Back to Blog

The M&S and Co-op Attacks: Your Help Desk Is the Front Door

In April 2025, Marks & Spencer and the Co-op were both compromised. M&S expected a £300m hit to operating profit; statutory pre-tax profit for the six months to 27 September fell from £391.9m to £3.4m. The Co-op took an £80m hit in the first half and projected £120m for the full year. Online orders at M&S were suspended for 46 days.

No zero-day was involved. The attackers picked up the phone.

The initial access

Both intrusions have been attributed to Scattered Spider (also tracked as UNC3944) — publicly identified by the NCSC and National Crime Agency as the primary suspect in May 2025. The group’s signature technique is social engineering of IT help desks: a fluent, confident phone call from someone claiming to be an employee locked out of their account, and a help desk operator who resets the password or re-enrols MFA on the caller’s device.

In the M&S case, reporting indicates the compromised help desk was operated by a third-party IT services contractor supporting identity and endpoint operations. The attackers did not need to breach M&S directly. They needed to convince a contractor’s employee, following a documented process, to do something entirely routine.

Why this is difficult to defend

This is what makes help desk social engineering effective: the person being manipulated is doing their job correctly. Resetting credentials for a locked-out user is the help desk’s core function, and every minute spent verifying identity is a minute an increasingly frustrated employee is unable to work. The incentives point the wrong way.

Technical controls do not help much here either. MFA was not bypassed — it was re-enrolled, legitimately, by staff with the authority to do so.

What actually reduces the risk

The fix is procedural, and it is uncomfortable. Identity verification for credential and MFA resets must not rely on information an attacker can research or socially engineer — not employee ID, not date of birth, not a manager’s name.

Workable approaches include verification via a pre-registered channel the caller did not nominate, approval from a manager contacted independently, video verification against a personnel record, or in-person reset for privileged accounts. Every one of them is slower. That is the point.

Then apply the same standard to your outsourced providers. If a third party can reset credentials in your environment, their verification process is your control, and you should have read it.

The uncomfortable question

Call your own help desk — or your provider’s — and ask them to reset your MFA without identifying yourself. What happens next tells you more about your security posture than most audits will. For a business the size of M&S, that call was worth £300m.

Sources

#CyberSecurity#Ransomware#SocialEngineering

Need IT support?

Let's discuss how we can help protect and optimise your technology infrastructure.