Site navigation

Google Warns US Retailers Could Be Next Following UK Cyber-attacks

Elizabeth Greenberg

,

retail cyber-attacks
“US retailers should take note,” said Google cybersecurity analyse John Hultquist.

The same hacking group responsible for targeting M&S and other UK retailers could now be targeting US companies, Google warns.

The tech giant warned in a statement on Wednesday that the Scattered Spider hacking group reportedly behind the M&S hack as well as the Co-op and Harrods attacks, may now target US retailers.

“US retailers should take note. These actors are aggressive, creative, and particularly effective at circumventing mature security programmes,” said Google cybersecurity analyse John Hultquist.

Hultquist warned that Scattered Spider typically focuses on a specific sector at a time, and will likely to continue targeting the retail sector.

“The actor, which has reportedly targeted retail in the UK following a long hiatus, has a history of focusing their efforts on a single sector at a time, and we anticipate they will continue to target the sector in the near term,” he warned.

The loosely interconnected network Scattered Spider involves hackers with a range of sophistication skills – their attack on M&S has left a lasting impact on the retailer, which still has their online operations interrupted.

The major UK retailer recently revealed that customer data was accessed in the cyber-attack, but this data did not include payment or password details. Still, the company is requiring users to reset their passwords.


Recommended reading


Scattered Spider was reportedly also behind the major ransomware attacks on MGM and Caesars Entertainment, casino titans based in the US, two years ago, which prompted warnings from US officials about the group’s social engineering tactics.

It appears that the group may have an international base, as the UK arrested a teenager for his potential role in the attack on MGM. Other arrestees for the attack and potential involvement in the group were US citizens.

Following this, Scattered Spider was also credited with high-profile attacks against several digital platforms, including Reddit, Riot Games, Mailchimp, Coinbase, Twilio, and LastPass.

While the warning is pertinent, and echoes the ‘wakeup call’ voiced by cybersecurity officials in the UK, it remains to be seen how retailers across the globe will react.

Don’t Miss Scotland’s Biggest Tech Event!

Join us at DIGIT Expo West on 5th June at the SEC Glasgow. Get leading industry insights across AI, Cyber Security, and Data, and grow your network at Scotland’s largest gathering of tech leaders – with 1500+ attendees, 50+ speakers, and 50+ exhibitors.

Register your FREE place now at www.digitexpowest.com

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data