Using early 2000s security posture, staff working from offices are an incredible risk to the organization. They will be compromised just as fast there, while also being inside a physical perimeter.
@Walker @GossiTheDog
×
Harrods say they are not asking customers to do anything differently at this point.
Financial Times report Marks and Spencer expect to claim £100m on their cyber insurance, the maximum allowed, suggesting losses probably more. https://www.ft.com/content/723b6195-1ce7-4b5f-94f5-729e9152c578
M&S cyber insurance payout to be worth up to £100mn

UK retailer to file big claim as it admits for first time that some customer data was stolen in recent hack

Financial Times

Co-op Group say they have exited containment and begun recovery phase https://www.theguardian.com/business/2025/may/14/co-op-cyber-attack-stock-availability-in-stores-will-not-improve-until-weekend

Marks and Spencer are still in containment

If you want figures for your board to set expectations in big game ransomware incidents, Co-op containment just over 2 weeks, M&S just over 3 weeks so far - recovery comes after.

In terms of external assistance, Co-op have Microsoft Incident Response (DART), KPMG and crisis comms. M&S have CrowdStrike, Microsoft, Fenix and crisis comms.

Co-op cyber-attack: stock availability in stores ‘will not improve until weekend’

Group in ‘recovery phase’ and working closely with suppliers after customers complain of empty shelves

The Guardian

The threat actor at Co-op says Co-op shut systems down, which appears to have really pissed off the threat actor. This was the right, and smart, thing to do.

While I was at Co-op we did a rehearsal of ransomware deployment on point of sale devices with the retail team, and the outcome was a business ending event due to the inability to take payments for a prolonged period of time. So early intervention with containment was the right thing to do, 100%.

https://www.bbc.co.uk/news/articles/cwy382w9eglo

'They yanked their own plug': how Co-op averted an even worse cyber attack

The revelation - from the criminals responsible - explains why the Co-op is getting back to business faster than M&S.

BBC News
Co-op Group recruitment looks like it is starting again, first new roles in two weeks posted. https://hcnq.fa.em2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX/jobs
Co-op External Career Section Careers

Find your Co-op job

Co-op External Career Section
Marks and Spencer say food distribution to their stores is returning to normal. It follows Co-op's announcement yesterday that food and drink distribution will begin to return to normal from the weekend. https://www.reuters.com/business/retail-consumer/uks-ms-says-food-availability-improving-every-day-2025-05-15/
27 new jobs at Co-op added today, and it's only midday. So recruitment was definitely paused for two weeks and now active again.

M&S have finally told staff that data about themselves was stolen: https://www.telegraph.co.uk/business/2025/05/16/ms-staff-data-stolen-by-hackers-in-cyber-attack/

You may notice I said they had staff data stolen on May 9th in this thread.

M&S staff data stolen by hackers in cyber attack

Employees’ email addresses and full names have been taken by hackers, sources claim

The Telegraph

For the record, the tools listed in this article aren't used by Co-op.

https://www.computing.co.uk/news/2025/security/five-cyber-tools-co-op-used-to-defeat-ransomware-attack

The link in the article to Vectra Cognito AI has a Coop Sweden logo on it, and the Coop Sweden CISO is named. Coop Sweden is different company. Coop Sweden went on to have a ransomware attack that crippled the org, including point of sale, so I don't think it's a good sales point. Same with Silverfort.

Google AI has ingested the article and now uses it to claim Co-op Group use the tools.

Here are the five cyber tools Co-op used to help defeat its recent ransomware attack

Computing research has identified the security tools and partners the Co-op used to stop last month’s cyberattack in its tracks.

M&S recruitment is still fully stopped, almost a month in. Co-op opened 46 new vacancies today.
Marks and Spencer’s CEO will lose a £1.1m share grant as a result of their cyber incident. https://www.ft.com/content/43531d25-4f7a-4d6e-b809-e85bb8f0033e
M&S chief executive faces £1.1mn pay hit after cyber attack

Stuart Machin’s awards set to shrink after UK retailer’s share price drops following disclosure of sweeping hack

Financial Times

The Times reports M&S were breached through a contractor and that human error is to blame. (Both M&S and Co-op use TCS for their IT Service Desk).

