Cybercrime rocks the high street – what (or who) is next?

23/05/25 Wavenet
Cybercrime rocks the high street – what (or who) is next? placeholder thumbnail

Picture waking up to headlines revealing your business has been targeted by a sophisticated cyber-attack. This recent harsh reality, of stolen customer data and significant operational disruption, faced by UK retail giants Marks & Spencer and Co-op, has exposed the extreme vulnerability of retail cyber security.

So, what is the story behind these attacks, and how can you protect your business from becoming the next headline in cybercrime news?

The breaches brought to light exhibit the rising threat from organised cybercrime groups like Scattered Spider and DragonForce. While the full scope is still unravelling, what is clear is that these incidents emphasise that businesses can no longer afford insufficient cyber security measures.

While publicly available technical insights about these attacks remain sparse, our security teams have put together a high-level overview based on our experiences with similar incidents and our threat intelligence regarding the known threat actor.

What do we know so far?

Scattered Spider, notorious for its sophisticated social engineering and sky-high ransom demands against high revenue European and US companies, in exchange for not leaking sensitive company and customer data, allegedly orchestrated the attacks. Yet, newer ransomware group DragonForce has publicly claimed responsibility.

Reports from both BBC and the National Cyber Security Centre suggest that social engineering (hacking through human error) was the gateway, with crafty manoeuvres like smishing (SMS) or vishing (voice phishing), bypassing defences and gaining access to C-suite, IT, or security roles.

Both M&S and Co-op have suffered significant operational and reputational damage as a result of the attacks. And the M&S share price has dropped by over 14%, wiping more than £1 billion from its market capitalisation. Fully recovering from this cyber attack will be a lengthy and challenging process – if it’s even achievable at all.

Who is most under threat?

Major enterprises in sectors such as retail, finance, telecommunications, hospitality, and cloud services are prime targets for these cyber predators. Why? Their operational complexity and high value data make them especially tempting for Scattered Spider. While patterns of behaviour exist for this most disruptive and innovative cybercriminal collective, it continually adapts tactics, techniques, and procedures (TTPs) to bypass security controls, so unpredictability remains their powerful weapon. The question isn’t “if” but “when” they will strike again.

"Protecting data is not a luxury - it's a fundamental necessity. Cyber threats are evolving rapidly, and organisations of all sizes are at risk. Insider knowledge confirms that cyber security must be embedded into your core business strategy - it's not optional.” - Paul Colwell, Chief Information Security Officer, Wavenet.

What can you do to protect your business?

These recent attacks aren’t isolated incidents; they’re part of a broader surge in targeted, sophisticated cybercrime. But – have no fear – proactive measures can drastically reduce your risk:

Deploy phishing-resistant multi-factor authentication (MFA)

Secure your access points with advanced MFA solutions including hardware security keys (such as YubiKey) and modern app-based number matching.

Enforce strict call-back verification for password resets

Enhance your password reset procedures and instate strict call-back verification protocols. This ensures the identity is thoroughly confirmed before any sensitive account changes are made.

Implement network segmentation

Implement VLANs, firewalls, and access controls, and regularly test segmentation effectiveness to isolate critical systems and limit lateral movement by attackers.

Patch business-critical systems in a timely manner

Stay updated, monitor for new vulnerabilities, schedule and deploy patches, and verify successful updates to minimise the window of exposure to known exploits.

Regularly test your data backups, failover and failback

Schedule and conduct regular backup tests, including failover and failback exercises, to ensure data can be restored quickly and reliably in a crisis.

Monitor security logs for suspicious activity

Implement 24/7 security monitoring with a Security Operations Centre (SOC) across your environment, using advanced SIEM (Security Information and Event Management) tools. This detects, investigates, and responds to suspicious activity in real time.

Perform regular penetration tests including social engineering assessments

Engage in regular testing with CHECK and CREST-accredited penetration testers that will conduct regular technical and social engineering assessments (such as phishing simulations and vishing) and provide detailed reports and actionable recommendations to address weaknesses.

Create and rehearse business continuity & incident response plans

Regularly rehearse Business Continuity and Incident Response Plans and facilitate tabletop exercises and live simulations to ensure your team is prepared for incidents.

Prepare and protect your data using the 3-2-1 strategy

Regularly review backup strategies to ensure compliance and resilience and follow the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy off-site (or in the cloud).

Ensure your data is immutable or air-gapped

Configure immutable backups (that can’t be altered or deleted, even by attackers) and set up air-gapped storage solutions, providing maximum protection against ransomware and insider threats.

