#244: Comparing Two Modern UK Cyber Attacks
From TfL to Marks & Spencer
Key Takeaways
The Transport for London and Marks & Spencer cyber attacks demonstrate how modern attackers increasingly prioritise identity compromise and social engineering over traditional exploitation techniques.
Both incidents highlight that highly disruptive cyber attacks no longer require advanced malware or previously unknown vulnerabilities. Compromising trusted identities can provide attackers with the access they need.
The attacks show similarities in attacker behaviour, including the targeting of human processes, abuse of legitimate access and the use of existing administrative tools after gaining entry.
The incidents also demonstrate important differences. TfL primarily exposed the risks of identity compromise within a public service environment, while the M&S attack showed how a retail organisation can suffer prolonged operational and financial disruption from a similar class of intrusion.
Security teams should increasingly focus on identity resilience, privileged access management, help desk security, third-party risk and business continuity alongside traditional technical controls.
#243: The Entrepreneurial Adversary
A Complimentary Pen Test from the Team That Tests the Whole Product
A Complimentary Pen Test from the Team That Tests the Whole Product
Most product teams test components in isolation. Winmill tests the product ecosystem as one connected surface: the device, hardware, and firmware, the OS and communication protocols, the web, mobile, and API applications that connect to it, and the cloud backend and network behind it, in one engagement, so every attack surface is covered.
The timing matters. For companies selling connected products into the EU, the Cyber Resilience Act and the Radio Equipment Directive are active obligations. Winmill testing aligns with EN 18031 (RED), with accredited laboratory engagements available when your compliance path requires them.
To see our approach firsthand, we are offering SecPro readers a complimentary penetration test.
Cybersecurity incidents are often analysed individually. A breach affecting a transport organisation is viewed as a critical infrastructure problem, while an attack against a retailer is treated as a business continuity issue. However, examining major incidents together often reveals broader trends that are less obvious when each event is considered in isolation.
The cyberattacks affecting Transport for London (TfL) and Marks & Spencer (M&S) provide a useful comparison because they represent two different organisations facing a similar style of modern threat. One operates a public transport network used by millions of people, while the other manages one of the UK’s most recognisable retail brands. Despite the differences in their missions, both incidents demonstrate how attackers increasingly target identity, trust and operational processes rather than relying solely on technical exploitation.
The attacks also challenge some long-standing assumptions about cybercrime. Significant disruption has historically been associated with highly advanced adversaries using sophisticated malware or previously unknown vulnerabilities. Recent incidents suggest a different reality. Attackers can achieve substantial operational impact by combining social engineering, stolen credentials, legitimate administrative access and knowledge of how organisations function.
The most important lesson from both incidents is that modern cybersecurity is increasingly about protecting trust. Organisations no longer operate within clearly defined network boundaries, and attackers understand that compromising a legitimate identity can provide more value than attempting to bypass technical controls directly.
The Transport for London Cyber Attack
Transport for London disclosed in September 2024 that it had experienced a cyber incident affecting parts of its network and internal systems. The organisation activated its incident response procedures and worked with external cybersecurity specialists, law enforcement and government agencies to investigate the intrusion and restore affected services.
Public reporting indicated that the attackers gained access through social engineering techniques rather than exploiting a previously unknown vulnerability. Investigations later focused on individuals associated with the attack, with authorities identifying young suspects who had allegedly used compromised accounts and attempted to access TfL systems. The case ultimately resulted in criminal prosecutions, with the financial impact of the incident estimated at tens of millions of pounds.
The incident was significant because it demonstrated that even large, highly visible organisations can be affected by relatively straightforward attack techniques. TfL operates a complex technology environment supporting transport operations, customer services and internal business functions. However, the attackers did not need to defeat every security control protecting that environment. Instead, they focused on obtaining legitimate access and using trusted mechanisms to move through the organisation.
This represents a broader trend in cyber attacks. Attackers increasingly understand that employees, contractors and support processes represent important security boundaries. If an attacker can convince an organisation to provide access, reset credentials or approve a request, they can often bypass many of the controls designed to protect against external threats.
The TfL incident therefore provides a clear example of why identity security has become central to modern cybersecurity strategies. Multi-factor authentication, privileged access controls, monitoring of unusual authentication activity and robust help desk procedures are no longer optional enhancements. They are fundamental security requirements.
The Marks & Spencer Cyber Attack
The Marks & Spencer cyberattack followed a similar pattern but resulted in a much broader and more visible operational impact. The incident affected online ordering, digital services, fulfilment operations and customer-facing systems, creating significant disruption for one of the UK’s largest retailers.
Public reporting linked the incident to attackers associated with the Scattered Spider ecosystem, a loosely organised group of threat actors known for social engineering campaigns and identity-based attacks. Reports indicated that attackers targeted human processes, including service desk operations, to obtain access rather than relying exclusively on technical exploitation.
The consequences were substantial. M&S experienced disruption across multiple business functions, affecting online shopping, customer services and parts of its supply chain. The company later warned investors that the incident would have a significant financial impact, with costs associated with lost sales, recovery efforts and security improvements expected to be considerable.
