Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    While Microsoft is obsessed with AI, Valve is stealing PC gaming away

    DIY PC building is a no-fly zone in 2026. (Thanks, RAM.) Now what?

    How to fix a touchpad that’s not working in Windows 11

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      A new pope, political shake-ups and celebs in space: The 2025-in-review news quiz

      December 31, 2025

      AI has become the norm for students. Teachers are playing catch-up.

      December 23, 2025

      Trump signs executive order seeking to ban states from regulating AI companies

      December 13, 2025

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025
    • Business

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025

      Zeroday Cloud hacking event awards $320,0000 for 11 zero days

      December 18, 2025

      Amazon: Ongoing cryptomining campaign uses hacked AWS accounts

      December 18, 2025

      Want to back up your iPhone securely without paying the Apple tax? There’s a hack for that, but it isn’t for everyone… yet

      December 16, 2025
    • Crypto

      $1 for the Keys? Dark Web Post Claims Kraken Admin Access for Sale

      January 2, 2026

      ZachXBT Flags Ongoing Wallet Exploit With Losses Exceeding $107,000

      January 2, 2026

      Analysts Identify 3 Indicators That Could Signal an Altcoin Season in 2026

      January 2, 2026

      Over $2.2 Billion in Bitcoin and Ethereum Options Expire as 2026 Begins

      January 2, 2026

      PEPE Surges 20% as James Wynn Gives Bold Prediction For 2026

      January 2, 2026
    • Technology

      While Microsoft is obsessed with AI, Valve is stealing PC gaming away

      January 2, 2026

      DIY PC building is a no-fly zone in 2026. (Thanks, RAM.) Now what?

      January 2, 2026

      How to fix a touchpad that’s not working in Windows 11

      January 2, 2026

      CES 2026 will bring faster, stranger laptops. Just don’t expect them to be cheap

      January 2, 2026

      Chip wars: What to expect from Intel, AMD, Nvidia, and Snapdragon at CES 2026

      January 2, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»M&S, Co-op attacks a ‘Category 2 cyber hurricane’, say UK experts
    Technology

    M&S, Co-op attacks a ‘Category 2 cyber hurricane’, say UK experts

    TechAiVerseBy TechAiVerseJune 20, 2025No Comments5 Mins Read1 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    M&S, Co-op attacks a ‘Category 2 cyber hurricane’, say UK experts
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    M&S, Co-op attacks a ‘Category 2 cyber hurricane’, say UK experts

    Tryfonov – stock.adobe.com

    The UK’s Cyber Monitoring Centre has published its first in-depth assessment of a major incident, reflecting on the impact of and lessons learned from Scattered Spider attacks on M&S and Co-op

    By

    • Alex Scroxton,
      Security Editor

    Published: 20 Jun 2025 17:00

    The Scattered Spider/Dragonforce cyber attacks that struck Marks & Spencer and Co-op during the spring have been classed as a Category 2 cyber event on the UK Cyber Monitoring Centre’s (CMC’s) recently launched ‘hurricane scale’, with total costs likely to end up somewhere between £270m and £440m.

    The CMC – an arm’s-length body set up by the insurance industry to assess the impact of cyber attacks on the UK and help organisations better manage their risk profiles, and backed by cyber experts including former NCSC lead Ciaran Martin – said that based on its incident categorisation matrix, the incident had had a “substantial financial impact” and resulted in “economic reverberations “across third-party suppliers, franchisees and supporting services”.

    In their assessment, the CMC team described the impact from the event as “narrow and deep” with significant implications for both companies and knock-on effects spreading to their suppliers, partners and service providers. This is in stark contrast to a “shallow and broad” event like the CrowdStrike incident of July 2024, where a far larger number of businesses suffered but the impact to any one organisation was much less.

    The CMC said that while it has yet to book a Category 4 or 5 event in the UK, had the disruption extended more widely across the retail sector, the attack campaign might have been ranked higher. In the event, of course, Scattered Spider’s campaign is known to have hit just two major retailers.

    That said, the CMC did note a third attack on Harrods, and other retailers and retail-adjacent organisations reported to have experienced incidents in the past few months, but said it had to confine its analysis to the more widely reported M&S and Co-op incidents because there was a lack of information about the cause and impact of other events at the time.

    CMC CEO Will Mayes told Computer Weekly: “This assessment provides, for the cyber and wider business community, a robust piece of analysis on the financial impact of a cyber event affecting two major retailers, which has been at the centre of a high volume of media attention.

