M&S Cyberattack: A Wake-Up Call for UK Businesses

Lessons from a cyber attack

In the current cybersecurity landscape, many businesses believe that regular vulnerability scans are enough to safeguard their systems. While scans can highlight obvious weaknesses, they fall short of simulating the real world tactics that threat actors use to infiltrate networks, steal data, and disrupt operations. The recent cyberattack on Marks & Spencer (M&S) is a stark reminder of why penetration testing is not just important, it’s essential.

In April 2025, retail giant Marks & Spencer became the target of a sophisticated cyberattack orchestrated by the hacking group Scattered Spider. This wasn’t a simple case of outdated software or unpatched systems; a vulnerability scan alone wouldn’t have prevented it. The attackers had reportedly infiltrated M&S’s systems as early as February, deploying ransomware and exfiltrating sensitive internal data, including credential stores like the NTDS.dit file.

The result?
– Nationwide disruption to online orders, click and collect services, and in-store systems
– Suspension of recruitment and slowdowns in tills and stock delivery
– A £650 million drop in market value
– Damage to brand reputation and customer trust

Despite the severity of the attack, M&S has stated that no customer data was compromised, a testament to some strong security protocols. But the breach still brought daily operations to a halt and exposed how advanced attackers can slip past basic defences.

Why Vulnerability Scans Aren’t Enough
Vulnerability scans are automated tools that identify known issues, outdated software, open ports, or misconfigured firewalls. They’re essential for routine maintenance but limited in scope. They don’t think like hackers. They don’t test chained exploits or look for logic flaws that aren’t documented. And most importantly, they can’t tell you how deep an attacker could go if they got inside. This is where penetration testing comes in.

The Case for Penetration Testing
Pen testing is the human-led, adversary simulated approach to cybersecurity. A skilled tester mimics a real attacker’s mindset, trying to:
– Gain unauthorised access through social engineering or phishing
– Escalate privileges from low level user accounts
– Move laterally within the network
– Exfiltrate sensitive data without being detected

In M&S’s case, a thorough penetration test could have helped identify:
– Privilege escalation paths to Active Directory credentials
– Lateral movement routes that ransomware later exploited
– Gaps in detection and response processes

Pen testing doesn’t replace vulnerability scans it complements them. Where scans show what’s broken, pen tests reveal how an attacker might actually break in.
Harvey Ellams, Digital Safety’s Security Architect, highlights the importance of senior management understanding cybersecurity and the quality of testing in place; there should be evidence that they actually compromised the system, and not a glorified vulnerability scan written with lots of boilerplate text.

A Call to Action for UK Businesses
With UK retailers and service providers increasingly under threat, it’s no longer a question of if you’ll be targeted, but when. Penetration testing helps you move from reactive to proactive. It reveals the weak spots no automated scan will catch and helps your security team prepare for the real thing, before a threat actor forces you to.

Don’t wait for a breach to expose your gaps. Invest in pen testing now.
For more information or a confidential chat, contact info@ds-cic.com