UK IT Channel News | IT Channel Oxygen
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
Members
Must-Know Distributors
Oxygen 250
No Result
View All Result
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
No Result
View All Result
UK IT Channel News | IT Channel Oxygen
No Result
View All Result
Home Cybersecurity

14 most significant cyber-attacks of 2025 so far – with a twist…

The twist being that our rundown is based entirely on the views of 12 partner leaders

Oxygen staff by Oxygen staff
30 June 2025
in Cybersecurity, Indepth, News, Partner
14 most significant cyber-attacks of 2025 so far – with a twist…
Share on LinkedinShare on Twitter

Marks & Spencer

When: April

What happened?

This wasn’t just a cyber-attack… it was an M&S cyber-attack that left management faces as bright pink as its Percy Pig gums.

The retail giant is still reeling from the effects of a “highly sophisticated and targeted” attack in April, which has been linked to notorious English-speaking hacker group Scattered Spider. The hackers reportedly tricked IT helpdesk workers to access company systems.

Although M&S has won praise elsewhere in this article for how it handled the fall-out, the incident will dent its profits by an estimated £300m, with online disruption expected to continue into July.

Who nominated it, and why?

Nicola Saner, Chorus IT
Nicola Saner, Chorus IT

Every single one of our 12 panellists had it in their top 5 (if you include the four that rolled it up into the wider Scattered Spider-related retail attacks), with the majority putting it top of the pile.

“The M&S attack is without doubt the most significant for me this year,” Computacenter’s Dr Colin Williams said.

“The company is held dear in the hearts of UK citizens which made the attack feel more personal than others. It also elevated the impact of social engineering, showcasing the effectiveness of identity manipulation tactics in the hands of skilled cyber attackers. The high financial impact and remediation cost estimates published by M&S and how challenging recovery has proved is a wake-up call for all organisations regardless of sector.”

“This one catches the eye for a few reasons, primarily the sheer scale of impact and apparent financial damage to the business,” Chorus MD Nicola Saner added.

Channel takeaway:

Chorus’ Saner said the nature of how the cyber-criminals accessed M&S’ systems could prompt other companies to tighten up their security.

“It’s been suggested there is a potential mix of third-party helpdesk, plus a lack of end-user verification when staff call the helpdesk,” she said.

“End user verification is understood but not widely deployed in our experience and we expect to see an uptake in this requirement going forward.”

Performanta CEO Guy Golan said the M&S attack offers an opportunity for cyber providers to discuss three things with their clients, namely security by design, change of CISOs’ reporting lines, and seeing security through a “bean counting mentality” rather than an investment.

Page 15 of 15
Prev1...1415
Tags: BridewellChorus ITComputacenterCybaVerseCyberfortCyXcelfeaturedmemberNGSPerformantaQuorum CyberRed HelixSapphireSeconTrending
Previous Post

A new ‘global standard’ for ISVs seeking Microsoft Marketplace success?

Next Post

‘A whirlwind’ – Wiz ‘well on way’ to 100% channel

Related Posts

Bechtle CEO, Dr Thomas Olemotz
Business

Bechtle posts ‘strong’ UK growth as CEO says ‘difficult period’ behind it

14 November 2025
Ken Scaturro, CEO of Yorktel-Kinly and Tom Martin, CSO of Yorktel-Kinly
M&A

Yorktel and Kinly collide to create ‘top five’ collaboration MSP

13 November 2025
Dave Stevinson and Charlie Heald, QBS Software
Business

‘We want to operate like a large cap company’ – QBS Software CEO on PwC pact

13 November 2025
Graham Charlton, Softcat
Partner

Ten things we’ve learned in ten years of public trading

13 November 2025
AWS - employees at Seattle HQ
Vendor

AWS makes triple tweak to solution partner incentives

12 November 2025
Bytes Technology Group and Softcat dominate £3.7bn public sector VAR market
Public sector

‘Greater value for the nation’ – Crown Commercial Service to get facelift

11 November 2025
Joachim Mason, Cisco
Big Interview

Cisco exec’s message to partners amid big 360 profitability reveal

11 November 2025
Advania Iceland HQ
Careers & Skills

Advania UK ‘positioned for growth’ after headcount trim

11 November 2025
Next Post
Nick Ross, Wiz

‘A whirlwind’ – Wiz ‘well on way’ to 100% channel

Follow Us

IT Channel Oxygen keeps you informed on the UK IT channel and its sustainable transformation. Learn more

  • About
  • Our Team
  • Partner with us
  • Privacy Policy
  • Terms & Conditions
  • News
  • Cookie Policy (UK)

© 2025 IT Channel Oxygen

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Oxygen 250
  • Must-Know Distributors
  • Member area
  • Big Interview
  • Pulsant Zone
  • News
  • Indepth
  • About
  • Partner with us

© 2025 IT Channel Oxygen