Back to feed

Scattered Spider social engineering exploits service desks to breach UK retailers

1 min
Scattered Spider social engineering exploits service desks to breach UK retailers

This digest was compiled by AI from multiple sources — links to the originals are below.

Scattered Spider used social engineering to breach UK retailers including Marks & Spencer, Co-op, and Harrods in April 2025. The attacks exploited service desk password resets and authentication changes to bypass security controls. Microsoft separately warned of two social engineering campaigns targeting cloud accounts and fraudulent ACH payments.

Key Facts

  • Marks & Spencer suffered a cyber-attack in April 2025 that disrupted online operations and resulted in customer data being taken.
  • Co-op was targeted in the same wave of attacks, with attackers using social engineering to gain access to an employee account.
  • Harrods restricted internet access across parts of its network in April 2025 after detecting unauthorized access attempts.
  • Microsoft warned of a campaign urging employees to process ACH payments totaling nearly $50,000 through executive impersonation.
  • Microsoft observed identity-based attacks targeting personal phones since May 2026 using AiTM and device code phishing.

Scattered Spider Playbook

Scattered Spider's defining tactic is social engineering through service desk calls. Attackers research employees via LinkedIn, company websites, and breach datasets to impersonate them convincingly. Caller-ID spoofing, email spoofing, and SIM-swapped phones strengthen the impersonation. Operatives call the service desk with routine requests like 'I've changed phones' or 'My authenticator isn't working'. The 2023 MGM Resorts attack exemplified this playbook, leading to widespread disruption and ransomware.

Microsoft Cloud Campaigns

Microsoft detailed a campaign on Sept. 9 involving calls or messages claiming victims need to update passkeys, MFA, or SSO configurations. Attackers use adversary-in-the-middle techniques or device code phishing to steal credentials and session tokens. A second campaign, detailed Sept. 10, impersonates executives to request ACH payments of nearly $50,000. Microsoft suspects generative AI is used to create convincing fake email threads in the fraud campaign. Compromised cloud accounts often lead to extortion by groups such as ShinyHunters and Helix.