Phishing, Threat Intelligence

Hackers pose as IT staff in UK retail cyber strikes

A glowing red exclamation point inside a glowing red triangle on a glowing red digital background

BBC reports that the UK’s National Cyber Security Centre has issued a critical alert to businesses after a series of cyber attacks on major retailers, including Marks & Spencer, Co-op, and Harrods, where hackers impersonated IT help desks to gain unauthorized access.

Criminals used social engineering tactics, such as posing as locked-out employees or IT staff, to manipulate password resets and breach systems. The NCSC urged organizations to reevaluate help desk authentication procedures, especially for senior personnel, and recommended implementing multi-factor verification and code words for identity confirmation. Although the group behind the attacks denied links to the notorious Scattered Spider collective, known for sophisticated, financially motivated breaches, their methods bear striking similarities. Instead, the attackers identified themselves as “DragonForce,” a group reportedly fluent in English and already claiming responsibility for breaching Co-op systems and stealing data. Investigations are ongoing, with authorities collaborating with affected companies to assess the scope and origins of the campaign.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds