Cyberattacks impacting UK retailers are a wake-up call

Cyberattacks impacting UK retailers are a wake-up call

The United Kingdom’s National Cyber Security Centre warned that ongoing cyberattacks impacting multiple UK retail chains should be taken as a “wake-up call.”

Part of the GCHQ British intelligence agency, the NCSC provides support and guidance to private and public sector entities following major cybersecurity incidents to protect the UK’s critical services.

In a statement issued this week, the NCSC also confirmed that it’s working with affected organizations in the retail sector to assess the attacks’ nature and impact.

“The disruption caused by the recent incidents impacting the retail sector are naturally a cause for concern to those businesses affected, their customers and the public,” .

“These incidents should act as a wake-up call to all organisations. I urge leaders to follow the advice on the NCSC website to ensure they have appropriate measures in place to help prevent attacks and respond and recover effectively.”

Since the attacks surfaced, the UK House of Commons’ Business and Trade Committee the CEOs of and to share whether relevant government agencies (including the National Crime Agency and the National Cyber Security Centre) provided support.

Cyberattacks targeting UK retailers

confirmed it was targeted in a cyberattack on May 1st, becoming the third major UK retailer to report cyberattacks over the last two weeks following incidents at the Co-operative Group (Co-op) supermarket chain and British retailer giant .

Harrods told BleepingComputer that threat actors recently attempted to hack into its network, which prompted the luxury department store to restrict internet access to sites. While Harrods didn’t share whether its systems were breached, limiting access to some platforms hints at an active response to the attack.

On Wednesday, Co-op after what they described as attempts to hack into their systems. However, Co-op Chief Digital and Information Officer Rob Elsey said in an internal memo urging employees to be vigilant when using email and Microsoft Teams that VPN access has been disabled, indicating potential containment measures following a security breach.

Last week, Marks & Spencer was also  that caused and impacted its contactless payments and Click & Collect services.

BleepingComputer later confirmed that the with threat actors using tactics associated with , where they deployed the DragonForce ransomware on the company’s network.

Other high-profile attacks linked to Scattered Spider include those on , , , , , , , and .

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.