The Containment Era is here. →Explore

Executive Summary

In early 2025, Marks & Spencer (M&S) and Co-op Group, two major UK retailers, suffered significant ransomware attacks following sophisticated vishing campaigns. Attackers impersonated IT support and targeted outsourced helpdesk staff to capture corporate credentials, enabling unauthorized access to internal networks. Once inside, threat actors leveraged overprivileged accounts and weak segmentation to laterally move and exfiltrate sensitive data, ultimately deploying ransomware that disrupted operations. The incidents resulted in direct losses exceeding £500 million (USD 667 million), with long-term impacts including reputational harm and regulatory scrutiny.

This breach underscores the ongoing threat of identity-based attacks, particularly those exploiting social engineering and credential harvesting to bypass perimeter defenses. With the rise of distributed workforces, cloud adoption, and third-party supply chains, organizations of all sizes remain vulnerable to similar tactics, making identity security and robust privilege management more urgent than ever.

Why This Matters Now

Identity-based attacks such as vishing and targeted credential theft are escalating, enabling attackers to exploit gaps in privilege management and segmented controls. As digital transformation accelerates, urgent implementation of zero trust principles and stronger authentication has become critical to defend against evolving threats and minimize breach impact.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used vishing to trick IT helpdesk staff into revealing corporate credentials, then exploited overprivileged accounts and poor segmentation to move laterally and deploy ransomware.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust controls including identity-based segmentation, centralized policy enforcement, and egress monitoring could have constrained the adversaries' lateral movement, privilege escalation, and exfiltration efforts. Applying CNSF capabilities such as Zero Trust Segmentation, East-West Traffic Security, and Egress Policy Enforcement would have limited blast radius, hindered data theft, and accelerated detection and response.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Suspicious credential usage would be rapidly detected across environments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Least privilege network policy would confine user access, reducing escalation pathways.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Unauthorized intra-cloud movement would be blocked or alerted.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Real-time anomaly detection would flag and contain suspicious C2 activity.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Outbound data transfers to unapproved destinations would be blocked or logged.

Impact (Mitigations)

Distributed inline controls help detect and contain widespread ransomware actions.

Impact at a Glance

Affected Business Functions

  • Retail Operations
  • Customer Service
  • Supply Chain Management
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $667,000,000

Data Exposure

Potential exposure of customer personal and payment information due to compromised credentials.

Recommended Actions

  • Enforce identity-based Zero Trust segmentation to restrict lateral movement from compromised accounts.
  • Deploy centralized visibility and anomaly detection to rapidly identify suspicious credential usage and insider threats.
  • Apply outbound egress filtering and policy enforcement to stop data exfiltration and C2 traffic.
  • Regularly review and minimize privilege assignments, using automated tools to detect overprivileged or dormant accounts.
  • Integrate inline detection and response controls across cloud and hybrid environments to contain ransomware and unauthorized actions in real-time.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image