• Home
  • Services
    • Services for Organisations
    • Services for Individuals
    • Training
  • Fee Structure
    • Fee Structure for Organisations
    • Fee Structure for Individuals
  • News & Insights
  • Join Us
  • Contact
  • Home
  • Services for Organisations
  • Services for Individuals
  • Training
  • Fee Structure for Organisations
  • Fee Structure for Individuals
  • News & Insights
  • Join Us
  • Contact
 

The M&S cyber attack

Back to News
Contact Us
 
 
 

We attach a recent article below written by Rupert Davey of ctm Information Technology, a colleague of KPDP Consultancy. An article which is becoming increasingly relevant in terms of data protection in view of M&S's recent admission that some personal data was stolen by the cyber attackers. For more details see the BBC News article published on the 13th of May 2025: M&S says personal customer data stolen in recent cyber attack - BBC News.

 

The British retailer M&S have been hit by a cyber attack impacting their stores and operations.

At ctm Information Technology we do not publicly talk about how we defend and secure IT systems, because the bad actors would love to know that, so I won't go into those specifics!


But it is interesting how long M&S have been offline.


The attackers, Scattered Spider, use Adversary-in-the-middle (AitM) to gain access to systems. Side note, hackers don't "hack", they log in:


1️. A user gets an email, clicks a link which goes to an attacker-controlled website.
2️. This looks exactly like the login page to Microsoft 365. The user enters their username & password, which the attacker now has.
3️. The attackers pop them into the real Microsoft site, which passes back the MFA code, which the attacker passes to the user.
4️. The attacker now has the MFA token of the user too and can log in as them.

 

The attacker is in the middle between the user and Microsoft, hence AitM.

This is all too easy to do. Scattered Spider go by various names, depending on who you ask, but the Microsoft details on the threat actor are here: https://lnkd.in/eW25Y8cg

Be under no illusion, these types of attacks are part of a huge dark-economy. Ransomware-as-a-Service (RaaS)... where the bad actors are actually customers, affiliates, of larger attackers.

Microsoft Security have this on RaaS: https://lnkd.in/ezYcsUh5

 

But why have M&S taken so long to get sorted?

To me, it looks like they didn't have thorough post-breach processes and procedures in place.

Perhaps they simply weren't resilient enough and now they're paying the price?

The Zero Trust architecture, that any organisation should have in place, as three pillars, are:

1️.  Verify explicitly
2️.  Use least privilege access
3️.  Assume breach

Verify explicitly... using multifactor authentication, such as identity, device location, security of device, along with monitoring for any unusual activity.

Use least privilege access... only giving people the bare minimum access they need to do their job, and nothing more.

 

Assume breach... you assume you're going to get breached. And this then leads onto Incident Response Planning, Incident Recovery Planning... and a bunch of other stuff that all kicks in post-breach to allow you to get back up and running quickly.

Microsoft introduction to Zero Trust is here: https://lnkd.in/egUDuVC9

ctm Information Technology is an Ambassador for The Eastern Cyber Resilience Centre so check out their resources for an independent view on all this.

Also check out the National Cyber Security Centre.

But if you want to talk more about this, or your cybersecurity concerns, message Rupert Davey at ctm Information Technology.

We hold the Microsoft Security Solution Partner designation and there's more information about how we can help you here:
www.ctm-it.com/cybersec.

 

If you have been victim to this or another cyber attack affecting your personal data contact info@kpdpconsultancy.co.uk to discuss your data protection rights.

 

This article is for general information only. It does not constitute legal advice and should not be relied upon as such. If you require further information regarding its content, please contact us at info@kpdpconsultancy.co.uk. Law as of May 2025.

 

KPDP Consultancy does not provide legal advice. KPDP Consultancy is a Consultant Practice of Nexa Law Limited, and DR Solicitors Limited. All legal work is strictly conducted only via Nexa Law Limited, or DR Solicitors Limited.

Nexa Law Limited is a limited company registered in England & Wales, under number 10209198 and registered at Unit 14a Maes Y Clawdd, Maesbury Road, Oswestry, Shropshire SY10 8NN. Nexa Law Limited is authorised and regulated by the Solicitors Regulation Authority under SRA number 633024.

DR Solicitors Limited is a limited company registered in England & Wales, under number 06122637 and registered at 7400 Daresbury Park, Daresbury, Warrington, England, WA4 4BS. DR Solicitors Limited is authorised and regulated by the Solicitors Regulation Authority under SRA number 522996.

Cookie Notice

Digital Privacy Notice

Copyright © 2025 KPDP Consultancy. All Rights Reserved. Website designed by FirstFound

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept AllRead MoreReject All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
SAVE & ACCEPT

Get in Touch

Have a question about data protection? Fill in your details below and we will get back to you. 




    [honeypot winnie]