In recent weeks, three of the UK’s most recognisable retailers Marks & Spencer, Co-op, and Harrods have found themselves in the spotlight for the wrong reasons: significant cyber breaches that disrupted operations, compromised customer data, and exposed vulnerabilities in their digital infrastructure.

Retailers are increasingly targeted by cybercriminals due to the breadth of their digital footprint and the vast amount of sensitive customer data they hold. The complexity of just-in-time supply chains and reliance on integrated systems mean that even a short disruption can lead to financial losses, reputational damage, and customer dissatisfaction. These latest incidents reinforce the growing concern around the retail sector’s resilience to cyber threats.

What Happened?

The breaches, believed to be the work of a ransomware group known as DragonForce, involved impersonation techniques where attackers posed as employees to trick IT help desks into granting network access. This social engineering approach similar to methods previously attributed to the hacking group dubbed “Scattered Spider” allowed attackers to bypass security controls and infiltrate internal systems.

The attack on M&S occurred over the Easter bank holiday weekend, severely disrupting the retailer’s digital operations. Shoppers were unable to complete contactless payments, and services such as click-and-collect and online ordering were suspended. The attack is believed to have compromised the retailer’s stock ordering systems, leading to supply chain issues that resulted in empty shelves and the temporary withdrawal of meal deals. M&S has not yet confirmed the full scope of the breach but has remained cautious in reactivating affected services. Investigations suggest the breach was the result of a sophisticated ransomware attack involving impersonation tactics to gain access to internal systems.

Just days later, Co-op became the second major UK retailer to report a cyber incident. On 30 April, the company confirmed that parts of its back-office systems and customer call centres had been affected by a cyberattack. Staff were instructed to keep cameras switched on during video meetings, avoid recording calls, and refrain from sharing sensitive information via Microsoft Teams all measures designed to mitigate further exposure. By 4 May, reports emerged that a “significant” volume of customer data had been accessed by the attackers. The breach has raised concerns about internal security protocols and the handling of sensitive consumer information.

On 2 May, Harrods revealed that it too had experienced an attempted cyberattack. While the department store has not disclosed the full nature of the incident, it confirmed that cyber security specialists had been brought in to investigate and contain the threat. Unlike M&S and Co-op, Harrods managed to fend off the intrusion before extensive damage could occur. However, the attempted breach marked the third consecutive attack on a high-profile UK retailer within two weeks, fuelling broader concerns about the sector’s preparedness to withstand sophisticated cyber threats.

These incidents follow a pattern seen in previous high-profile retail breaches and serve as a reminder that both customer-facing services and back-end systems must be secured with equal diligence.

NCSC’s Guidance on Protecting Against Such Attacks

The UK’s National Cyber Security Centre (NCSC) has responded with a renewed call for action, particularly across retail and other consumer-facing sectors. It has urged organisations to bolster their defences by focusing on both prevention and incident response capabilities.

Key recommendations include:

  • Implementing multi-factor authentication (MFA) across all accounts, especially those with elevated access.
  • Enhancing monitoring capabilities to detect unusual login patterns, such as access from unknown locations or devices.
  • Reviewing internal IT processes, particularly password reset protocols, to prevent social engineering attacks targeting help desks.
  • Securing privileged accounts — such as Domain Admins and Cloud Admins — by verifying access rights and monitoring for misuse.
  • Strengthening incident response to detect and contain breaches early, minimising damage and ensuring recovery procedures are in place.
  • Consuming real-time threat intelligence to stay ahead of emerging tactics used by groups like Scattered Spider.

NCSC’s CEO, Dr Richard Horne, described these recent events as a “wake-up call” and urged businesses to adopt the centre’s guidance to better defend themselves against modern cyber threats.

How Your Business Can Stay Protected

Cybercrime is evolving rapidly, and small to medium-sized businesses are increasingly at risk, often due to limited resources and outdated security practices. As cybercriminals grow more sophisticated, the need for a robust cyber security strategy becomes not just important but essential.

At Kalamazoo IT, we specialise in helping businesses of all sizes build resilient digital infrastructures. From ransomware protection and security audits to advanced monitoring and staff training, we’re here to guide you through every stage of your cyber defence journey.

If your business handles sensitive data, relies on digital transactions, or simply wants to improve its cyber hygiene, we invite you to speak to one of our cyber security specialists.