The threat actor went undetected for 52 hours. (I suspect detection was when their ESXi cluster got encrypted).

M&S have told the Times they had no “direct” communication with DragonForce, which is code for they’re using a third party to negotiate - standard practice.

https://www.thetimes.com/uk/technology-uk/article/m-and-s-boss-cyber-attack-7d9hvk6ds

M&S bosses under fire after ‘damaging and embarrassing’ cyberattack

The Times reveals that the hackers penetrated the retailer’s IT systems through a contractor and worked undetected for about 52 hours before the alarm was raised

The Times

M&S looks to be moving to reposition their incident as a third party failure, which I imagine will help redirect some of the blame (they present their financial results during the week to investors): https://www.bbc.co.uk/news/articles/cpqe213vw3po

Both M&S and Co-op outsourced their IT, including their Service Desk (helpdesk), to TCS (Tata) around 2018, as part of cost savings.

M&S hackers believed to have gained access through third party

The retailer has been struggling to get its services back to normal after a cyber-attack in April.

BBC News

There's nothing to suggest TCS itself have a breach btw.

Basically, if you go for the lowest cost helpdesk - you might want to follow the NCSC advice on authenticating password and MFA token resets.

I've put a 3 part deep dive blog series coming out probably next week called Living-Off-The-Company, which is about how teenagers have realised large orgs have outsourced to MSPs who follow the same format of SOP documentation, use of cloud services etc. Orgs have introduced commonality to surf.

The Office of the Privacy Commissioner for Personal Data (PCPD) has confirmed that Marks and Spencer (M&S) Hong Kong has not informed it of a recent customer data leak, nor responded to its enquiries. https://hongkongfp.com/2025/05/19/ms-hong-kong-not-responding-to-privacy-commissioners-office-after-online-customer-data-breach/
M&S Hong Kong not responding to Privacy Commissioner’s Office after online customer data breach

The Office of the Privacy Commissioner for Personal Data says M&S Hong Kong has not informed it of a recent customer data leak, nor responded to its enquiries.

Hong Kong Free Press HKFP

"Cyber analysts and retail executives said the company had been the victim of a ransomware attack, had refused to pay - following government advice - and was working to reinstall all of its computer systems."

Not sure who those analysts are, but since DragonForce haven't released any data and M&S won't comment other than to say they haven't had any "direct" contact with DragonForce, I wouldn't make that assumption.

https://www.reuters.com/business/retail-consumer/ms-slow-recovery-cyberattack-puts-it-risk-lasting-damage-2025-05-19/

There's also a line in the article from an cyber industry person saying "if it can happen to M&S, it can happen to anyone" - it's ridiculous and defeatist given Marks and Spencer haven't shared any technical information about how it happened, other than to tell The Sunday Times it was "human error"

The Air Safety version of cyber industry would be a plane crashing into 14 other planes, and industry air safety people going "Gosh, if that can happen to British Airways it could happen to anybody!"

Tomorrow it’s one month since Marks and Spencer started containment, it’s also their financial results day.

Online ordering still down, all recruitment stopped, Palo-Alto VPNs still offline.

I made this point a few weeks ago, but... outsourcing all your IT, Networks, Service Desk (helpdesk) and operational cybersecurity is a temporary cost saving and basically paints a ticking timebomb on the org, IMHO.
M&S say online ordering will be stopped until sometime in July, and it has taken a £300m hit, far higher than analysts had predicted. https://www.bbc.co.uk/news/articles/c93llkg4n51o
M&S cyber-attack disruption to last until July and cost £300m

Customers have been unable to order online for almost a month due to the cyber-attack.

BBC News
@GossiTheDog I must admit to not being particularly enamoured by the overall concept of third party identity security services.
@GossiTheDog how do in register a future "I told you so" without disclosing who it's for? Asking for a friend...
@GossiTheDog I can imagine many business leaders going "oh, it's okay, we don't use TCS, we have another outsourced supplier..."

@GossiTheDog Want to guess how much of my IT leadership career has been focused on building in-house expertise and dialing back the presence of MSPs?

Enough that it's made for a pretty good living...

