In April 2025, two of Britain's most iconic retailers fell victim to sophisticated cyber attacks that have severely disrupted their operations and compromised customer data. While both M&S and Co-op are still working to recover fully, their experiences offer valuable insights for technology professionals and business leaders alike. This article examines both incidents separately while highlighting the concerning similarities and crucial lessons for the industry.
The M&S Attack: A Crippling Blow to a Retail Giant
Timeline of Events
- April 22, 2025: Initial disruption reported with customers unable to use contactless payments and click-and-collect services. [1]
- April 24: M&S continued experiencing issues, moving several processes offline to protect customers and business.
- April 25: Complete shutdown of online sales as the company worked to contain the attack.
- April 29: Reports linked the attack to the Scattered Spider hacking collective.
- May 13: M&S confirmed personal customer data had been stolen. While primary M&S.com account passwords and payment details were reported as not directly compromised due to secure, separate storage, the company initiated a precautionary password reset for all online accounts to mitigate any potential unforeseen risks. [2]
Attack Method & Threat Actors
Technology specialist site BleepingComputer reported that the attack began with an alarmingly simple yet effective social engineering tactic: hackers impersonated employees while contacting the company's IT help desk. [3] These attackers, believed to be part of the Scattered Spider (also known as Octo Tempest) hacking collective, reportedly used SIM-swapping techniques to steal phone numbers and personal data to convincingly impersonate legitimate employees. [4]
Once they tricked IT help desk workers into granting them access, the attackers utilized M&S's Active Directory to gain broader control of the company's network infrastructure. BleepingComputer linked the attack to Scattered Spider deploying DragonForce ransomware. [3]
Impact & Current Status
The attack's consequences have been severe and far-reaching:
- Complete shutdown of online ordering for clothing and home products.
- Significant stock shortages in physical stores.
- Work-from-home staff locked out of IT systems.
- Theft of customer personal data.
- Precautionary password reset mandated for all online customer accounts.
- Ongoing disruption to normal operations with no clear timeline for full recovery. [4]
Financial Fallout
The market has responded harshly to the incident. Since the attack began:
- More than £700 million ($930 million) has been wiped from M&S's market value.
- Share prices fell 6.5% overall, including a 2.2% drop on the first day of disruptions.
- By May 7, shares were down 12% since the incident was first disclosed.
- Online shopping, which generates approximately £3.8 million daily and represents one-third of M&S's clothing and home sales, remained halted. [5]
The Co-op Attack: Swift Response to a Major Threat
Timeline of Events
- April 30, 2025: Co-op reported a cyberattack affecting back-office systems and call center services. [2]
- May 1: Co-op instructed staff to stop using VPNs and warned that communication channels might be compromised. [1]
- May 4: Revelation that hackers had accessed a "significant" amount of customer data. [2]
Attack Method & Threat Actors
Similar to M&S, the Co-op attack reportedly began with hackers impersonating employees to trick IT help desk workers. [3] A group calling itself DragonForce claimed responsibility, contacting the BBC with the statement: "Hello, we exfiltrated the data from your company. We have customer database, and Co-op member card data." [6]
The group allegedly sent proof of their breach to the BBC, including a sample of 10,000 customers' records containing membership card numbers, names, addresses, emails, and phone numbers, along with databases of employee credentials. [6]
Impact & Current Status
While the Co-op attack "didn't escalate as dramatically" as the M&S breach [7], it still resulted in:
- Temporary shutdown of back-office systems and call centers.
- New security protocols requiring staff to keep cameras on during remote meetings.
- Instructions not to record calls, transcribe meetings, or share sensitive information via Teams.
- Compromise of significant amounts of customer personal data including names, contact details, and dates of birth. [2]
The retailer acted proactively, shutting down portions of its IT network quickly after detecting the threat. By mid-May, the Co-op had managed to restock its shelves but was still not providing a timeline for complete recovery. [4]
Striking Similarities Between the Attacks
The parallel nature of these incidents raises serious concerns for the retail sector and beyond:
- Identical Initial Access Methods: Both attacks exploited human vulnerability through social engineering of IT help desks rather than technical vulnerabilities. [3]
- Similar Timing: The attacks occurred within days of each other, suggesting a coordinated campaign.
- Possible Shared Threat Actors: The DragonForce ransomware name has been linked to both attacks. [3, 6]
- Customer Data Targeting: Both breaches resulted in the theft of significant amounts of personal information.
