Hackers may ‘try their luck’ with other retailers after M&S breach, experts say

2 May 2025, 10:14

A zoom burst photo of a user touching the screen of a laptop displaying a ‘Matrix’-style screensaver
Internet Browsing Stock. Picture: PA

Cybersecurity experts say the flurry of attacks on retailers shows hackers are becoming bolder.

Cybercriminals are becoming “increasingly opportunistic” and willing to “try their luck” with cyber attacks on firms in the same sector, experts have said after Harrods confirmed it was the latest retailer to be targeted.

The luxury London department store said it had restricted internet access across its sites on Thursday as a precautionary measure following an attempt to gain unauthorised access to its systems.

It follows a serious ransomware attack on Marks & Spencer that has forced the company to suspend online orders and halt all recruitment, and the Co-op has also confirmed it was the target of an attempted breach, and it too has shut down some of its IT systems as a precaution.

It’s typical for similar companies in the same sector to become secondary targets after a huge cyber attack

Jake Moore, Eset

Jake Moore, global cybersecurity adviser at Eset, said other retailers being targeted in the wake of the M&S breach was “typical”, as hacking groups are often inspired to “try their luck” by using the same type of ransomware elsewhere.

“It’s typical for similar companies in the same sector to become secondary targets after a huge cyber attack,” he said.

“As the strain of ransomware called DragonForce can simply be purchased on the dark web in a model called ‘ransomware-as-a-service’, other hacking groups are also able to attempt their luck on similar businesses and start demanding ransoms where possible.

“It is often a precautionary measure to shut down parts of a system after a major cyber attack to mitigate any threats and prevent similar breaches.

“However, attacks involving the DragonForce ransomware most commonly start by targeting known vulnerabilities such as attacking systems that have not been kept up to date with the latest security patches, so businesses need to be extra vigilant and improve how quickly they update their networks.”

Cybersecurity expert Cody Barrow, chief executive of EclecticIQ, said the flurry of attacks showed cybercriminals are becoming bolder.

What's deeply concerning is generative AI is accelerating the threat landscape

Cody Barrow, EclecticIQ

“Coming on the heels of recent breaches at Co-op and M&S, it highlights an alarming trend: attackers are becoming increasingly opportunistic, exploiting weaknesses across complex, highly interconnected supply chains,” he said, warning that artificial intelligence was also making it easier for lower-skilled hackers to put together sophisticated attacks.

“What’s deeply concerning is generative AI is accelerating the threat landscape.

“Sophisticated phishing campaigns, deepfake social engineering, and adaptive malware are now within reach of even low-skilled attackers.

“This widespread access to advanced attack tools is driving up attack volume, speed, and complexity.”

According to reports, a hacking group known as Scattered Spider is said to be behind the M&S attack, although this has not been confirmed.

It also remains unclear if the three attacks are linked.

It’s a lesson again in the growing difficulty large organisations have in securing against threats in their supply chain, particularly as those threats grow in volume and sophistication

Toby Lewis, Darktrace

Toby Lewis, head of threat analysis at cybersecurity firm Darktrace, said the attacks could be linked by a common piece of technology used by all three firms that has a vulnerability, or that Co-op and Harrods had stepped up their own security response in the wake of the M&S breach.

“Details of the cyber attack at Harrods are still low and we shouldn’t rule out that the three incidents impacting M&S, Co-operative and Harrods are coincidence,” he said.

“However, with the information publicly available we can see two other likely scenarios: either a common supplier or technology used by all three retailers has been breached and used as an entry point to big-name retailers, or the scale of the M&S incident has prompted security teams to relook at their logs and act on activity they wouldn’t have previously judged a risk.

“It’s a lesson again in the growing difficulty large organisations have in securing against threats in their supply chain, particularly as those threats grow in volume and sophistication.”

By Press Association

More Technology News

See more More Technology News

In this photo illustration, an Apple logo is seen displayed alongside the Google logo.

Tech giants Apple and Google 'profiting from phone thefts', MPs claim

A man's hands using a laptop keyboard

Scots warned of ‘scamdemic’ as £860,000 lost to cyber criminals in 12 months

A close up image of a The North Face fleece

North Face and Cartier customer data stolen in cyber attacks

Imagery of a Zilch payments card and a virtual card

Buy now pay later provider Zilch to launch first physical card

UK’s most EV-friendly city has been revealed by new research.

Cities with slowest EV charging times and least amount of chargers revealed

View of a VodafoneThree logo outside the firm's offices

Vodafone completes Three UK mega-merger to form ‘new force’ in mobile market

A hand holding a Monzo bank card and a mobile phone showing the Monzo app

Monzo annual profit surges as paying subscribers boost digital bank

Majestic British Airways Airbus A380 taking off from London Heathrow at sunset, amazing colors

UK airspace shake-up could slash journey times and cut flight delays for millions of passengers

File photo dated 30/05/25 of the saltmarsh at Abbotts Hall in Essex. Saltmarshes are 'significant' carbon stores, but are at risk from rising sea levels, new research reveals

UK's muddy saltmarshes vital to tackle climate change, report finds

Nigel Farage

Reform backs cryptocurrency tax cut as party receives first Bitcoin donations

Digital devices on office workplace table of young business woman

‘Young people and black workers at highest risk of workplace surveillance’

Debris from the Titan submersible, recovered from the ocean floor near the wreck of the Titanic, is unloaded from the ship Horizon Arctic at the Canadian Coast Guard pier in St. John's, Newfoundland, in June 2023

The shock household item discovered in 'sludge' of OceanGate sub wreckage

Google is facing a £25 billion legal claim in the UK, accusing the tech giant of abusing its dominant position in the online search advertising market

Google facing £25 billion legal claim over abuse of search advertising market

A hand holding a phone showing the Nvidia logo

Nvidia posts strong growth despite ongoing tariff challenges

Dinosaur fossils could hold the key to new cancer discoveries and influence future treatments for humans, scientists have said.

Dinosaur fossils with tumours could hold key to new cancer treatments for humans, scientists say

A SpaceX Starship spun out of control in a test flight

Elon Musk's SpaceX Starship spirals out of control before exploding in third consecutive mission failure