Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Retail Lessons From a £300 Million Cyber Attack

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2025, written in 2026 with the benefit of hindsight.

The short version: In 2025, attackers reportedly tricked an IT help desk into resetting access, then shut down Marks & Spencer's online store for weeks. The company estimated around £300 million in lost profit. It was the same technique used against MGM two years earlier.

Why retail is especially exposed

Retailers depend on tightly connected systems — e-commerce, warehouses, stores, suppliers — and often outsource IT support. A single compromised account can reach systems that, if disrupted, stop sales immediately.

The business impact

  • Weeks without online sales.
  • Empty shelves from logistics disruption.
  • Customer data theft.
  • Hundreds of millions in lost profit.

Questions to ask your team

  • How does our IT help desk — including outsourced providers — verify who's calling before resetting access?
  • Could an attacker with one employee's password register their own login device?
  • How long could we run stores and fulfillment if our core systems were down?
  • Have we tested our help desk against impersonation?

What good looks like

Strong verification at every help desk, extra protection for privileged accounts, controls preventing attackers from registering their own MFA devices, and continuity plans for revenue-critical systems.

The decision

Require your outsourced IT providers to follow — and prove — the same verification standards as your internal team. In both MGM and M&S, the help desk was the front door.

marks and spencer cyber attack impactM&S / Scattered Spider2025

More on this story