UK IT Channel News | IT Channel Oxygen
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
Members
Must-Know Distributors
Oxygen 250
No Result
View All Result
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
No Result
View All Result
UK IT Channel News | IT Channel Oxygen
No Result
View All Result
Home Cybersecurity

14 most significant cyber-attacks of 2025 so far – with a twist…

The twist being that our rundown is based entirely on the views of 12 partner leaders

Oxygen staff by Oxygen staff
30 June 2025
in Cybersecurity, Indepth, News, Partner
14 most significant cyber-attacks of 2025 so far – with a twist…
Share on LinkedinShare on Twitter

Marks & Spencer

When: April

What happened?

This wasn’t just a cyber-attack… it was an M&S cyber-attack that left management faces as bright pink as its Percy Pig gums.

The retail giant is still reeling from the effects of a “highly sophisticated and targeted” attack in April, which has been linked to notorious English-speaking hacker group Scattered Spider. The hackers reportedly tricked IT helpdesk workers to access company systems.

Although M&S has won praise elsewhere in this article for how it handled the fall-out, the incident will dent its profits by an estimated £300m, with online disruption expected to continue into July.

Who nominated it, and why?

Nicola Saner, Chorus IT
Nicola Saner, Chorus IT

Every single one of our 12 panellists had it in their top 5 (if you include the four that rolled it up into the wider Scattered Spider-related retail attacks), with the majority putting it top of the pile.

“The M&S attack is without doubt the most significant for me this year,” Computacenter’s Dr Colin Williams said.

“The company is held dear in the hearts of UK citizens which made the attack feel more personal than others. It also elevated the impact of social engineering, showcasing the effectiveness of identity manipulation tactics in the hands of skilled cyber attackers. The high financial impact and remediation cost estimates published by M&S and how challenging recovery has proved is a wake-up call for all organisations regardless of sector.”

“This one catches the eye for a few reasons, primarily the sheer scale of impact and apparent financial damage to the business,” Chorus MD Nicola Saner added.

Channel takeaway:

Chorus’ Saner said the nature of how the cyber-criminals accessed M&S’ systems could prompt other companies to tighten up their security.

“It’s been suggested there is a potential mix of third-party helpdesk, plus a lack of end-user verification when staff call the helpdesk,” she said.

“End user verification is understood but not widely deployed in our experience and we expect to see an uptake in this requirement going forward.”

Performanta CEO Guy Golan said the M&S attack offers an opportunity for cyber providers to discuss three things with their clients, namely security by design, change of CISOs’ reporting lines, and seeing security through a “bean counting mentality” rather than an investment.

Page 15 of 15
Prev1...1415
Tags: BridewellChorus ITComputacenterCybaVerseCyberfortCyXcelfeaturedmemberNGSPerformantaQuorum CyberRed HelixSapphireSeconTrending
Previous Post

A new ‘global standard’ for ISVs seeking Microsoft Marketplace success?

Next Post

‘A whirlwind’ – Wiz ‘well on way’ to 100% channel

Related Posts

Alex Phillips, Northamber
Business

Northamber’s annual losses widen amid ‘deliberate transition’

24 December 2025
Westcon-Comstor HQ, Dave Stevinson, QBS Software, Patrick Zammit, TD Synnex, Ingram Micro HQ
Distributor

Meet the DSOR dozen as AWS Marketplace tightens distie embrace

23 December 2025
Russell Brown, SCC
People Moves

Exclusive: SCC snags Computacenter veteran as new UK CEO

19 December 2025
Dino Cooper, Viadex
M&A

Viadex ‘going back to what we’re known for’ as it splits from Fulcrum

19 December 2025
Exertis Enterprise stalwarts Browne and Croucher exiting for rival
People Moves

VMware UK channel boss heading for exit – partner sources

18 December 2025
The UK IT channel’s 9 biggest stories of 2025
Tech trends

The UK IT channel’s 9 biggest stories of 2025

18 December 2025
Pax8 Beyond
Distributor

Pax8’s MIP tip as UK revenues pip £130m

18 December 2025
Softcat Dublin
Careers & Skills

Dublin down? Softcat ticks fifth city off office upgrade list

17 December 2025
Next Post
Nick Ross, Wiz

‘A whirlwind’ – Wiz ‘well on way’ to 100% channel

Follow Us

IT Channel Oxygen keeps you informed on the UK IT channel and its sustainable transformation. Learn more

  • About
  • Our Team
  • Partner with us
  • Privacy Policy
  • Terms & Conditions
  • News
  • Cookie Policy (UK)

© 2025 IT Channel Oxygen

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Oxygen 250
  • Must-Know Distributors
  • Member area
  • Big Interview
  • Pulsant Zone
  • News
  • Indepth
  • About
  • Partner with us

© 2025 IT Channel Oxygen