Empty store shelves, bricked online shopping platforms and stolen customer data – cyber-attacks are bringing a reckoning to some of the UK’s largest retail firms.
In what was described as a “wake-up call” by Pat McFadden, the cyber-attacks have left the retail world squirming in discomfort, as Google warns US retail titans to “take note” and stay on their toes.
The tech giant has stated that it’s likely that Scattered Spider – the loosely connected consortium of hackers reportedly responsible for the attacks – will hit again, seeking not only to further compound the misery of the UK’s retail sector, but casting its net wider to other nations.
But why did the UK see such a succession of cyber-attacks against some of the most well-known retail brands operating in the country?
If these top brands are in danger of such disastrous breaches, what does that mean for the rest of the sector?
To shed light on these recent attacks and what they can teach us about the overall threat landscape, DIGIT spoke to Cody Barrow, chief executive officer of EclecticIQ and former senior intelligence officer for the Defense Intelligence Agency in the U.S., to delve into the targeting of the retail sector, AI’s perhaps unsurprising role in helping to accommodate this, and how governments, companies – and the public – can get used to this new normal in cyber.
Why Retail?
When Barrow explains the reasons for targeting retail, it becomes obvious that the sector could be a goldmine for cyber-criminals.
“Retail platforms have online order systems that have no tolerance for outages,” Barrow explained. A simple lag time in ordering can push consumers to competitors – outages equal huge financial loss. This means they will do anything to keep their systems on – which could mean continued exposure to breaches, or paying off a ransom speedily.
We’ve seen this play out in the recent attacks – M&S did not shut down all their systems and faced a customer data breach. Co-op, on the other hand, was praised for shutting down their own systems, taking a more long-term mitigation approach despite being aware of the short-term damage.
Both stores, however, faced empty shelves and ongoing issues, though Co-op’s online services were able to bounce back faster than those of M&S.
“Retail giants have huge, messy attack surfaces,” Barrow further explained. Juggling multiple vendors, thousands if not millions of logins, backend and front end services to manage the live availability of products and services, is a demanding front to master.
“I think that the attackers also consider that a retailer may have a slimmer security budget,” Barrow said as well.
“So when you factor in the need to have maximum service availability, the wide attack service with a lot of complexity and a range of tools, and that their security budgets may not be as sophisticated or as large as a big financial institution, retailers become a very juicy target.”
Further, with these potentially less sophisticated, less expensive security postures, cyber-criminals are able to target retailers without going to their most specialist tools.
“For the ransomware that they have deployed,” in the case of Scattered Spider, “they didn’t have to go through the same sophisticated tool building for their attack procedures. They employed, what I would say are, low skill, high impact techniques.”
This is what makes retail truly so appealing to bad actors, especially as traditional cyber-crime tactics become more accessible and attack vectors expand.
The UK: A Cyber Leader In An Industry Falling Behind
The UK could be considered a global cyber leader, with pioneering efforts by the National Cyber Security Centre and other institutions being parts of major stings against cyber gangs and in fighting fraud.
Global leader or not, the UK still has a “need to adapt,” according to Barrow.
Given the UK’s levels of supposed prestige within the global cybersecurity lexicon and relative ease in which these devastating attacks were conducted, what does that say about the overall threat landscape?
“If the UK is a leader, then probably no one is really ready for the acceleration in the cyber threat landscape,” Barrow said.
AI is a major culprit in this “acceleration”, lowering the barrier to entry for prospective threat actors, but also the increasing complexity of the attack surface all along the supply chain, as well as the added nation state interest in exploiting these factors.
Global uncertainty, on top of all of this, adds political and financial tension, leading more to turn to cyber-crime and cyber espionage.
Further, the nature of cyber defence is ‘defence’, which will always be trailing offense in terms of innovation. While there are proactive measures, at the forefront of cyber, it is largely reactionary.
“We’re not looking at what might evolve, which means that all we have is a historical record,” Barrow said, “So that means we’re always going to be behind.”
And with AI, we are already seeing these threats evolve, and defences flounder. As deepfakes become more advanced and prevalent, social engineering techniques will only improve. Face scanning, voice recognition, and biometric identification may not be enough in the wake of AI that can effectively mimic these.
Recommended reading
- Google Warns US Retailers Could Be Next Following UK Cyber-attacks
- M&S Confirms Customer Data Breach After Cyber-attack
- Cyber-attacks A “Wake-up Call” to Retail Sector
So what can be done?
Besides basic cyber hygiene, Barrow thinks the government, the public, and organisations need to change their perception.
“It’s been accelerating for years, if not decades,” Barrow said about the threat. “It is becoming the new normal.”
For the public, this means understanding that cybersecurity breaches of major companies happen, so taking steps to be resilient – protecting your identity, your assets, your personal data – is vital.
For organisations, going beyond cyber hygiene is now more important. Barrow suggests an “assume breach” approach.
This is evermore important as organisations are more and more reliant on third-party vendors which, alongside supply chain risks, continue to contribute to major cyber breaches and incidents.
“I think third parties are the core part of your attack surface,” Barrow said.
It’s a sentiment backed up with plenty of data. According to Gartner, more than 60% of cyber incidents now involve a third party, making it one of the biggest blind spots in enterprise activity.
Other features of ensuring an “assume breach” model is successful include a lot of basic cyber hygiene, as well as consistent auditing and testing, attacking your own systems and ensuring advanced identity authentication checks.
However, as mentioned, AI is complicating a lot of these features. AI’s deepfake capabilities makes certain identification methods less secure – even Co-Op’s protocol of making people keep their cameras on to ensure their identity may not work in a world of accurate deepfake technology.
“AI in some ways is going to make the friction even worse,” when it comes to account access for customers and employees.
But this can be mitigated to ensure safety.
Similarly, CISOs are consistently facing backlash when they approach boards asking for increased security budgets in a landscape that keeps shovelling funds to AI initiatives.
“Security leaders need to frame security as revenue protection,” Barrow suggested, rather than the “expense centre.”
“Security is an essential part of protecting their operations and their revenue – it can be kind of an irritation like a fire alarm, but it’s something that’s necessary to prevent your building from burning down.”
Why Do These Retail Attacks Matter?
In the grand scheme of things, these attacks on the UK retail sector were concentrated and seemed to revolve around one adversary group. What do they mean for the wider cybersecurity landscape when global conflict has led to a rise in nation-state adversaries and cyber-attacks on critical infrastructure?
“This is a fundamental national security challenge,” Barrow explained.
“This is not only because these attackers can go after your economic levers,” he said. “It’s also because these attacks are proving grounds, and are places where nation states can observe what’s happening.”
Adversaries can learn from these attacks, they can find vulnerabilities and see which exploitation tactics work.
“Its a very good proving ground for observers,” Barrow said.
While the economic impact of these attacks are more obvious, Barrow wants governments to consider these cases a national security threat.
The case also does show that AI is manifesting in cyber differently than often projected. Scattered Spider appeared to not have relied on AI for its social engineering tactics.
“People are talking about AI, but what we still don’t see enough is that it’s the human level that is primarily exploitable,” Barrow noted.
“It’s chipping away at what we think is the safety of the ‘human in the loop.’
“AI is primed to exploit human psychology and not just technical vulnerabilities,” he said, pointing that these AI phishing emails, phone calls, and other tactics are still aiming at a human target to penetrate a system.
Understanding how AI can be integrated into systems to protect humans from malicious AI can be key in negating these advancing threats.





