Cybercrime rocks the high street – what (or who) is next?

23/05/25 Wavenet
Cybercrime rocks the high street – what (or who) is next? placeholder thumbnail

Picture waking up to headlines revealing your business has been targeted by a sophisticated cyber-attack. This recent harsh reality, of stolen customer data and significant operational disruption, faced by UK retail giants Marks & Spencer and Co-op, has exposed the extreme vulnerability of retail cyber security.

So, what is the story behind these attacks, and how can you protect your business from becoming the next headline in cybercrime news?

The breaches brought to light exhibit the rising threat from organised cybercrime groups like Scattered Spider and DragonForce. While the full scope is still unravelling, what is clear is that these incidents emphasise that businesses can no longer afford insufficient cyber security measures.

While publicly available technical insights about these attacks remain sparse, our security teams have put together a high-level overview based on our experiences with similar incidents and our threat intelligence regarding the known threat actor.

What do we know so far?

Scattered Spider, notorious for its sophisticated social engineering and sky-high ransom demands against high revenue European and US companies, in exchange for not leaking sensitive company and customer data, allegedly orchestrated the attacks. Yet, newer ransomware group DragonForce has publicly claimed responsibility.

Reports from both BBC and the National Cyber Security Centre suggest that social engineering (hacking through human error) was the gateway, with crafty manoeuvres like smishing (SMS) or vishing (voice phishing), bypassing defences and gaining access to C-suite, IT, or security roles.

Both M&S and Co-op have suffered significant operational and reputational damage as a result of the attacks. And the M&S share price has dropped by over 14%, wiping more than £1 billion from its market capitalisation. Fully recovering from this cyber attack will be a lengthy and challenging process – if it’s even achievable at all.

Who is most under threat?

Major enterprises in sectors such as retail, finance, telecommunications, hospitality, and cloud services are prime targets for these cyber predators. Why? Their operational complexity and high value data make them especially tempting for Scattered Spider. While patterns of behaviour exist for this most disruptive and innovative cybercriminal collective, it continually adapts tactics, techniques, and procedures (TTPs) to bypass security controls, so unpredictability remains their powerful weapon. The question isn’t “if” but “when” they will strike again.

"Protecting data is not a luxury - it's a fundamental necessity. Cyber threats are evolving rapidly, and organisations of all sizes are at risk. Insider knowledge confirms that cyber security must be embedded into your core business strategy - it's not optional.” - Paul Colwell, Chief Information Security Officer, Wavenet.

What can you do to protect your business?

These recent attacks aren’t isolated incidents; they’re part of a broader surge in targeted, sophisticated cybercrime. But – have no fear – proactive measures can drastically reduce your risk:

Deploy phishing-resistant multi-factor authentication (MFA)

Secure your access points with advanced MFA solutions including hardware security keys (such as YubiKey) and modern app-based number matching.

Enforce strict call-back verification for password resets

Enhance your password reset procedures and instate strict call-back verification protocols. This ensures the identity is thoroughly confirmed before any sensitive account changes are made.

Implement network segmentation

Implement VLANs, firewalls, and access controls, and regularly test segmentation effectiveness to isolate critical systems and limit lateral movement by attackers.

Patch business-critical systems in a timely manner

Stay updated, monitor for new vulnerabilities, schedule and deploy patches, and verify successful updates to minimise the window of exposure to known exploits.

Regularly test your data backups, failover and failback

Schedule and conduct regular backup tests, including failover and failback exercises, to ensure data can be restored quickly and reliably in a crisis.

Monitor security logs for suspicious activity

Implement 24/7 security monitoring with a Security Operations Centre (SOC) across your environment, using advanced SIEM (Security Information and Event Management) tools. This detects, investigates, and responds to suspicious activity in real time.

Perform regular penetration tests including social engineering assessments

Engage in regular testing with CHECK and CREST-accredited penetration testers that will conduct regular technical and social engineering assessments (such as phishing simulations and vishing) and provide detailed reports and actionable recommendations to address weaknesses.

Create and rehearse business continuity & incident response plans

Regularly rehearse Business Continuity and Incident Response Plans and facilitate tabletop exercises and live simulations to ensure your team is prepared for incidents.

Prepare and protect your data using the 3-2-1 strategy

Regularly review backup strategies to ensure compliance and resilience and follow the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy off-site (or in the cloud).

Ensure your data is immutable or air-gapped

Configure immutable backups (that can’t be altered or deleted, even by attackers) and set up air-gapped storage solutions, providing maximum protection against ransomware and insider threats.

All of these measures will help. The key question is - are you confident that your organisation can withstand such organised cyber onslaughts?

Paul Colwell continues: “Every employee and every process must treat security as a vital requirement, because if human error or complacency creates vulnerabilities, it could cost your organisation greatly. It's not just prevention; it's safeguarding!".

