WH Smith, the UK retailor, has been the target of a cyber-attack in which hackers have breached company data.
Current and former employee information has been accessed as part of the cyber ‘incident’.
However, the company stressed that its trading activities have not been affected by the hack, and its website, customer accounts, and customer databases have not been impacted.
The company has already investigated the incident and reported it to the relevant authorities.
WH Smith said: “Upon becoming aware of the incident, we immediately launched an investigation, engaged specialist support services and implemented our incident response plans, which included notifying the relevant authorities.
“WH Smith takes the issue of cyber security extremely seriously and investigations into the incident are ongoing.
“We are notifying all affected colleagues and have put measures in place to support them.”
Recommended
- UK Seeks to Build Stronger Economic and Tech Ties in Indo-Pacific
- YouTube Accused of Breaching ICO Children’s Code
- Revealed: Bank Customers Facing the Most Fraud
So far, the company has not shared any details on what type of employee data was hacked or how the data was accessed.
Javvad Malik, lead security awareness advocate at KnowBe4 commented: “While details of the hack are limited at present, it does show how criminals are increasingly attacking UK organisations across a variety of industries. Solidifying the fact that no vertical or size or organisation is safe from attacks.
“The most common ways criminals will breach organisations by way of social engineering attacks such as phishing, or by exploiting poor passwords, or through exploiting unpatched software. So it’s important that organisations work on addressing the common root causes of attacks, and ensure they have a layered and defensible security strategy in place.”
Last year saw a wave of cyber-attacks facing UK retailers and organisations, and this year a major cyber attack affecting Royal Mail services for months rattled the country’s postal service.
JD Sports also suffered a major cyber-attack this year which affected the data of millions of customers.
Guy Golan, CEO and co-founder of cyber security firm Performanta, said: “Major brands such as WH Smith should assume they will be breached by cyber-attacks and have an appropriate plan in place to respond with. Previously, the common consensus was that if you invest in cybersecurity, you’re safe. But now it’s question of when an attack will occur, rather than if, and how ready household name brands are for that scenario.”
Erfan Shadabi, cybersecurity expert at comforte AG said: “Retailers are a prime target for cybercriminals due to the volume of sensitive information that they store and handle, making them vulnerable to various types of cyberattacks, including phishing, malware, and ransomware. Retailers and ecommerce organizations must absolutely assume that their environment is currently under attack and protect this sensitive data accordingly.
“Businesses in these sectors need to apply data-centric protection to any sensitive data within their ecosystem (PII, financial, and transactional) as soon as it enters the environment and keep it protected even as employees work with that data.”
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