All of these measures will help. The key question is - are you confident that your organisation can withstand such organised cyber onslaughts?

Paul Colwell continues: “Every employee and every process must treat security as a vital requirement, because if human error or complacency creates vulnerabilities, it could cost your organisation greatly. It's not just prevention; it's safeguarding!".

Is your business prepared for what’s next?

These disruptive organised attacks are increasing and other major UK retailers such as Harrods have already become victims. But this isn’t the only type of threat that is intensifying.

Ransomware, AI-driven attacks, phishing, DDoS, supply chain compromises, insider threats, and vulnerabilities in cloud, containers, and emerging technologies are all increasing in frequency and sophistication.

Businesses must evolve, too, bolstering detection, response and resilience strategies to stay ahead.

Our Cyber and Operational Resilience expert Martin Lewis, adds a cautionary word to make sure your approach to backup and recovery is part of your cyber resilience and not an afterthought. “Effective data protection strategies are not just compliance checkboxes, they are critical controls that can protect your sensitive data and help to contain the blast radius of a cyber incident.”

With our comprehensive suite of cyber security services you gain a trusted partner equipped to navigate these challenges. To explore how we can help, visit the CyberGuard homepage.

 

Cyber Security, Retail, CyberGuard

Latest blogs

See all posts
A happy house tenant is using an app on her phone to report a home issue to her housing provider
From risk to resolution: how Active Assessor helps you stay ahead of Awaab's Law

What does Awaab's Law mean and why does it matter? Damp and mould aren’t just inconvenient maintenance problems - they’re serious risks to tenant health, regulatory compliance, and the reputation of housing providers. Nearly 1 in 7 social homes in England failed to meet the Decent Homes Standard in 2023¹. On top of that, the NHS is estimated to spend £1.4 billion a year treating health issues related to cold, damp housing². And yet, more than half of tenants experiencing condensation, damp or mould don’t report it. Often, they don’t recognise the early signs, or they simply don’t believe they’ll be taken seriously. This silence leaves landlords in the dark and turns small, fixable issues into expensive, high-risk problems. The tragic death of Awaab Ishak in 2020 brought national attention to the dangers of mould in social housing. In response, Awaab’s Law was introduced in 2023, significantly raising the bar for housing providers. Under the new legislation, social landlords must investigate hazards like damp and mould within 14 days, begin necessary repairs within 7 days, and complete the work within 21 days. This has turned what was once a service expectation into a legal requirement. But with so many issues going unreported, housing providers are left vulnerable. Failing to detect or act on early signs doesn’t just put tenants at risk—it can now result in legal and reputational consequences. The Challenge: Strained Teams & Outdated Systems Most housing providers care deeply about tenant safety. The problem isn’t willingness—it’s capacity. Maintenance teams, IT departments, and customer contact centres are already stretched thin. Spotting early-stage issues requires tools they simply don’t have. Traditional, manual inspections are expensive and slow. Reactive workflows leave little room to get ahead of problems. And despite growing demand for proactive service, only 13% of customers actually receive it. The systems many teams rely on today are fragmented, outdated, and not fit for the pressures of a post-Awaab world. The Solution: Active Assessor by 8x8

Read more
Placeholder thumbnail
There's more to the PSTN switch-off than meets the eye

What is the PSTN switch-off? The impending PSTN (Public Switched Telephone Network) switch-off isn’t just about replacing traditional lines. It’s a seismic shift that impacts far more than most realise – and if you’re not prepared, it could cost your business dearly. Most companies are aware that traditional analogue lines and ISDN systems for calls and broadband are being phased out by January 2027. But what many don’t see is the vast ripple effect of this transition – touching everything from lifts to life-critical systems, cash machines, and even traffic lights. What does the PSTN switch-off mean in simple terms? When it comes to the PSTN switch-off, it’s easy to think that it is just about phone lines. But the truth is, it’s much more complex. Here is what’s at stake: Life-saving systems: fire alarms, major medical and safety devices, emergency alarms in care homes, emergency pendants, telemetry services monitoring boiler rooms, dams, sluice gates, and substations. Public infrastructure: traffic lights, bus stops, speed cameras, and traffic management systems. Business-critical devices: PDQ and payment terminals, ATMS, CCTV, video surveillance, door entry, security systems, and remote access points. Transport & emergency services: roadside AA/RAC recovery alerts and devices, and emergency phone lines in hazardous environments. Telecommunications & internet: leased lines, private networking facilities, dial-up lines, broadband DSL services, and international leased lines. Community & public services: emergency teams and vehicles, payphones, modems, industrial control, public alerts, and more. If every one of these vital systems suddenly loses connectivity – chaos, downtime, and danger could follow. The possible business impact of the PSTN switch-off could be financial losses, public safety risks and erosion of customer trust. The PSTN switch-off is a vital business resilience issue – the time to act is now Unlike many providers who may focus on the obvious, we see what others miss. Our team dives beneath the surface, examining your entire network ecosystem to identify what’s at risk when the PSTN switches off. We have mapped out the hidden web of critical systems that rely on legacy infrastructure – and yes, we’ve prepared solutions for each one. Check out our iceberg infographic to see a quick glance of the PSTN switch-off picture. The switch-off is just the tip of the iceberg. Without planning, your operations could face catastrophic disruption. Don’t let your business be caught unaware. Reach out today for an in-depth assessment, and explore solutions tailored to your critical systems. Because when it comes to the PSTN switch-off, we see beyond the iceberg – and help your business stay afloat.