Is your business prepared for what’s next?

These disruptive organised attacks are increasing and other major UK retailers such as Harrods have already become victims. But this isn’t the only type of threat that is intensifying.

Ransomware, AI-driven attacks, phishing, DDoS, supply chain compromises, insider threats, and vulnerabilities in cloud, containers, and emerging technologies are all increasing in frequency and sophistication.

Businesses must evolve, too, bolstering detection, response and resilience strategies to stay ahead.

Our Cyber and Operational Resilience expert Martin Lewis, adds a cautionary word to make sure your approach to backup and recovery is part of your cyber resilience and not an afterthought. “Effective data protection strategies are not just compliance checkboxes, they are critical controls that can protect your sensitive data and help to contain the blast radius of a cyber incident.”

With our comprehensive suite of cyber security services you gain a trusted partner equipped to navigate these challenges. To explore how we can help, visit the CyberGuard homepage.

 

Cyber Security, Retail, CyberGuard

Latest blogs

See all posts
it in education
Best IT support for schools: enhance education

The right IT support services help schools and colleges operate smoothly, prevent downtime, and enhance the overall learning experience. This guide breaks down the most effective IT solutions for educational institutions and explains how to choose the right IT partner. Why IT support is essential in modern education Schools and colleges depend on technologies such as cloud platforms, WiFi networks, learning management systems (LMS), and safeguarding tools. Without strong IT support, everyday learning can easily be disrupted. High‑quality IT support ensures: Consistent uptime for learning platforms Secure protection for student and staff data Smooth operation of classroom hardware Reliable connectivity across campus A strategic roadmap for future IT improvements Top IT support services for schools and colleges 1. Managed IT support Managed IT support gives schools access to a fully equipped technical team without needing an in‑house department. Typical features include: 24/7 help desk Device and server management Cyber security monitoring Backup and disaster recovery Software updates and patch management This approach reduces costs, increases system reliability, and frees educators to focus on learning—not technical issues. 2. Student technology support Students rely on devices and online platforms every day. Student tech support ensures they can access lessons without interruption. Common services include: Device troubleshooting (laptops, tablets, Chromebooks) Login and password resets Connectivity support Assistance with online learning platforms Safety filtering guidance This support is especially vital in hybrid or remote learning environments. 3. Classroom technology solutions Modern classrooms need fully supported and integrated digital tools. Classroom IT solutions typically include: Interactive whiteboards Projectors and AV systems Classroom management software WiFi optimisation Digital collaboration tools These technologies make lessons more engaging and interactive. 4. Microsoft education support Microsoft remains one of the most widely used platforms in schools. Supporting these tools effectively helps ensure seamless digital learning. Key areas include: Office 365 management Teams for Education Intune device management Azure cloud services Identity and access management 5. Microsoft education training Empower your teaching and facilitate innovative learning for your students with Microsoft education training. Key areas include: Microsoft 365 Education Tools Training Microsoft's Showcase School Programme How to choose the right IT support provider When evaluating IT support services, schools should consider: Budget and funding constraints Current IT infrastructure Scalability needs Security and compliance requirements Provider’s education-sector experience Availability of both remote and on‑site support Choosing a specialist with education experience ensures better safeguarding compliance, user-friendly solutions, and long‑term value. The benefits of outsourcing IT support Practical and operational benefits More schools now outsource IT due to benefits in security, performance, management and cost: Lower long‑term costs Access to specialist expertise Faster response and issue resolution Stronger cyber protection A strategic, future-proof technology plan Learning benefits Technology is enabling and facilitating better learning experiences and outcomes, empowering teachers, increasing pupil engagement and enriching the classroom experience: Personalised learning paths Instant access to learning resources Better collaboration among students Support for SEND and diverse learning needs Preparation for a digital workforce Schools that invest wisely in IT create stronger educational outcomes. The growing demand for IT skills in education As digital transformation accelerates, technology is playing a key role in enhancing learning and schools increasingly require IT professionals skilled in: Networking Cyber security Cloud infrastructure EdTech implementation Support and troubleshooting Online IT certification programmes are helping build the next generation of education‑sector IT specialists. Wavenet: A trusted IT partner for UK schools and the public sector For educational institutions seeking a reliable and experienced IT services provider, We are one of the UK’s leading education technology specialists. With over 30 years of experience delivering designed‑for‑schools solutions, we supports more than 4,000 education establishments nationwide across cloud platforms, cyber security, communications, safeguarding, and network services. We provide ICT services, broadband, WiFi, audio‑visual systems, remote support, and fully managed IT services - all delivered by DBS‑checked staff and supported with clear, transparent SLAs. By partnering with us, schools gain access to expert guidance, best‑practice ICT strategy, robust cybersecurity, and a long‑term technology roadmap - helping them create a connected, secure, and future‑ready educational environment.

Read more