Cyber Security Insights May 2025

Cyber Security Insights May 2025

Written by Bryan Altimas

Well, what a month! UK retail is under attack with Marks and Spencer (M&S), Co-op and Harrods all suffering attacks. In this month's edition we look at:

  • The attacks on the retail trade from a different perspective. What accreditations did the companies have at the time of the attacks and what does this tell us about their attitude to cyber security.
  • Next we look at 2 major UK attacks that happened in October 2023 at the British Library and at Synnovis, in June 2024, who are the pathology system supplier to the Guys and St. Thomas's NHS Foundation Trust and Kings College NHS Foundation Trust and how they are recovering.
  • Our third article looks at cyber resilience and why it matters to you.

Cyber Attacks on Retail

M&S Co-Op and Harrods logos

Retail Giants Under Siege: Cyberattacks on M&S, Co-op, and Harrods

Overview

In April 2025, UK retailers Marks & Spencer (M&S) and Co-op and followed by Harrods in early May experienced significant cyberattacks, disrupting operations and exposing vulnerabilities in their cybersecurity frameworks. All three cases have been claimed by the Scattered Spiders group deploying DragonForce ransomware. Hackers impersonated employees to deceive IT help desks into resetting passwords, granting unauthorised access to internal networks.

Key Incidents

  • Marks & Spencer (M&S): Suffered a ransomware attack over the Easter weekend, leading to the suspension of online orders and shortages of food on shop shelves. The attack resulted in estimated losses of £15 million per week and a £750 million drop in market value. Three weeks after the attack it is not known when full operation will return.
  • Co-op: Faced IT system shutdowns affecting deliveries and customer data exposure. According to a BBC interaction with the hackers 20 million personal data records of all Co-op members and all 70,000 employees access credentials have been stolen.
  • Harrods: Detected unauthorised access attempts, prompting immediate security measures. While operations continued, the incident highlighted potential vulnerabilities. There has not been any further statement on the impact at Harrods.

Insights

These attacks underscore the importance of robust cybersecurity frameworks, including adherence to standards like ISO 27001. The incidents reveal how social engineering tactics can bypass technical defences, emphasising the need for comprehensive security awareness and training. An appropriately designed scope of ISO 27001 and continued adherence to the cyber security controls will provide sufficient protection to make the hackers go elsewhere.

  • Whilst the M&S Annual Report 2024 does mention cyber security details are scant. Cyber and information security risks are discussed in the Principal Risks and Uncertainties section. They are standard risks written by an audit team.
  • I have also examined the M&S website and cannot find evidence of ISO27001 or similar cyber security standard accreditation.
  • The Co-op Annual Report 2024 also has a risk for cyber security in the Principal Risks and Uncertainties section. Again, it is a standard risk written by an audit team and mitigation details are few and far between.
  • The Co-op website does not have evidence of ISO 27001 or similar cyber security standard accreditation.
  • Neither of Harrods Annual Report 2024 or their website mentions cyber security nor ISO27001 or similar cyber security accreditation.

In the 2025 CISCO Cybersecurity Readiness Index (UK) it says only 4% of UK businesses reached the mature stage of readiness and alarmingly 70% are in the beginner (9%) and formative (61%) stages.

What does this say about all three companies attitude to cyber security? My opinion is that none of the companies are demonstrating to the public they had taken cyber threats seriously and probably had not invested sufficiently to prevent attacks. However, they are similar to most companies.

DM me with the word retail to discuss your cyber risks.

The British Library and NHS Cyber Incidents

Overview

The British Library suffered a ransomware attack in 2023. NHS services, provided by Synnovis the supplier of pathology systems to Guy’s & St Thomas’ NHS Foundation Trust and King’s College NHS Foundation Trust, experienced cyberattacks in June 2024 disrupting critical operations and blood transfusions and blood tests.

Key Incidents

  • British Library: In October 2023, the library suffered a ransomware attack by the Rhysida group, leading to significant service outages and the leak of 600GB of sensitive data. Recovery efforts have been extensive, with costs estimated at £7 million.
  • Synnovis and NHS Hospitals: A ransomware incident at Synnovis in June 2024 disrupted pathology services, affecting patient care and requiring extensive recovery efforts. The attack, attributed to the Qilin group, led to the cancellation of thousands of appointments for blood tests, urgent blood transfusions and delayed many operations.

Insights

All the organisations have recovered now though? The attacks were in 2023 and 2024. The answer is no!

British Library

AI generated image depicting the cyber attack on the British Library
AI generated image depicting the cyber attack on the British Library

The British Library has been praised for its response to the attack and its transparency into what happened. It is still recovering undertaking a recover and rebuild program for many of its systems that were outdated and out of support.

