All news
Security
6 May 2025

M&S and Co-op: social engineering, not clever hacking

A run of attacks on UK retailers started with convincing phone calls to IT help desks rather than technical exploits.

What this means for your business

Attackers reset credentials by persuading a human. Any business with a help desk, an office manager or an IT supplier can be targeted the same way.

The 2025 attacks on Marks & Spencer, Co-op and other UK retailers cost hundreds of millions in lost trade and led to weeks of disrupted operations. What made them notable wasn't the malware; it was the entry route. Attackers rang IT support desks, impersonated staff convincingly enough to get passwords and MFA reset, and walked in through the front door.

Why small businesses should care

The same technique is cheaper and easier against a small firm. There's usually no formal process, everyone knows each other, and being helpful is the culture. That's a strength most of the time and a weakness on the day someone calls pretending to be a director stuck at an airport.

Controls that actually stop this

  • A defined identity check for password and MFA resets — a callback to a known number, or a manager's confirmation. Write it down and stick to it even when the caller is annoyed.
  • No resets by email or chat alone. Compromised mailboxes send very convincing requests.
  • Named people who can authorise changes, agreed with your IT provider in advance.
  • Tell your team it's fine to say no and check. Most breaches of this type succeed because someone didn't want to be awkward.

We operate a verification step on sensitive requests for the customers we support, including password and MFA resets, and we'd rather ring you back than take a chance.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.