The M&S Cyber Attack Started With a Phone Call
The cyber attack on Marks & Spencer has become one of the most discussed business security incidents in UK history. With confirmed losses now exceeding £100 million and a separate attack on Co-op, carried out by the same criminal group, resulting in the theft of 6.5 million customer records, both incidents have prompted serious questions about how UK organisations protect themselves.
They deserve attention for one particular reason: neither attack started with sophisticated malware or a technical zero-day exploit.
They started with a phone call.
What actually happened
The group responsible for the attacks, a criminal network reportedly operating under the name Scattered Spider and using DragonForce ransomware, used a technique called social engineering. Rather than finding a technical flaw in M&S’s systems, the attackers called a third-party IT support contractor. They impersonated a legitimate employee, persuaded the help desk operator to reset login credentials, and used those credentials to gain access to the network.
Social engineering means manipulating people rather than technology. In this case, the attacker did not need specialist hacking tools. They needed a convincing story, a phone, and a help desk operator who had not been trained to verify who they were actually speaking to.
Once inside, the attackers moved through systems, extracted data, and eventually deployed ransomware that caused widespread and sustained disruption to operations.
The final bill for M&S alone: £101.6 million, including £82.7 million in incident response costs and £18.9 million in third-party costs. Contactless payments failed. Online orders were down for weeks. The reputational damage continues.
Why this matters to your business
Here is the uncomfortable reality: if this technique can bring down one of the UK’s largest retailers with a dedicated IT security team and significant technology investment, it can be used against almost any organisation.
In some respects, smaller businesses are more exposed. There is often less formal guidance on how staff should verify callers, fewer controls over who can authorise a password reset, and closer, more informal relationships with IT support providers where trust is assumed rather than checked.
NCSC research published this year found that 1 in 2 small businesses experiences a cyber security incident annually. The average cost of a significant attack is £195,000. For a business with 10 to 20 employees, that figure alone could be existential. And unlike M&S, most small businesses do not have the reserves to absorb it.
The M&S and Co-op attacks are a reminder that cyber security is not purely a technology problem. It is a people and process problem as much as anything else. The most sophisticated firewall cannot stop an attacker who is handed the keys by a well-meaning member of staff.
What we have already done for managed clients
For businesses we look after through our managed IT security services, we have controls in place that make this type of attack significantly harder to execute:
- Multi-factor authentication (MFA) is required on all accounts. MFA is a second verification step required at login, such as a code from a mobile app, on top of a password. It means that even if an attacker obtains or is given a valid password, they cannot log in without also having access to that second factor. A stolen password alone is no longer enough.
- Identity verification procedures apply to any request involving account access changes. Before any password reset or account modification is made, the identity of the person requesting it is confirmed through a secondary method, not just taken on trust.
- Staff awareness guidance is provided to client teams, covering impersonation attempts, phishing, and how to respond to unusual or urgent requests.
We apply these same standards to how we handle requests made to us. Any call claiming to be from a client and requesting account access goes through a documented verification process before any change is made.
What to check if no one is managing this for you
If you manage your own IT or use a provider without these controls in place, here are the most important steps to take now:
- Enable MFA on every account. Microsoft 365, email, accounting software, banking, anything business-critical should require a second verification step. This is the single most effective control against credential theft. The NCSC provides straightforward guidance on how to do this at ncsc.gov.uk, and it is free.
- Create a verification process for IT requests. Anyone requesting a password reset or account change, whether that is your staff, your IT provider, or someone claiming to be either, should be verified through a second, independent channel before any change is made. A phone call is not enough on its own.
- Teach your team to treat urgency as a warning sign. Social engineering attacks almost always create artificial pressure: “I am locked out and need access right now.” Train staff that the correct response is always to slow down and verify, never to act quickly because someone sounds stressed or important.
- Ask your IT provider how they verify your identity. What happens if someone calls them claiming to be you and asks for a password reset? If they do not have a clear, documented answer, that is a gap that needs closing.
If you are unsure whether your business has the right controls in place, our IT support team can carry out a review. We also offer Cyber Essentials certification, the government-backed security scheme that establishes a practical baseline of controls, including MFA requirements and access management, that make social engineering attacks significantly harder to execute. Contact us to find out more.
The lesson
The M&S attack was not primarily a failure of technology. It was a failure of process and of the assumption that trust is a substitute for verification. Getting the basics right, MFA, documented verification procedures, and staff awareness, is not glamorous. But it is what stops a phone call from becoming a six-figure crisis.
If your business has not reviewed its access controls and verification procedures recently, now is the right time to do so.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