@GossiTheDog Its rather hypocritical that the Coop would be wading into the outsourcing game
@GossiTheDog Every company is a computer company now

@GossiTheDog when I got my business degree, one of my management profs said that the instant you outsource, you give up control. To the service provider, you move from income to liability on the balance sheet because you now are costing them money, and to eke out any profit they need to cut costs related to providing service to you.

Thus you get all this *gestures vaguely*

@GossiTheDog I'm guessing it's a liability thing? I.e. they can recover a significant chunk of the losses from TCS contractually?

@GossiTheDog "paints a ticking timebomb" - bit of a mixed metaphor, could be "paints a target" or "plants a ticking timebomb" ? 😎

The shortsightedness of outsourcing everything is undeniable though!

@GossiTheDog I would buy one of those action that goes up when it goes done ! Would that be considered 'outsider trading' ?
@GossiTheDog They are still within the contract sla period for a response from the outsourced help desk. Sorry. But the contract sla only covers time to first response to the ticket not when the ticket will be done. Also orders for that many new machines exceeds the average % of requests and so is subject to delays from the equipment supplier

@GossiTheDog I would love for IT to publish accident investigation reports in the same way as aviation.

No blame, no liability, no finger pointing, just lessons for everyone to learn and hopefully avoid the same.

(I know there have been some like the Irish Health Service that were excellent.)

@GossiTheDog The “human error” is the humans in the boardroom and the C-suite not putting sufficient effort or resources into securing their networks.

@GossiTheDog yeah, breach the "low cost" IT outsourcer - whose staff feel little connection or affinity with the corporate customer - and *bingo* you hit the jackpot 🎰 with multiple corporate accounts to ransom.

How's that "low cost IT outsourcing" looking now?

@matthewskelton @GossiTheDog Of course, make it clear how little you care about your in-house support staff and the same problem arises.
@RogerBW @GossiTheDog oh for sure. It's always seemed weird to me that orgs treat IT admin as low skilled. They are the info front line - you need some of the best people in that position or you're fscked.
@matthewskelton @GossiTheDog Chickens. Home. Roost. Or something like that 🐓🏠💥
@GossiTheDog One of the big MSP's from India was adamant:
1. Personnel is not allowed to store passwords.
2. Must use unique passwords for every service.
3. Passwords must rotate every X days.
4. Only sanctioned apps are allowed.
5. No password manager is sanctioned or installed by default.

@GossiTheDog I recall it was a "TCS_80_ip" list in Entra Id marked "Trusted"/"MFA exempt" that contained 80 ranges from /15 to /24...

Yet happily pivoting through 3 layer deep RDP to get to a system to manage 

@GossiTheDog I wonder would there be a drop in threat activity if someone made sure all teenagers are in school/training/work/at a youthclub (if there were any).
@GossiTheDog Something, something, can't outsource risk.
@GossiTheDog
Argh, flashbacks to trying to convince directors that outsourcing IT is bad. Very bad.
@sunflowerinrain @GossiTheDog I've seen a full remote tech company where IT was outsourced, and the contract was managed by HR. Like if the CEO didn't trust the engineers (building the product).
@GossiTheDog paywall 😭
RemovePaywall | Free online paywall remover

Remove Paywall, free online paywall remover. Get access to articles without having to pay or login. Works on Bloomberg and hundreds more.

@GossiTheDog No direct contact with DragonForce? I'm sure they'll drag them Through The Fire And The Flames over this one.

@GossiTheDog “we aren’t a computer company, so off to India / China / Vietnam / Philippines / etc for all this non-core-business shit”

“Why company not run without computers? Who did this?”

@GossiTheDog As a Co-op member, I'm very happy to see them getting back to business
@GossiTheDog
This was yesterday evening in my local co-op store (close to central Manchester.) Still lots of empty spaces on the shelves.
@GossiTheDog And I was expecting the first vacancy to be CTO 😆
@GossiTheDog Those who know this is going to become more and more.

@GossiTheDog

The quote

> They torched shareholder value

made me laugh

they have no idea what the Coop is

@GossiTheDog
Confident on containment within 2 weeks?
@GossiTheDog I will henceforth not do anything differntly and therefore continue not to be a Harrods customer.
@GossiTheDog exactly... They should be talking to the butler.