The 2025 attacks on Marks & Spencer, Co-op and other UK retailers cost hundreds of millions in lost trade and led to weeks of disrupted operations. What made them notable wasn't the malware; it was the entry route. Attackers rang IT support desks, impersonated staff convincingly enough to get passwords and MFA reset, and walked in through the front door.
Why small businesses should care
The same technique is cheaper and easier against a small firm. There's usually no formal process, everyone knows each other, and being helpful is the culture. That's a strength most of the time and a weakness on the day someone calls pretending to be a director stuck at an airport.
Controls that actually stop this
- A defined identity check for password and MFA resets — a callback to a known number, or a manager's confirmation. Write it down and stick to it even when the caller is annoyed.
- No resets by email or chat alone. Compromised mailboxes send very convincing requests.
- Named people who can authorise changes, agreed with your IT provider in advance.
- Tell your team it's fine to say no and check. Most breaches of this type succeed because someone didn't want to be awkward.
We operate a verification step on sensitive requests for the customers we support, including password and MFA resets, and we'd rather ring you back than take a chance.