UK Retail Under Siege: Understanding and Defending Against the Latest Cyber Attacks
- News

[Author: Luke Bullimore, Senior SOC Analyst at KHIPU Networks]
The past few weeks have witnessed a concerning wave of sophisticated cyberattacks targeting prominent UK retailers, including Marks & Spencer (M&S), the Co-operative Group (Co-op), and Harrods. These incidents have moved beyond mere disruption, actively compromising systems and underscoring critical vulnerabilities in the retail sector’s cybersecurity defenses. This post delves into the specifics of these attacks, identifies the likely threat actor, highlights key Indicators of Compromise (IOCs), and provides actionable recommendations to help your organisation strengthen its resilience.
Recent Retail Cyber Attack Breakdown:
-
Marks & Spencer (M&S): Ransomware Attack Exploits Active Directory // M&S fell victim to a significant ransomware attack attributed to the notorious hacking group Scattered Spider (UNC3944). The attackers’ tactics involved the exfiltration of the
NTDS.ditfile, which houses critical Active Directory credentials. This allowed for seamless lateral movement across the network, culminating in the deployment of DragonForce ransomware. The impact was widespread, disrupting online services, contactless payments, and even recruitment systems.Learn More: [https://specopssoft.com/blog/marks-spencer-ransomware-active-directory/]
Key Takeaway: The compromise of Active Directory remains a potent attack vector, granting attackers deep access and control.
-
Co-operative Group (Co-op): Thwarted Intrusion Highlights Sector Vulnerability // The Co-op detected unauthorised access attempts early enough to proactively shut down specific IT systems, including back-office and call centre operations. While their retail stores continued to operate, this incident serves as a stark reminder of the constant threat faced by the retail sector and the potential for widespread disruption.
Key Takeaway: Early detection and swift response are crucial in mitigating the impact of cyber intrusions.
-
Harrods: Targeted Attempt Underscores High-Profile Retail Risk // Luxury retailer Harrods experienced attempts to breach its internal systems, leading to the precautionary restriction of internet access across its sites. While no customer data compromise has been reported in this instance, the attack highlights the increasing focus of cybercriminals on high-profile retail targets.
Source: [https://www.thetimes.com/article/harrods-cyberattack-marks-and-spencer-coop-mj7vjkdkv]
Key Takeaway: Even organisations with significant security resources are attractive targets for persistent threat actors.
Understanding the Threat Actor: Scattered Spider (UNC3944)
Scattered Spider, also tracked as UNC3944, is a sophisticated cybercriminal group known for its effective use of social engineering techniques. Their modus operandi often includes:
- Credential Theft: Targeting and exfiltrating Active Directory databases (
NTDS.dit) to obtain valuable password hashes. - Lateral Movement: Utilising compromised legitimate credentials to navigate victim networks stealthily and gain further access.
- Ransomware Deployment: Frequently deploying ransomware, as seen with the DragonForce strain in the M&S attack, to encrypt critical systems and demand ransom payments.
This group has a history of targeting various sectors, including hospitality and technology, demonstrating a versatile and persistent threat.
Further Reading: [https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/]
Actionable Indicators of Compromise (IOCs)
Domains Associated with Recent Attack Campaigns (Blacklist Immediately):
- sytemstern[.]net
- xn--gryscale-ox0d[.]com
- iyft[.]net
- bbtplus[.]com
- squarespacehr[.]com
- mytsl[.]net
- gemini-sso[.]com
- prntsrc[.]net
- freshworks-hr[.]com
- klaviyo-hr[.]com
- login.freshworks-hr[.]com
- login.hr-intercom[.]com
- activecampiagn[.]net
- acwa-apple[.]com
- birdsso[.]com
- okta-ziffdavis[.]com
- pfchangs-support[.]com
- x-sso[.]com
- okta-onsolve[.]com
- okta-ripple[.]com
- dashboard-iterable[.]com
- paxos-my-salesforce[.]com
- corp-azure[.]com
- hr-myccmortgage[.]com
- hr-synovus[.]com
- 7-eleven-hr[.]com
- bell-hr[.]com
- cts-comcast[.]com
- citrix-okta[.]com
Newly Registered Domains Mimicking Legitimate Services (Monitor Closely):
Threat actors are also actively registering domains designed to deceive users and bypass security controls. Be vigilant for domains such as:
<targeted_company>-cdn.com<targeted_company>-sso.com<targeted_company>-servicedesk.com<targeted_company>-okta.com
Proactive Recommendations to Strengthen Your Defences
To effectively mitigate the risk of falling victim to similar cyber threats, KHIPU strongly advises implementing the following critical security measures:
- Active Directory Security: Implement rigorous auditing and continuous monitoring of your Active Directory environment for any unusual or suspicious activity. Enforce tiered administrative access models and strictly adhere to the principle of least privilege.
- Robust Credential Protection: Deploy and actively manage tools like Microsoft’s Local Administrator Password Solution (LAPS) to secure local administrator passwords effectively.
- Universal Multi-Factor Authentication (MFA): Mandate MFA across all user accounts, with a particular focus on remote access points and administrative functions.
- Advanced Endpoint Detection and Response (EDR): Implement comprehensive EDR solutions to provide real-time detection, analysis, and automated response to malicious activities on your endpoints.
- Strategic Network Segmentation: Architect your network with robust segmentation to contain potential security breaches and significantly limit the ability of attackers to move laterally within your infrastructure.
- Reliable and Regular Backups: Maintain frequent, offline backups of all critical systems and data. Ensure these backups are isolated and readily available to facilitate swift recovery in the event of a successful ransomware attack.
- Comprehensive User Awareness Training: Conduct regular and engaging training sessions for all employees to educate them about the ever-evolving landscape of phishing tactics, social engineering techniques, and other common attack vectors.
- Well-Defined Incident Response Planning: Develop, regularly review, and rigorously test your organisation’s Incident Response Plans (IRPs) to ensure a state of preparedness for effectively managing and recovering from potential cyber incidents.
How KHIPU Empowers Your Cybersecurity Resilience
KHIPU offers a comprehensive suite of services specifically designed to bolster your organisation’s cybersecurity posture and mitigate the risks highlighted in these recent attacks:
Conclusion
The recent cyber attacks on UK retailers serve as a critical wake-up call for the entire sector. By understanding the tactics of threat actors like Scattered Spider, staying vigilant for emerging Indicators of Compromise, and implementing proactive security measures, organizations can significantly strengthen their defenses. KHIPU is committed to providing the expertise and services necessary to navigate this evolving threat landscape and build a more secure future for the retail industry.
Contact KHIPU
Contact KHIPU today to learn how our tailored cybersecurity solutions can help protect your organisation from sophisticated cyber threats.