Two Years Later, the Same Phone Call
Anatomy of an Identity Incident — M&S and Co-op, 2025. The exact playbook that took down MGM in 2023, run again, against an outsourced service desk, for a few hundred million pounds.
Forensic write-ups of public identity breaches, strictly at the identity layer. No vendor is the villain — the point is the structural class of failure, not the logo on it.
The 60-second version
In the spring of 2025, two of Britain's best-known retailers — Marks & Spencer and the Co-op — were hit in what investigators treated as a single combined event, with Harrods targeted alongside. The estimated damage ran into the hundreds of millions of pounds. M&S stopped taking online clothing orders for 46 days.
The entry technique was not novel. It was not even new. Attackers impersonated an employee and called the IT service desk — at M&S, a desk run by a third party — and got a password reset. M&S's own chairman said so publicly. If that sounds familiar, it should: it is, almost beat for beat, the MGM and Caesars playbook from 2023. Same threat crew profile, same social-engineered help-desk reset, same outcome. Two years on, the door was still unlocked, and this time someone had outsourced the lock.
The identity timeline
Only identity-relevant events.
- The impersonation call — An attacker contacts the IT service desk posing as a specific employee, with enough detail to be convincing.
- The reset — The desk performs a password reset for the impersonated account. At M&S this desk was operated by a third-party provider; the verification that should have caught the impersonation did not.
- The foothold — The attacker is now an authenticated employee, with no exploit involved.
- The escalation — From that foothold the intrusion spreads through the environment, consistent with the actor reaching directory-level control.
- The payload — Systems are encrypted and data exfiltrated in a double-extortion ransomware scheme.
- April–June 2025 — The disruption plays out publicly; M&S halts online orders and resumes them after a 46-day gap. Damage estimates reach into the hundreds of millions of pounds, and arrests follow.
The pivot point
The pivot is identical to the one I wrote about for MGM, which is the entire point of writing about it again: a human at a service desk reset a credential for someone they had not actually verified.
I won't repeat the full mechanics — recovery flows exist to issue access to people who can't currently prove who they are, which makes them the one door designed to open for someone failing the normal checks. What's worth adding here is the new wrinkle, because 2025 sharpened it: at M&S the service desk was run by a third party. So the verification step that the whole breach turned on wasn't even performed inside the company. It was a process, executed by another company's staff, measured presumably on resolution speed, standing upstream of the retailer's entire identity estate.
That is the pivot made structural. In 2023 the lesson was "your help desk is your identity control plane." In 2025 the lesson is "and you may have handed that control plane to a vendor without hardening the one decision that matters." The reset didn't fail because the technology was weak. It failed because the human verification was someone else's job, loosely specified, and nobody owned it end to end.
What would have caught it
Naming controls, not products — and yes, they are the same controls as two years ago, which is itself the finding.
Strong identity verification at the service desk, contractually enforced when it's outsourced. The reset path needs proofing a phone call can't fake — video against a known reference, out-of-band manager approval, a code through a separately trusted channel. When a third party runs the desk, that standard has to be a written, audited requirement, not an assumption.
A separate, harder flow for privileged and sensitive accounts. Resetting a shop-floor login and resetting something that can reach the directory cannot be the same five-minute procedure.
Holds and alerts on resets. A reset on a sensitive account should page someone and carry a short delay, so a fraudulent one can be caught before it's used.
Phishing-resistant factors that resist casual re-issuance. Hardware-bound credentials make "just send me a new code" a heavier, more verifiable act.
Tiered admin and least privilege, so one recovered account can't walk to domain control.
The last mile
I am repeating myself, and that is the message. The MGM write-up argued that account recovery is the purest example of the identity last mile: a process living across people, scripts, and third parties, owned by no product and too often by no one. The M&S and Co-op incidents are that same argument, re-run two years later, at national scale, with the outsourcing dialed up.
Here is what should be uncomfortable about that. Between 2023 and 2025, every vendor in this space shipped more identity features, more conditional access, more phishing-resistant options. None of it closed the gap, because the gap was never in the product. It was in the operational discipline of verifying a human at a help desk — and that discipline does not arrive in a release note. If anything, the trend went the wrong way: outsourcing the service desk moved the critical verification step further from anyone with the context or incentive to harden it. The mile didn't just stay ownerless; it got an extra contractual seam running right through the middle.
This is why I keep insisting the last mile is an ownership problem, not a tooling one. A control that has to be performed correctly by a person, every time, including on a busy outsourced desk at the end of a shift, is exactly the kind of work that needs a continuous owner — someone whose job is to standardize and verify that verification, across the whole estate and across every third party in it. When that owner doesn't exist, you don't get a slightly worse outcome than MGM. You get the same outcome, because it is the same unowned mile, and it is patient.
For defenders
Five things you can check this week.
- If your service desk is outsourced, read the contract for identity-verification standards. If resets don't require strong, phone-proof verification, that's the M&S gap with your name on it.
- Harden the reset flow for privileged accounts into a separate procedure with out-of-band verification and multiple approvers.
- Alert on and delay resets for sensitive accounts, so a fraudulent one has a window to be caught.
- Move privileged and high-value accounts to phishing-resistant factors that are hard to socially re-issue.
- Re-read your last tabletop exercise. If it didn't include "attacker calls the (outsourced) help desk and impersonates an employee," it was missing the most-used technique of the last two years.
Built from public reporting and the parties' own disclosures; sources below.
Sources
- The Hacker News, "Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages" — https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html
- Specops Software, "M&S ransomware hack: Service Desk & Active Directory security lessons" — https://specopssoft.com/blog/marks-spencer-ransomware-active-directory/
- Computer Weekly, "M&S, Co-op attacks a 'Category 2 cyber hurricane', say UK experts" — https://www.computerweekly.com/news/366626336/MS-Co-op-attacks-a-Category-2-cyber-hurricane-say-UK-experts
- The Hacker News, "Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods" — https://thehackernews.com/2025/07/four-arrested-in-440m-cyber-attack-on.html