How to combat the ransomware that struck Marks & Spencer

The National Cyber Security Centre (NCSC) has issued fresh guidance on how to combat ransomware, following high-profile attacks on Marks & Spencer and the Co-Op.

Marks & Spencer’s systems are still being affected by an attack that was first revealed more than a fortnight ago, with the company’s website continuing to state this morning that “we have paused online orders”.

The hacking group Scattered Spider are believed to be responsible for the attack, which involved social engineering techniques used to impersonate employees and deceive IT help desks into resetting passwords. This allowed the hackers to spread ransomware across the retailer’s network.

A similar attack has targeted the Co-Op, believed to be orchestrated by the same group.

NCSC guidance

Although the NCSC says “we are not yet in a position to say if these attacks are linked, if this is a concerted campaign by a single actor or whether there is no link between them at all,” the fresh guidance issued by the organisation on the back of “recent attacks on the retail sector” strongly suggests it’s aware of the tactics used to infiltrate both retailers.

The NCSC says organisations are “strongly encouraged” to ensure that two-step verification is “deployed comprehensively” across their organisation, meaning that attackers can’t get in with compromised login details alone.

It advises companies to “enhance monitoring against unauthorised account misuse”, suggesting that IT admins scan for “risky logins” with Microsoft’s Entra ID Protection and pay careful attention to any sign-in attempts that have been flagged as suspicious or unusual.

Companies are told to take particular caution with logins for Domain Admin, Enterprise Admin or Cloud Admin roles, and ensure that they have the ability to detect logins from “atypical sources” such as VPNs.

In the clearest indication yet that the reported tactics for the Marks & Spencer attack are accurate, the NCSC is also advising companies to review their helpdesk’s password reset policies. This includes “how the helpdesk authenticates staff members credentials before resetting passwords, especially those with escalated privileges”.

Severe consequences

The NCSC warns that recovery from ransomware attacks can be lengthy and costly, and that’s certainly been the case for Marks & Spencer. The attack has wiped ยฃ500 million off the company’s share value and will cost at least ยฃ30 million to put right, according to a report from Reuters.

The weekly ongoing losses for the suspension of its online store and other disruption are estimated at ยฃ15 million, although some of that may be offset by insurance against such attacks.

Avatar photo
Barry Collins

Barry has 25 years of experience working on national newspapers, websites and magazines. He was editor of PC Pro and is co-editor and co-owner of BigTechQuestion.com. He has published a number of articles on TechFinitive covering data, innovation and cybersecurity.