Loading replies...
×
M&S recruitment is still fully stopped, almost a month in. Co-op opened 46 new vacancies today.
Marks and Spencer’s CEO will lose a £1.1m share grant as a result of their cyber incident. https://www.ft.com/content/43531d25-4f7a-4d6e-b809-e85bb8f0033e
M&S chief executive faces £1.1mn pay hit after cyber attack

Stuart Machin’s awards set to shrink after UK retailer’s share price drops following disclosure of sweeping hack

Financial Times

The Times reports M&S were breached through a contractor and that human error is to blame. (Both M&S and Co-op use TCS for their IT Service Desk).

The threat actor went undetected for 52 hours. (I suspect detection was when their ESXi cluster got encrypted).

M&S have told the Times they had no “direct” communication with DragonForce, which is code for they’re using a third party to negotiate - standard practice.

https://www.thetimes.com/uk/technology-uk/article/m-and-s-boss-cyber-attack-7d9hvk6ds

M&S bosses under fire after ‘damaging and embarrassing’ cyberattack

The Times reveals that the hackers penetrated the retailer’s IT systems through a contractor and worked undetected for about 52 hours before the alarm was raised

The Times

M&S looks to be moving to reposition their incident as a third party failure, which I imagine will help redirect some of the blame (they present their financial results during the week to investors): https://www.bbc.co.uk/news/articles/cpqe213vw3po

Both M&S and Co-op outsourced their IT, including their Service Desk (helpdesk), to TCS (Tata) around 2018, as part of cost savings.

M&S hackers believed to have gained access through third party

The retailer has been struggling to get its services back to normal after a cyber-attack in April.

BBC News

There's nothing to suggest TCS itself have a breach btw.

Basically, if you go for the lowest cost helpdesk - you might want to follow the NCSC advice on authenticating password and MFA token resets.

I've put a 3 part deep dive blog series coming out probably next week called Living-Off-The-Company, which is about how teenagers have realised large orgs have outsourced to MSPs who follow the same format of SOP documentation, use of cloud services etc. Orgs have introduced commonality to surf.

The Office of the Privacy Commissioner for Personal Data (PCPD) has confirmed that Marks and Spencer (M&S) Hong Kong has not informed it of a recent customer data leak, nor responded to its enquiries. https://hongkongfp.com/2025/05/19/ms-hong-kong-not-responding-to-privacy-commissioners-office-after-online-customer-data-breach/
M&S Hong Kong not responding to Privacy Commissioner’s Office after online customer data breach

The Office of the Privacy Commissioner for Personal Data says M&S Hong Kong has not informed it of a recent customer data leak, nor responded to its enquiries.

Hong Kong Free Press HKFP

"Cyber analysts and retail executives said the company had been the victim of a ransomware attack, had refused to pay - following government advice - and was working to reinstall all of its computer systems."

Not sure who those analysts are, but since DragonForce haven't released any data and M&S won't comment other than to say they haven't had any "direct" contact with DragonForce, I wouldn't make that assumption.

https://www.reuters.com/business/retail-consumer/ms-slow-recovery-cyberattack-puts-it-risk-lasting-damage-2025-05-19/

There's also a line in the article from an cyber industry person saying "if it can happen to M&S, it can happen to anyone" - it's ridiculous and defeatist given Marks and Spencer haven't shared any technical information about how it happened, other than to tell The Sunday Times it was "human error"

The Air Safety version of cyber industry would be a plane crashing into 14 other planes, and industry air safety people going "Gosh, if that can happen to British Airways it could happen to anybody!"

Tomorrow it’s one month since Marks and Spencer started containment, it’s also their financial results day.

Online ordering still down, all recruitment stopped, Palo-Alto VPNs still offline.

I made this point a few weeks ago, but... outsourcing all your IT, Networks, Service Desk (helpdesk) and operational cybersecurity is a temporary cost saving and basically paints a ticking timebomb on the org, IMHO.
M&S say online ordering will be stopped until sometime in July, and it has taken a £300m hit, far higher than analysts had predicted. https://www.bbc.co.uk/news/articles/c93llkg4n51o
M&S cyber-attack disruption to last until July and cost £300m

Customers have been unable to order online for almost a month due to the cyber-attack.

BBC News
Their CEO has commented they’ve drawn a line under the hack, without recovering, which has a bit of this energy honestly

The NCA has confirmed on the record that the investigation into the M&S and Co-op hack is focused on English teenagers. I could toot the names of the people I think they’ll pick up, but won’t.

https://www.bbc.co.uk/news/articles/ckgnndrgxv3o

M&S and Co-op hacks: Scattered Spider is focus of police investigation

The National Crime Agency tells the BBC how it is trying to find the culprits of the M&S and Co-op hacks.

BBC News
The CEO of M&S has declined to comment if they have paid a ransom. For the record: I’ve heard they have, in secret, via their insurance. https://www.reuters.com/business/retail-consumer/ms-says-cyber-attack-was-result-human-error-declines-comment-ransom-2025-05-21/
Co-op Group announces it's getting rid of paper prices in stores, going to electric displays. Good luck during a ransomware incident 😒

TCS has a security incident running around the M&S breach.

Interestingly the source claims TCS aren't involved in Co-op's IT - which is categorically false, they took over most of it while I worked there, including the helpdesk, and my team (SecOps) after I left.

https://www.ft.com/content/c658645d-289d-49ee-bc1d-241c651516b0

Insurance Insider say Co-op Group have no cyber insurance policy.

It’s got the insurance industry hard as they think they can ambulance chase other orgs with it.

https://www.insuranceinsider.com/article/2eu3sto6ggpzewrryexog/lines-of-business/cyber/m-s-attacks-could-be-the-key-to-winning-new-cyber-business

M&S attacks could be the key to winning new cyber business

While M&S had a cyber policy in place, Co-op and Harrods did not, Insurance Insider revealed.

