U.K. — The hacking collective Scattered Spider carried out cyberattacks against Marks & Spencer, Co-op, and Harrods in 2025. The attacks involved impersonating employees to access corporate systems.

Attackers gained access to Marks & Spencer internal systems by impersonating an employee and convincing a third-party service desk agent to reset credentials. Archie Norman, Chairman of Marks & Spencer, confirmed that attackers impersonated an employee to access the company's systems.

The method used by attackers to gain access to corporate systems involves service desk social engineering. Verizon's Data Breach Investigation Report found that stolen credentials are involved in 44.7% of breaches. This statistic highlights the prevalence of credential theft in security incidents. Organizations often rely on third-party service desks for IT support, creating potential vulnerabilities. Attackers exploit these channels by manipulating support agents into resetting passwords or granting access. The 2025 incidents demonstrate how social engineering tactics continue to evolve. Security experts emphasize the need for improved verification protocols. Training for service desk agents remains a critical defense layer. Companies must balance operational efficiency with strict identity confirmation measures. The impact of these breaches on affected retailers continues to be assessed. Customers may face risks if personal data was compromised during the intrusions. Regulatory bodies could review compliance with data protection standards following the attacks. The Scattered Spider group has been linked to previous high-profile cyber incidents. Their techniques often combine technical exploits with human manipulation. Preventing such attacks requires coordination between technology teams and employee awareness programs. The financial sector and retail industry remain frequent targets for these operations. Investigation into the full scope of the 2025 breaches is ongoing.