Following three major cyberattacks that hit leading retail chains in the UK, the National Cyber Security Centre (NCSC) has issued urgent security guidance, calling on all businesses to strengthen their cybersecurity defensive practices.

The reason for this intervention was the serious incidents of violation that occurred in the well-known chains Marks & Spencer, Co-op and Harrods — three giant companies in the British retail trade.
The first attack targeted Marks & Spencer , which was hit by the DragonForce ransomware . The group Scattered Spider is believed to be behind the attack . As a result, the company's critical services such as online shopping, contactless payments and Click & Collect were disrupted.
See also: New EDR bypass “Bring Your Own Installer” used in ransomware attacks
A few days later, the Co-op announced that it had encountered suspicious activity on its network, restricting access to the corporate VPN as a precautionary measure. Although it was initially suggested that the attack had been thwarted, it was eventually confirmed that a large amount of customer personal data had been stolen.
On May 1, Harrods announced that an attempted intrusion into its network had led to restrictions on online access, an indication of the organization's immediate response, although no breach was officially confirmed.
All three attacks are reportedly related to the DragonForce ransomware. According to BleepingComputer, the perpetrators reportedly used the same social engineering technique to breach both M&S and Co-op. Although the ransomware successfully installed itself on M&S’s network, Co-op managed to intercept the attack in time, before the encryption code could be activated.
The NCSC 's security guidance now comes with the warning that these incidents should be considered a "wake-up call" for every major business in the country, as they could be the next targets of similar attacks.
The picture behind the attacks is still unclear – Investigations continue
The NCSC is currently refraining from attributing responsibility to specific perpetrators, stating that the identity of those responsible remains under investigation. The agency continues to work with victims and authorities to determine whether this was a coordinated action or unrelated incidents.
"We have some indications, but we are not yet able to confirm whether these attacks are linked or whether they are isolated incidents from different threat actors," said an NCSC spokesperson, adding that investigations are continuing in conjunction with law enforcement.
See also: Ransomware attacks decrease in April (+ most significant incidents)
Although the NCSC has reservations, a report by BleepingComputer reports that the cyberattacks on M&S and Co-op bear the signature of groups such as Scattered Spider and Lapsus$, which are known for using similar tactics and are active in common digital environments such as Telegram, Discord and well-known hacking forums.
The two attacks appear to have started with social engineering methods: the attackers pretended to be employees of the companies and contacted technical support departments, eventually managing to convince employees to reset their access credentials – thus granting them access to internal networks.
For this reason, the NCSC is urging all companies to review their help desk security protocols. In particular, password reset procedures should be made more stringent, ensuring the identification of employees – especially those with elevated access rights.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The wave of cyberattacks affecting major businesses in the UK – such as Harrods, M&S and Co-op – clearly highlights how vulnerable even the most organised companies are when it comes to cybersecurity issues. These attacks demonstrate the need for ongoing staff training and strengthening a culture of digital security.

The fact that the attacks managed to paralyze critical functions (such as payments, online orders, and VPNs) shows how great the risk is not only for the technical infrastructure, but also for the reputation and trust of consumers.
The NCSC points out that while much data remains unclear, there is also information that is not being made public for security reasons, as the relevant investigations are ongoing.
NCSC guidelines for strengthening digital security
In response to recent cyber threats, the UK's National Cyber Security Centre (NCSC) has published a guide with key measures that companies should take to reduce the risk of digital intrusion and strengthen the protection of their infrastructure.
See also: Romania elections: Russian hackers carried out DDoS attacks
The organization's proposals are summarized in the following key points:
- Adopting multi-factor authentication (MFA) across all systems, without exceptions, to increase the difficulty of access by unauthorized users.
- Continuous monitoring for suspicious activity, such as unrecognized logins or account breaches, especially those detected through Microsoft Entra ID Protection.
- Regular auditing of administrative accounts (Domain, Enterprise and Cloud Admin), with the aim of confirming that they are only used by authorized personnel.
- Review support procedures regarding password resets, ensuring strong authentication protocols are in place before access is granted.
- Strengthen connection monitoring with an emphasis on suspicious sources, such as home VPNs or unidentified endpoints, to detect and isolate potential threats.
The NCSC emphasizes that all businesses, regardless of size or sector, must operate with the logic of "early preparation" and assume that they may be targeted by cybercriminals in the near future.
Meanwhile, experienced researchers like Kevin Beaumont and Will Thomas, who are closely monitoring the development of these attacks, have shared their own practical guidelines for identifying and neutralizing similar threats.
The central recommendation to the business world is clear: regardless of geographical location or sector of activity, it is essential to adopt these preventive practices to strengthen digital defense against an increasingly complex threat environment.
Source: www.bleepingcomputer.com
