The M&S cyber attack
We attach a recent article below written by Rupert Davey of ctm Information Technology, a colleague of KPDP Consultancy. An article which is becoming increasingly relevant in terms of data protection in view of M&S's recent admission that some personal data was stolen by the cyber attackers. For more details see the BBC News article published on the 13th of May 2025: M&S says personal customer data stolen in recent cyber attack - BBC News.
The British retailer M&S have been hit by a cyber attack impacting their stores and operations.
At ctm Information Technology we do not publicly talk about how we defend and secure IT systems, because the bad actors would love to know that, so I won't go into those specifics!
But it is interesting how long M&S have been offline.
The attackers, Scattered Spider, use Adversary-in-the-middle (AitM) to gain access to systems. Side note, hackers don't "hack", they log in:
1️. A user gets an email, clicks a link which goes to an attacker-controlled website.
2️. This looks exactly like the login page to Microsoft 365. The user enters their username & password, which the attacker now has.
3️. The attackers pop them into the real Microsoft site, which passes back the MFA code, which the attacker passes to the user.
4️. The attacker now has the MFA token of the user too and can log in as them.
The attacker is in the middle between the user and Microsoft, hence AitM.
This is all too easy to do. Scattered Spider go by various names, depending on who you ask, but the Microsoft details on the threat actor are here: https://lnkd.in/eW25Y8cg
Be under no illusion, these types of attacks are part of a huge dark-economy. Ransomware-as-a-Service (RaaS)... where the bad actors are actually customers, affiliates, of larger attackers.
Microsoft Security have this on RaaS: https://lnkd.in/ezYcsUh5
But why have M&S taken so long to get sorted?
To me, it looks like they didn't have thorough post-breach processes and procedures in place.
Perhaps they simply weren't resilient enough and now they're paying the price?
The Zero Trust architecture, that any organisation should have in place, as three pillars, are:
1️. Verify explicitly
2️. Use least privilege access
3️. Assume breach
Verify explicitly... using multifactor authentication, such as identity, device location, security of device, along with monitoring for any unusual activity.
Use least privilege access... only giving people the bare minimum access they need to do their job, and nothing more.
Assume breach... you assume you're going to get breached. And this then leads onto Incident Response Planning, Incident Recovery Planning... and a bunch of other stuff that all kicks in post-breach to allow you to get back up and running quickly.
Microsoft introduction to Zero Trust is here: https://lnkd.in/egUDuVC9
ctm Information Technology is an Ambassador for The Eastern Cyber Resilience Centre so check out their resources for an independent view on all this.
Also check out the National Cyber Security Centre.
But if you want to talk more about this, or your cybersecurity concerns, message Rupert Davey at ctm Information Technology.
We hold the Microsoft Security Solution Partner designation and there's more information about how we can help you here:
www.ctm-it.com/cybersec.
If you have been victim to this or another cyber attack affecting your personal data contact info@kpdpconsultancy.co.uk to discuss your data protection rights.
This article is for general information only. It does not constitute legal advice and should not be relied upon as such. If you require further information regarding its content, please contact us at info@kpdpconsultancy.co.uk. Law as of May 2025.
