Every country has its own version of Marks & Spencer—a store that defines a generation’s shopping experience. I remember going to the Brazilian equivalent with my parents. It felt like an event—we used to take the better part of the day roaming through departments, trying new clothes, having a coffee…for many of us, those stores weren’t just retail spaces; they were cultural landmarks. And while those memories are rooted in the physical experience, today’s retailers are trying to recreate that magic through technology.
Marks & Spencer is more than just a household name in the UK—it’s a cornerstone of British retail. With a history dating back to 1884, M&S has evolved from a penny bazaar into a multinational retailer with a broad footprint in clothing, food, and home goods. In recent years, the modern world has pushed them into its digital transformation. Online shopping, mobile apps, contactless payments, store totems—these are no longer optional, but essential.
In today’s hybrid retail environment, companies like M&S sit at the intersection of tradition and technology. Their customer experience relies as much on seamless tech as it does on trust. When that trust is broken, even briefly, the ripple effects can be enormous.
In my experience, this isn’t unusual. What makes insider threats so dangerous is how invisible they are—until they’re not. The story is a sharp reminder: your biggest risk may already have access.
The Attack: Sophistication Meets Simplicity
Over the Easter holiday in April 2025, M&S customers began reporting glitches with online services: Click & Collect wasn’t working, contactless payments failed, and digital orders stalled. By April 25, the company suspended all online orders in its clothing and home departments. Customer frustration quickly grew, and the story caught national headlines.
At first glance, the disruption seemed like a technical hiccup. But behind the scenes, a highly coordinated cyberattack was unfolding. The attackers didn’t brute-force a firewall or exploit a zero-day vulnerability. Instead, they targeted Tata Consultancy Services (TCS), M&S’s third-party IT provider, using old-school social engineering.
According to public reports, cybercriminals impersonated legitimate M&S employees, convincing IT help desk agents to reset internal passwords. For a detailed account of the breach, see Reuters’ coverage. With access granted, they deployed ransomware, stole customer data, and encrypted key systems. DragonForce—a ransomware-as-a-service group—was quickly identified, with suspected involvement from the teenage hacking group Scattered Spider.
This method of attack is neither novel nor rare. But it remains devastatingly effective. When attackers can manipulate your people, they don’t need to outsmart your technology.

The Human Risk Factor: A Breach Built on Trust
What makes this incident especially concerning isn’t just the breach’s size—it’s how it happened. In my view, this was a masterclass in human manipulation.
Attackers didn’t need to exploit code. They simply understood people: how IT staff might respond under pressure, how identity checks could be sidestepped, how protocol gaps could be weaponized. When someone calls sounding urgent and authoritative, it’s human nature to want to help.
The real weak point? The human layer. M&S’s digital walls stood tall, but the front door was wide open. Without strong identity verification protocols or better-trained personnel, attackers bypassed even the best tools. Even seasoned IT professionals can fall prey to tactics designed to disorient and deceive.
And this isn’t unique to M&S. It’s an industry-wide issue. As the BBC reported, attacks like these are increasing in frequency and impact, often relying on social engineering over technical exploits. Social engineering is on the rise precisely because it works—and because so many organizations have overlooked human risk as a core part of their cyber defense.
Download: Traditional Security Awareness vs Human Risk Management
Traditional Security Awareness doesn’t do the job anymore. Download our guide to see how HRM upgrades your program and takes Security Awareness into your larger cybersecurity goals.

Ripple Effects in Retail: Money, Media, and Regulation
The financial fallout has been brutal. M&S estimates up to £300 million in lost operating profit. Online sales halted. Market cap dropped by over £1 billion. Weekly losses? As much as £40 million. Shareholders took notice, and so did regulators.
Reputation-wise, it’s a hit that will sting for months. While M&S confirmed no passwords or payment data were compromised, stolen personal info still erodes customer trust. And regulators are watching closely. Breach notifications, compliance reviews, and potential fines are all on the table.
There’s also the long-term brand damage to consider. Retail is built on convenience and loyalty. When systems fail, or worse, when customer data is stolen, that loyalty is tested. In our experience, recovering brand trust often takes longer—and costs more—than fixing the technical damage.

Why Human Risk Management (HRM) Matters More Than Ever
Here at Right-Hand, we’ve long believed cybersecurity isn’t just a tech problem—it’s a people problem. The M&S breach illustrates that perfectly.
Human Risk Management focuses on the behaviors and processes that leave organizations exposed. Phishing clicks, credential misuse, help desk manipulation—these aren’t rare events. They’re daily risks. And they require daily defenses.
In our view, effective HRM means meeting people where they work. That includes nudges embedded into Slack, Microsoft Teams, and even email—real-time reminders that make secure behavior second nature. It also means running simulations that mirror real-world attacks: impersonation drills, spear phishing, and social engineering tactics.
Cultural reinforcement is key. It’s one thing to know the rulebook; it’s another to live by it. And that’s where HRM shines: reinforcing awareness through practice, not just policy.
Our HRM Platform: Enabling a Stronger Human Layer
At Right-Hand, we’ve designed our Human Risk Management Platform to address the exact types of behavioral vulnerabilities this breach revealed. Rather than relying on theoretical defenses or one-off training sessions, our platform operationalizes HRM in real time.
Key capabilities include:
Real-time security nudges delivered via Slack, Teams, and email
Just-in-time micro-training for employees facing social engineering scenarios
Risk-based user profiling and continuous behavioral analysis
Simulation tools for phishing, impersonation, and procedural testing
Integration with your existing IT and security stack for seamless visibility
Our goal is simple: help organizations build a culture where secure behavior becomes second nature—without slowing business down. Whether it’s reinforcing identity checks at the help desk or alerting analysts when risky behavior surfaces, our platform empowers teams to stay one step ahead.
HRM isn’t about fear—it’s about readiness, context, and habit. And that’s exactly what our solution is built to support.
Conclusion: From Awareness to Action
The M&S breach was avoidable. That’s the hard truth. A few stronger processes, better-trained teams, or timely red flags—and the outcome might have been very different.
But the silver lining? Every incident like this becomes a lesson. And for those of us in cybersecurity, it’s a powerful reminder: Our strongest line of defense isn’t software. It’s people.
Let’s empower them. Let’s build smarter defenses that include human behavior, not just firewalls. Let’s treat help desk agents and IT teams as frontline defenders—because that’s what they are.



