In response to a series of cyberattacks targeting major UK retailers, the National Cybersecurity Center (NCSC) has urged businesses to enhance their cybersecurity measures. The advisory follows incidents involving prominent retailers such as Marks & Spencer, Co-op, and Harrods, which have faced data breaches and operational disruptions. The NCSC aims to assist companies in minimizing the risk of such attacks by recommending the implementation of multifactor authentication, monitoring unusual login activities, and reviewing password reset protocols.
The cyberattack on Marks & Spencer has been attributed to the financially driven cybercrime group Scattered Spider, which deployed DragonForce ransomware on the company’s VMware ESXi server. Similarly, Co-op faced a security breach that led to the temporary shutdown of its online ordering system. While customer data, including names and contact information, was compromised, Co-op clarified that no financial details were accessed. Harrods also reported a cyber incident, leading to restricted internet access in some of its stores.
The UK Information Commissioner’s Office confirmed that both Co-op and Marks & Spencer have reported the breaches and are collaborating with the NCSC to investigate further. While the NCSC is actively working with the affected organizations and law enforcement, it remains unclear whether these attacks are interconnected or perpetrated by the same actor. However, the agency is committed to understanding the nature of these incidents and mitigating potential damage.
Matt Western, chair of the Joint Committee on the National Security Strategy, emphasized the gravity of these cyberattacks, highlighting their potential impact on the broader food supply chain and local communities. Western called for a robust government response to address these threats seriously. In line with this, Pat McFadden, the minister for intergovernmental relations, conducted a briefing with the NCSC CEO to discuss the support extended to affected retailers.
These incidents serve as a wake-up call for businesses to bolster their cybersecurity defenses and ensure resilience against potential cyber threats. The NCSC’s recommendations are aimed at helping organizations safeguard their operations and protect sensitive customer data from future cyberattacks.