How attackers walked into three UK retailers through the service desk

October 15, 2025

Between April and May 2025, three British retailers were disrupted by the same group of attackers. Marks & Spencer stopped taking online orders for several weeks, the Co-op emptied shelves it could not restock, and Harrods restricted internet access at its sites. None of it began with a software vulnerability.

Giving evidence to a House of Commons sub-committee on 8 July 2025, the chairman of Marks & Spencer described how the attackers had got in. They impersonated an employee, telephoned the service desk operated by a third-party provider, and asked for a password reset, which the desk carried out.

The control that failed was a conversation

Everything downstream of that call was ordinary. With a working credential the attackers moved through the estate at their own pace, and by the time anything looked wrong the position was already established. The security industry spent the following months discussing ransomware strains and lateral movement, which is a reasonable technical conversation and a poor description of what actually happened.

What happened is that a person with authority to reset a password was persuaded to use it. That authority is a control in the same sense that a firewall rule is a control, but it is rarely documented as one, rarely tested, and almost never included in the register of things that would be catastrophic if misused.

The group behind the attacks, tracked publicly as Scattered Spider, is known for exactly this approach. It does not need an unpatched server when it can find somebody whose job is to be helpful and who is measured on how quickly they resolve a ticket.

An outsourced desk is still your perimeter

The service desk in this case was run by a supplier, which is normal and by itself unremarkable. The consequence is that the effective authority to reset credentials sat with people employed by another organization, working to that organization's handling times, under a contract that almost certainly described service levels in far more detail than it described identity verification.

This is the part worth taking to your own arrangements. The question is not whether your provider is competent, because they usually are. The question is what a helpful agent under time pressure is permitted to do when somebody who sounds credible says they are locked out and needs access before a deadline.

Two people in shirtsleeves conferring over a phone held between them

The attackers did not exploit a vulnerability. They telephoned a service desk, said they were an employee who had lost access, and were given a password reset by somebody whose job was to help.

The loss was operational rather than informational

Marks & Spencer told investors in April 2025 that the incident was expected to take roughly £300 million off its annual profit. In June 2025 the Cyber Monitoring Centre classified the Marks & Spencer and Co-op incidents together as a single Category 2 systemic event. It estimated the combined financial impact at between £270 million and £440 million, and described the shape of it as narrow and deep.

That figure is worth reading carefully, because most boards have been trained to think about breaches in terms of data. Here the expensive part was weeks of interrupted trading, cancelled online ordering and depleted shelves, and none of that appears in a template built around notification obligations and records exposed.

An organization that has modelled its cyber exposure purely as a privacy problem has modelled the smaller half of it. The recovery time of the systems that take money is the number that determines what an incident costs, and it is a question for business continuity as much as for the security team.

What is reasonable to ask a provider

Three questions are worth putting to whoever runs your service desk, and the value is in the specificity of the answers rather than in the fact of asking.

  • What proof of identity is required before a privileged credential is reset, and who is permitted to waive it? A process with a documented exception route is more honest than one that claims never to bend, and the exception route is where the risk lives.
  • What is the agent measured on? Where handling time is the primary metric, verification is the step that gets compressed, and no amount of policy language changes that incentive.
  • What happens when the caller is persistent or senior? Escalation under pressure is the specific scenario the attackers rehearse, and it should be the specific scenario your provider has rehearsed too.
Close-up of syntax-highlighted source code on a dark screen

Everything after the reset was ordinary intrusion work. The step that decided the outcome happened before any of it, in a conversation that left no technical trace.

Rehearsal beats policy

The organizations that handle this well tend to have run the scenario rather than written it down. A short exercise in which somebody plausible calls the desk and asks for access reveals more about the real procedure than a review of the documented one, and it tends to be uncomfortable in a way that produces change.

This is the argument for treating training as an operational control rather than an annual compliance task. Staff who have been walked through the specific approaches used against organizations like theirs behave differently on the call, and the people who most need that rehearsal are often the ones furthest from the security function.

The same reasoning applies to the wider estate. A cybersecurity review that examines systems without examining the human procedures wrapped around them will conclude that the controls are sound, and in the technical sense it will be right.

Where this leaves the board

Three things are worth establishing, and none of them requires a technical briefing to understand.

  1. Who, inside the organization and outside it, can reset access to a privileged account, and what they would need to see before refusing.
  2. How long the systems that take money would take to restore, tested rather than estimated, since that number sets the cost of an incident.
  3. Whether the identity-verification steps in your outsourcing contracts are specified at the same level of detail as the response times.

The retailers hit in 2025 were not careless organizations, and that is the uncomfortable part. They were large, well-resourced businesses whose technical controls did what they were built to do, reached through a procedure nobody had thought of as a control at all. For a longer account of how ordinary organizational habits become the opening, our Book of the Month shelf has The Cuckoo’s Egg, which remains the clearest description of an intruder moving patiently through systems that were working exactly as designed.


Falcone International

Bring us a question like this one

We handle corporate investigations, due diligence, financial investigations and duty of care — usually for people who need something established quietly, and established properly, before it turns into a problem.

Talk to usSee what we do

Discover more Insights from Falcone International

“Never Split the Difference” offers an inside look into the world of high-stakes hostage negotiations, translated into tactics for personal and business use. Chris Voss, a former FBI negotiator, shares strategies that center around empathy, active listening, and tactical mirroring to sway outcomes. This book is an essential guide for anyone aiming to improve their negotiation skills and interpersonal effectiveness.

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

Fraud rises when budgets tighten. Pressure goes up, headcount comes down, and controls that quietly depended on someone having spare time stop working. This weekend read sets out where exposure concentrates during a downturn and which defenses actually hold: strong internal controls, systems that flag the patterns people miss, a crisis plan written before it is needed, and a culture in which raising an anomaly is not a career risk.

Joel Brenner sets the demand for transparency against the need for secrecy and finds that most institutions have no coherent answer to the collision. “Glass Houses” is less a privacy book than an account of what secrecy now costs, who can still maintain it, and how little of it survives in a world where nearly every action leaves a record somewhere.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories