In spring 2025 a wave of cyberattacks struck major UK retailers including Marks & Spencer, Co-op and Harrods — disrupting operations, online orders and, in some cases, customer data. M&S in particular faced weeks of disruption and a financial hit widely reported to run into the hundreds of millions of pounds.
The attacks were a stark reminder that size is no protection — and that attackers often get in through people and suppliers rather than brute force, with social engineering of IT help desks reported as a way in.
Why this matters
- Size is no defence — household names were hit hard.
- People are the entry point — attackers tricked staff and help desks into granting access.
- Downtime is the real cost — lost trading and recovery dwarfed any ransom.
- Supply chains widen the risk — third-party access is a favourite route in.
What we’d advise
The lesson scales down to any business: lock down access with MFA, train your team to spot manipulation, and have a tested response plan. We help clients put exactly those defences in place.
Source: widely reported in April–May 2025, including by the BBC and Reuters.