- Extended Recovery Periods: Weeks after the initial breaches, both retailers continue to experience disruption with no clear end in sight. [4]
Critical Lessons for Technology Leaders
1. Strengthen Help Desk Authentication Protocols
The UK's National Cyber Security Centre has specifically recommended that all companies review their help desk processes in the wake of these attacks. [3] Technology leaders should implement:
- Multi-factor authentication for all help desk requests.
- Callback verification to pre-registered numbers.
- Biometric voice authentication where possible.
- Strict limits on what actions can be performed through remote assistance.
- Principles of least privilege for help desk staff accounts to minimize potential impact if compromised.
2. Prepare for Extended Recovery Timelines
Recovery from sophisticated attacks takes significantly longer than many organizations anticipate. This includes not only system restoration but also rebuilding trust and addressing regulatory scrutiny.
- "Depending on the scale and complexity of the breach, this process can take weeks or even months. The average time to identify and contain a data breach is 258 days according to IBM's latest (2024) Cost of a Data Breach Report. It can take as long as 3 years to fully recover from a cyber attack in some cases." [8]
Organizations should develop robust business continuity and disaster recovery plans that account for potential month-long disruptions to critical systems. These plans must include regular, tested, and offline backups, especially for protection against ransomware.
3. Recognize the Financial Stakes
The market response to M&S's breach demonstrates the enormous financial impact of cyber incidents:
- £700 million market value lost.
- 12% share price decline.
- Multiple millions in lost daily revenue. [5]
These figures dramatically underscore why cybersecurity deserves significant investment and board-level attention.
4. Embrace Rapid Detection and Response
Co-op's experience highlights the value of proactive measures:
- "Co-op proactively shut down parts of its IT network after detecting a potential cyber threat... a textbook example of early detection and decisive action making all the difference." [7]
Organizations that can detect and respond to threats quickly, often aided by Endpoint Detection and Response (EDR/XDR) solutions and dedicated Security Operations Centers (SOCs), appear to suffer less severe operational disruption.
5. Foster Industry Collaboration
Retail Technology Magazine publisher Miya Knights emphasizes that retailers must share knowledge:
- "Chief information security officers (CISOs) in retail need to get round a table and talk about what happened and share best practice and knowledge so they can all be better armed against these hackers. What floats all boats can also sink all boats, so I think they need to share knowledge about what's happened so they can all be better protected." [2]
The Retail Security Wake-Up Call
These attacks represent what many experts are calling a "wake-up call" for the retail industry. As Florimond De Tinguy of digital commerce platform VTEX noted:
- "This isn't just an IT failure; it's a breakdown in how risk is prioritised at the board level. The takeaway is retailers need to treat digital infrastructure as critical infrastructure." [9]
The vulnerability extends beyond just M&S and Co-op. According to research from Cisco, just one in four UK firms are fully prepared to defend against complex cyber threats, with nearly half of surveyed organizations having over ten unfilled cybersecurity roles. [2]
Final Thoughts
The parallel cyber attacks on M&S and Co-op demonstrate that even well-established, resource-rich organizations remain vulnerable to determined attackers using relatively low-tech social engineering methods. As customers continue to expect seamless digital experiences and organizations collect ever-increasing amounts of personal data, the retail sector must fundamentally reconsider its approach to cybersecurity.
For technology professionals across all industries, these incidents serve as a sobering reminder that cybersecurity is not merely an IT problem but a critical business risk that requires continuous investment, board-level attention, and cross-industry collaboration.
Footnotes
[1] Computer Weekly, "Chaos spreads at Co-op and M&S following DragonForce attacks," May 2025
[2] Retail Gazette, "The M&S and Co-op Cyber Attacks: Implications for UK Retailers?," May 2025
[3] Reuters, "M&S, Co-op cyberattackers duped IT help desks into resetting passwords, says report," May 2025
[4] ITV News, "M&S and Co-op: What we know weeks after cyber attacks," May 2025
[5] Al Jazeera, "M&S and Co-op Hit by Cyberattack: What Happened, Who's Behind It?," May 2025
[6] Grocery Gazette, "After M&S and Co-op's cyber hacks, who's next?," May 2025
[7] Cyber Security Awareness, "Cyber attack hits M&S and Co-op," May 2025
[8] Prolific North, "Cyber security expert warns of three-year wait for full recovery from M&S and Co-op cyber attacks," May 2025
[9] City AM, "Why M&S and the Co-op Were Hit by Cyber Attacks," May 2025