    “We’re hugely grateful to our Technical Committee for the depth of expertise and experience that they applied to analysing the implications of the incident.”

    Financial costs

    In arriving at its figure of £270m to £400m, the CMC has drawn on a range of public and commercial data sources, including its own modelling, and a figure of approximately £300m floated by M&S in May during its annual results call.

    The CMC said its figure might have been higher based on statements made by M&S of an anticipated July restart date for online shopping. However, the fact that the retailer has since stood up some of its online shopping operations meant the CMC could pare back its estimates.

    The total figure includes covering the costs of business interruption arising from lost sales opportunities, incident response and IT restoration costs, and legal and notification costs. It does not include any ransom payments as it is not known if any have been made.

    Based on stats drawn from transactional data platform Fable Data, the CMC said that M&S saw a daily reduction in spend of 22% during the incident, with online sales dropping to essentially zero and in-store sales down 15% as the firm struggled to keep its Food Halls and other locations topped up. For Co-op, daily spend dropped by 11% during the first 30 days of the incident.

    The CMC observed that M&S’ distinct own-label business model and a number of exclusive contracts with suppliers left it particularly vulnerable to supply chain effects, with suppliers struggling to reroute goods, particularly items relying on cold chain storage.

    Turning to Co-op, the Fable data show daily spend dropped by 11% during the first 30 days of the incident. The CMC said that because Co-op is frequently the only bricks and mortar grocery chain in more isolated and remote parts of the country – particularly in the Highlands and Islands of Scotland – the incident demonstrated the broader social impacts of such cyber attacks.

    “The event underscores retail sector vulnerabilities tied to just-in-time stock systems, lack of back-end storage, and high dependency on IT-driven order flows. When systems fail, it is challenging to revert to manual processes,” said the team.

    Preparing to fail

    Looking into the future, the CMC said the Scattered Spider attacks had been an object lesson in preparedness for the retail sector, stressing the need to test business continuity and crisis response plans against ransomware attacks, including procedures for inventory management, and crisis communications.

    As well as noting, naturally, the need for improved cyber hygiene and proper understanding of retailers’ exposure to third-party risk – likely how the M&S and Co-op incidents began – the CMC also said that retailers needed to consider that the costs of business interruptions can be extreme, and it is wise to ensure that capital, or adequate insurance protection, is available to cover cyber attacks.

    This article was edited at 21:30 BST on Friday 20 June 2025 to incorporate additional information provided by the CMC.

    Read more on Data breach incident management and recovery


    • Scattered Spider widens web to target insurance sector

      By: Alex Scroxton


    • Adidas confirms customer data was accessed during cyber attack

      By: Caroline Donnelly


    • M&S cyber attack disruption likely to last until July

      By: Alex Scroxton


    • Retail cyber attacks hit food distributor Peter Green Chilled

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleElection workers’ data stolen in cyber breach of Oxford City Council
    Next Article Cyber Essentials certifications rising slowly but steadily
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    While Microsoft is obsessed with AI, Valve is stealing PC gaming away

    January 2, 2026

    DIY PC building is a no-fly zone in 2026. (Thanks, RAM.) Now what?

    January 2, 2026

    How to fix a touchpad that’s not working in Windows 11

    January 2, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025571 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025212 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025118 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025100 Views
    Don't Miss
    Technology January 2, 2026

    While Microsoft is obsessed with AI, Valve is stealing PC gaming away

    While Microsoft is obsessed with AI, Valve is stealing PC gaming away Skip to content…

    DIY PC building is a no-fly zone in 2026. (Thanks, RAM.) Now what?

    How to fix a touchpad that’s not working in Windows 11

    CES 2026 will bring faster, stranger laptops. Just don’t expect them to be cheap

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    While Microsoft is obsessed with AI, Valve is stealing PC gaming away

    January 2, 20261 Views

    DIY PC building is a no-fly zone in 2026. (Thanks, RAM.) Now what?

    January 2, 20261 Views

    How to fix a touchpad that’s not working in Windows 11

    January 2, 20261 Views
    Most Popular

    What to Know and Where to Find Apple Intelligence Summaries on iPhone

    March 12, 20250 Views

    A Team of Female Founders Is Launching Cloud Security Tech That Could Overhaul AI Protection

    March 12, 20250 Views

    Senua’s Saga: Hellblade 2 leads BAFTA Game Awards 2025 nominations

    March 12, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.