers. It had already been unable to process click and collect orders in stores after being impacted by the “cyber incident”.

The company reported the incident to data protection supervisory authorities and the National Cyber Security Centre.

Source link

- A word from our sponsors -

spot_img

Most Popular

More from Author

Majority of investors planning to boost portfolios in 2026, survey finds

Your support helps us to tell the storyFrom reproductive rights to...

Gold and silver prices broke all previous records

Gold, silver, and platinum hit record highs on Friday, as...

Challenge: Only a person with 20/20 vision can spot the summer drink within 12 seconds |

Amidst the twinkling lights and cozy stalls of a delightful...

2025 likely to be UK’s hottest year on record, says Met Office

Mark PoyntingClimate researcherEPARising temperatures in the UK will become "the new...

- A word from our sponsors -

spot_img

Read Now

Majority of investors planning to boost portfolios in 2026, survey finds

Your support helps us to tell the storyFrom reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines...

Gold and silver prices broke all previous records

Gold, silver, and platinum hit record highs on Friday, as speculative momentum and thinning year-end liquidity powered the precious metals, along with markets pricing in more US rate cuts, and rising geopolitical tension. ...

Challenge: Only a person with 20/20 vision can spot the summer drink within 12 seconds |

Amidst the twinkling lights and cozy stalls of a delightful Christmas market, a refreshing summer surprise lies in wait, daring onlookers to uncover it in just 12 seconds. This visual trickery invites you to sharpen your perception, as your mind is led to expect only seasonal...

2025 likely to be UK’s hottest year on record, says Met Office

Mark PoyntingClimate researcherEPARising temperatures in the UK will become "the new normal", a leading government climate adviser has warned, as she called for more to be done to prepare for the impacts of climate change.It comes as the Met Office revealed 2025 was on course to be...

Perry Bamonte, guitarist for The Cure, dies after “short illness” at 65

Perry Archangelo Bamonte, longtime guitarist and keyboardist for the influential goth band The Cure, has died. He was 65.The band announced his death on their official website on Friday."It is with enormous sadness that we confirm the death of our great friend and bandmate...

Stocks making the biggest moves midday: FCX, CPNG, TGT

Check out the companies making the biggest moves midday: Freeport-McMoRan — The miner rose 3.1% as gold and other metals scaled to record levels. Target — The retailer rose more than 1% after the Financial Times reported, citing sources, that hedge fund Toms Capital Investment Management made...

Global Capital Is Doubling Down On NCR’s Commercial Assets; What’s Fuelling The Rush? | Real Estate News

Last Updated:December 27, 2025, 15:42 ISTNet office absorption in NCR jumped 61% year-on-year in 2024, the sharpest increase among major cities, to touch 9.5 million sq. ft.Of the $8.87 billion in real estate investments that entered India in 2024, global investors accounted for nearly two-thirds.Delhi-NCR has entered...

Apple fixes zero-day vulnerabilities in emergency security update

NEWYou can now listen to Fox News articles! Apple has released emergency security updates to fix two zero-day vulnerabilities that attackers actively exploited in highly targeted attacks. The company described the activity as an "extremely sophisticated attack" aimed at specific individuals. Although Apple did not identify...

Prince Harry, Meghan lose key team member responsible for royal truce

Prince Harry and Meghan have lost an important member of their team, who played an instrumental role in cracking...

AAA says a gallon hits 4-year low as holiday travel starts

Customers at the GasWay Xpress Mart at 1120 Erie Blvd. pump gas on Wednesday, Dec. 3, 2025, in Schenectady, N.Y. Lori Van Buren | Albany Times Union | Hearst Newspapers | Getty ImagesHoliday road-trippers are feeling some relief at the pump this year.The average price of unleaded...

Uttar Pradesh: Electric Bus Service Launched In Prayagraj Connecting THESE 4 Cities | Mobility News

Prayagraj, Uttar Pradesh: Taking a major step towards strengthening a clean and green public transport ecosystem, six electric buses were flagged off from the Leader Road Depot office in Prayagraj to Varanasi, Ayodhya, Kanpur and Lucknow. These new electric buses will offer passengers a safe, comfortable, and...