This is the latest update from the British Library website blog: Following the major cyber-attack in late 2023, 2024 saw us bring back interim versions of a number of our key services, including:

  • an online version of our catalogue;
  • remote ordering of print items to our Reading Rooms;
  • our entire print collection – including newspapers – accessible to Readers
  • the first 1,000 digitised manuscripts available to explore online.

The damage caused in the attack was extensive, and our recovery continues to be underpinned by the need to rebuild our infrastructure safely and securely. Over the next year we’ll continue to restore systems and services.

Synnovis, Guys & St. Thomas' and Kings College NHS Trusts

An AI created image of Synnovis, Guy's and St Thomas' and Kings College NHS Foundation Trusts' logos
AI created image of the 3 impacted organisations

By contrast 11 months after the Synnovis attack patients are still in the dark about what data was stolen, including information about their illnesses. The Qilin group published information on the dark web.

Synnovis has still not provided a detailed analysis of what data was published by Qilin. Data breach specialists CaseMatrix suggest more than 900,000 patients were impacted, with the published material including names, dates of birth, NHS numbers, and in some cases personal contact details. But the most sensitive information CaseMatrix identified included pathology and histology forms used to share patient details between medical departments and institutions. These forms often describe symptoms of intimate and private medical conditions.

Full recovery in both of these attacks is still some way off. The attack demonstrates that recovery from cyber-attacks is a complicated operation. The complexity is especially poignant when primary data and backup data is encrypted in the attack. Cyber security resilience is critical in surviving an attack.

Worried about your cyber security resilience DM me with the word resilience.

Cyber Resilience Isn’t Optional. It’s Business Survival.

It’s 2025. Cyber attacks aren’t rare. They’re relentless. There is an attack on UK business every 45 seconds (NCSC)

AI generated image for cyber resilience in action
AI generated image for Cyber resilience in action

🟦 Phishing and ransomware are no longer just threats — they’re business models.

🟦 Regulatory pressures aren’t slowing down — they’re stacking up.

🟦 AI is accelerating decision-making — but also amplifying risk at speed and scale.

If your organisation is still thinking in terms of cyber security as a box-ticking exercise, we need to talk. Because what you really need — now more than ever — is cyber resilience.

What is Cyber Resilience — and Why Should You Care?

Cyber resilience is the ability to prepare for, respond to, and recover from cyber incidents.

It’s not just about stopping threats. It’s about bouncing back fast, keeping operations running, and protecting your reputation while under pressure.

In plain terms: Security helps you avoid the fire. Resilience ensures your business survives the fire.

And in today’s climate, fires happen — often. There is an attack on UK businesses and / or infrastructure every 45 seconds (NCSC)

The Business Case for Resilience

Let’s get real. You’ve probably heard:

“We haven’t been hit yet. We’re fine.”

Until you’re not. And when that moment comes, it’s too late to start planning.

🟦 The average cost of recovery of a UK data breach in 2024? £3.4 million. Excluding lost sales, lost customers etc.

🟦 Downtime from ransomware? Days — sometimes months.

🟦 Regaining lost trust? Months… if ever.

But the real cost? Boardroom chaos. Customer churn. Contract loss.

Cyber resilience protects revenue continuity, brand trust, and investor confidence — the things that keep your business alive and growing.

Resilience Is a Whole-Business Capability

Resilience doesn’t live in IT.

🟦 The CFO needs to know the financial exposure.

🟦 The COO must understand operational impacts.

🟦 The CEO should be asking: “What’s our recovery time — and who’s accountable?”

🟦 Every employee must know what to do when something goes wrong.

Your people are your frontline — or your liability.

That’s why resilience must be embedded, not bolted on. Through planning, testing, and culture. Through partnerships — not products.

Where Do You Start?

If this all feels overwhelming, you’re not alone. Many scaling businesses realise too late they’ve outgrown their informal, ad-hoc approach.

Here’s what we tell clients:

🟦 Start with a business risk lens — not a tech one.

🟦 Run a readiness review — how fast can you detect, respond, and recover?

🟦 Map your crown jewels — know what data must be protected at all costs.

🟦 Drill your teams — tabletop exercises beat chaos every time.

🟦 Get external help — resilience isn’t DIY.

Bottom Line

Cyber resilience is what turns a cyber event into a blip — not a headline.

You don’t need to do everything at once. But you do need to start.

Because in today’s threat landscape, the question isn’t if your business will face disruption.

It’s when. And how prepared you’ll be to survive it.

💬 If you’re wondering where the gaps are in your cyber security — let’s have a conversation. DM me the word resilience.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right