Insurance Insider
Seven weeks in, Marks and Spencer still have recruitment closed, online orders stopped and no Palo-Alto GlobalProtect VPN.

While Co-op have restored every customer facing system and internal systems like recruitment and remote working, M&S still don't even have recruitment back.

I'm reliably told they paid the ransom, so they'll be target #1 basically forever with other ransomware groups now due to resiliency woes and willingness to pay.

DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers

Ransomware actor exploited RMM to access multiple organizations; Sophos EDR blocked encryption on customer’s network

Sophos News
@GossiTheDog The sla got reset because the helpdesk marked the ticket closed, reopen if the problem persists.
@GossiTheDog That is really surprising. I wonder why they didn't?
@GossiTheDog TCS will find a low-level engineer/analyst and their manager to fire. Say they've dealt with it and it'll never happen again.

@GossiTheDog

Take something from the shelf and when you reach the checkout, it costs twice as much! Nice!

@Newk @GossiTheDog
Which in the UK would be a criminal offence (under the law as it currently stands).
@GossiTheDog I guess it's low risk since the electronic displays are basically paper - Dumb eink displays that you update via RFID from a handheld. (The ones I saw in the local coop worked that way anyway.)
@ivor @GossiTheDog 3 or 4 years ago I was doing some IT work at a client while they had a demonstration of these eInk price displays. Those updated through IR, with special lamp fixtures with lots of mirrors on the ceiling – quite interesting technology, and I've since noticed those lamps at retailers that use this type of price displays. This can be tied directly into ERP, so as soon as you change the price in your accounting software, it can be changed on the shelf.

@GossiTheDog This stuff is brilliant. Based on e-paper and runs on Zigbee.

And they can raise the prices between you picking things off the shelf and going through the checkout and you'll have no proof that it was offered at a lower price.

@alda all you need is a smartphone or digital camera (Polaroid would work too, but might be a bit costly)
@GossiTheDog
@GossiTheDog and so the ransomware machine grinds on. Ffs.
@GossiTheDog > I could toot the names of the people I think they’ll pick up, but won’t. < Encrypt them with GPG and release the key afterwards?
@GossiTheDog I took that to mean that they (or more likely the analysts they hired) have concluded it's cheaper/quicker/safer to rebuild new systems from scratch than to continue any further recovery. So drawing a line in a financial & investigative sense, rather than saying that £300 million is just a scratch.
@GossiTheDog And rebuilding from the ground up would seem to tie in with their statement about online orders being unavailable until at least July and then "ramping up" after that.
@GossiTheDog I must admit to not being particularly enamoured by the overall concept of third party identity security services.
@GossiTheDog how do in register a future "I told you so" without disclosing who it's for? Asking for a friend...
@GossiTheDog unless maybe you outsource, but to a bunch of different providers, spreading risk? ie use local OpenLDAP as an organisation management tool (does not eerste a huge amount of resources, then set up mail with A, storage with B, web with C, etc. ?
@GossiTheDog I can imagine many business leaders going "oh, it's okay, we don't use TCS, we have another outsourced supplier..."

@GossiTheDog Want to guess how much of my IT leadership career has been focused on building in-house expertise and dialing back the presence of MSPs?

Enough that it's made for a pretty good living...

@GossiTheDog Its rather hypocritical that the Coop would be wading into the outsourcing game
@GossiTheDog Every company is a computer company now
@jpm @GossiTheDog this is how we know the species is doomed.

@GossiTheDog when I got my business degree, one of my management profs said that the instant you outsource, you give up control. To the service provider, you move from income to liability on the balance sheet because you now are costing them money, and to eke out any profit they need to cut costs related to providing service to you.

Thus you get all this *gestures vaguely*

@GossiTheDog I would buy one of those action that goes up when it goes done ! Would that be considered 'outsider trading' ?

@GossiTheDog I would love for IT to publish accident investigation reports in the same way as aviation.

No blame, no liability, no finger pointing, just lessons for everyone to learn and hopefully avoid the same.

(I know there have been some like the Irish Health Service that were excellent.)

@GossiTheDog yeah, breach the "low cost" IT outsourcer - whose staff feel little connection or affinity with the corporate customer - and *bingo* you hit the jackpot 🎰 with multiple corporate accounts to ransom.

How's that "low cost IT outsourcing" looking now?

@matthewskelton @GossiTheDog Of course, make it clear how little you care about your in-house support staff and the same problem arises.
@RogerBW @GossiTheDog oh for sure. It's always seemed weird to me that orgs treat IT admin as low skilled. They are the info front line - you need some of the best people in that position or you're fscked.
@matthewskelton @GossiTheDog Chickens. Home. Roost. Or something like that 🐓🏠💥
@GossiTheDog One of the big MSP's from India was adamant:
1. Personnel is not allowed to store passwords.
2. Must use unique passwords for every service.
3. Passwords must rotate every X days.
4. Only sanctioned apps are allowed.
5. No password manager is sanctioned or installed by default.

@GossiTheDog I recall it was a "TCS_80_ip" list in Entra Id marked "Trusted"/"MFA exempt" that contained 80 ranges from /15 to /24...

Yet happily pivoting through 3 layer deep RDP to get to a system to manage 

@GossiTheDog Something, something, can't outsource risk.
@GossiTheDog paywall 😭
RemovePaywall | Free online paywall remover

Remove Paywall, free online paywall remover. Get access to articles without having to pay or login. Works on Bloomberg and hundreds more.

@GossiTheDog having recently dealt with TCS, nothing would surprise me.
@GossiTheDog No direct contact with DragonForce? I'm sure they'll drag them Through The Fire And The Flames over this one.