Read more
Placeholder thumbnail
What will happen to businesses when landlines go digital?

Preparing your business for the WLR switch-off and ensuring a smooth transition Most businesses currently rely on traditional analogue lines, ISDN, or broadband connected through Wholesale Line Rental (WLR) – the infrastructure powering your calls, data, security systems, and more. But the truth is, the WLR switch-off is on the horizon – and it’s affecting businesses in ways they might not be expecting. It’s not just about telephony! Do you really know what your WLR lines are powering? And what your options are? The countdown is on - Openreach’s deadline to shut down traditional analogue phone lines, ISDN, broadband, and other vital WLR-connected services is January 2027 (or even sooner). If you’re not fully prepared, your business could face serious disruption: Your phones may stop ringing, cutting off essential customer contact Lifts and critical facilities could cease functioning Broadband and internet services might go offline unexpectedly Your customers’ access to your services could be lost What exactly are your WLR lines powering? Many businesses don’t realise just how much relies on their existing WLR lines and traditional networks. The PSTN and WLR include more than just voice calls; they power card payment terminals, security alarms, lift controls, entry systems, CCTV, emergency systems, and many other critical business operations. Without a clear understanding of which lines are used for what, you risk missing vital services during the switch-over. Managing large estates or multiple sites makes this even trickier – you may be unaware of what lines you have, what they’re used for, where they’re located, or what they are connected to, creating a significant business risk. What do you do when landlines go digital? Don’t wait until disruption strikes. The earlier you identify your current setup and plan your migration, the smoother and more secure your transition will be. Download our free WLR Audit Factsheet – a straightforward guide to show you how we can help. Stay ahead of the clock. Take control now to ensure your business’s ongoing communications and critical services remain unaffected. Visit wavenet.co.uk/pstn-switch-off  for more information. 

Read more
Placeholder thumbnail
What is the WLR switch-off?

The WLR switch-off roadmap The countdown has begun – are you prepared? The WLF (Wholesale Line Rental) switch-off is already underway, and by January 2027, all traditional PSTN and ISDN lines will be switched off. Doing nothing isn’t an option anymore. Without action, your vital communications could face disruption, affecting your business operations and customer service. Why act now for the WLR switch-off? This isn’t just a technical upgrade – it’s a chance to transform your communication infrastructure into a reliable, feature-rich, all-IP network. Moving to an all-IP network unlocks better reliability, feature-rich communication, and future-proof capabilities that keep your business connected and competitive in a digital-first world. Your WLR switch-off migration journey starts here Switching to an all-IP solution is easier than you think. We help you assess your current setup and craft a tailored plan for a smooth, seamless migration. Options include: FTTP & SOGEA: Super-fast dedicated internet for unbeatable connectivity IP Voice & Hosted Voice: Flexible, scalable telephony solutions for modern communication UC Applications: Boost collaboration across your team, anywhere, anytime SIP Trunking: Cost-effective, reliable connectivity that scales with your needs Future-proof your business today Migrating early minimises disruption and unlocks new operational efficiencies. An all-IP network offers smoother communication, advanced features, and easier management, so you stay ahead in today’s digital economy. Be prepared for the WLR switch-off Ready to make the switch? We’ve got the perfect resource to help you stay ahead: our visual quick guide on the Openreach switch-off schedule. It’s a simple, clear, and easy-to-follow overview that helps you understand the timeline and plan your migration effectively. Download the WLR Switch-off Guide now and get your WLR migration plan on track. Be proactive and secure your business’s future communications today! Visit wavenet.co.uk/pstn-switch-off for more information.

Read more

Stay service-savvy

Get all the latest news and insights straight to your inbox.