The M&S attack demonstrated how identity compromise can become a business-wide problem. Once attackers obtain legitimate access, they can operate using tools and accounts that appear normal within the environment. This makes detection more difficult because security teams must distinguish between legitimate employee behaviour and malicious activity performed through compromised accounts.
The incident also highlighted the growing importance of operational resilience. Modern organisations depend on interconnected digital services, meaning a successful cyber attack can affect not only information security but also revenue generation, customer experience and supply chain operations. Security incidents are no longer confined to IT departments; they can quickly become executive and board-level concerns.
Similarities Between the Two Attacks
The most obvious similarity between the TfL and M&S incidents is the apparent emphasis on identity compromise. Neither attack is primarily notable because of an advanced technical exploit. Instead, both demonstrate the effectiveness of targeting people, processes and trusted access mechanisms.
Social engineering remains one of the most effective techniques available to attackers because it exploits the same systems organisations rely upon every day. Employees need to collaborate, support teams need to reset access and administrators need to maintain operational efficiency. Attackers exploit these legitimate processes by creating situations where normal security procedures become opportunities for compromise.
Both incidents also demonstrate the importance of legitimate access. Once attackers possess valid credentials, many traditional security controls become less effective. Firewalls, endpoint protection and vulnerability management remain essential, but they cannot prevent every attack if an adversary is operating through an account that appears legitimate.
Another similarity is the level of operational disruption achieved. These were not simple data theft incidents where attackers quietly removed information and disappeared. Both attacks affected the ability of organisations to operate normally, demonstrating that modern adversaries increasingly understand the value of disruption.
The incidents also highlight how cyber attacks have become public-facing business events. TfL and M&S both operate services that directly affect customers and the public. As a result, incident response involved not only technical recovery but also communication, reputation management and maintaining stakeholder confidence.
Differences Between the Two Attacks
Despite the similarities, the two incidents also demonstrate important differences. The first difference is the nature of the organisations targeted. TfL provides an essential public service where availability and safety are primary concerns. A cyber attack against a transport operator raises questions about operational continuity and public confidence. M&S, while not critical infrastructure in the same sense, operates a complex commercial ecosystem where digital availability directly influences revenue, customer relationships and supply chain efficiency.
The operational consequences were therefore different. TfL focused heavily on maintaining transport services and restoring internal systems, while M&S faced disruption across customer transactions, online commerce and retail operations. The same broad attack methodology produced different consequences because of the organisations’ differing business models.
The second difference is the available public information. The TfL incident progressed through a criminal investigation that resulted in prosecutions, providing greater visibility into some aspects of the attackers and their activities. The M&S investigation has involved ongoing analysis, meaning some technical details remain based on public reporting rather than a complete forensic disclosure.
A third difference is the scale of commercial impact. While both organisations suffered disruption, M&S faced particularly significant financial consequences because retail operations depend heavily on continuous digital availability. Online ordering, fulfilment systems and customer interactions are now fundamental components of modern retail, meaning cyber disruption can translate directly into lost revenue.
These differences demonstrate why organisations must adapt security strategies to their operational context. A transport provider, retailer, healthcare organisation and financial institution may face similar attack techniques but experience very different consequences.
What Security Teams Should Learn
The first lesson from both incidents is that identity security must become a core security discipline. Organisations should assume that attackers will continue targeting credentials, authentication processes and privileged access because these methods remain highly effective. Identity governance, phishing-resistant authentication, privileged access management and continuous monitoring should be treated as foundational security controls.
The second lesson concerns human processes. Many organisations invest heavily in technical controls while leaving support workflows and administrative procedures less protected. Help desks, identity administrators and third-party support teams represent attractive targets because they have legitimate authority to change access. Security teams must ensure that these processes include strong verification mechanisms and are resistant to social engineering.
The third lesson is the importance of resilience. Preventing every successful intrusion is unrealistic, particularly as attackers continue improving their ability to manipulate legitimate access. Organisations must therefore ensure they can detect suspicious behaviour quickly, limit attacker movement, restore critical services and communicate effectively during incidents.
Finally, these attacks demonstrate the importance of understanding modern adversaries. Security teams cannot rely solely on assumptions about what a sophisticated attacker looks like. The individuals involved in these incidents challenged traditional expectations about age, organisational structure and technical background. Capability is becoming increasingly accessible, and threat models must reflect that reality.
Will We Learn for the Next Time?
The TfL and Marks & Spencer cyberattacks represent two different examples of the same broader shift in cybersecurity. Attackers are increasingly successful not because they possess unprecedented technical capabilities, but because they understand how organisations operate and where trust can be exploited.
Both incidents reinforce the idea that identity has become one of the most important security boundaries in modern enterprises. Credentials, access workflows and human decision-making processes are now as important to protect as networks and applications.
The lesson is not that organisations are vulnerable because their technology is inadequate. Rather, it is that the nature of cyber risk has changed. Modern attackers increasingly target the systems of trust that allow organisations to function, and security strategies must evolve accordingly.
The future of cybersecurity will depend not only on preventing compromise but on ensuring that when attackers obtain access, their ability to cause damage remains limited. Organisations that combine strong identity security, resilient operations, and mature incident response will be best positioned to withstand the next generation of cyberattacks.
Further Reading
Scattered Spider, NIST
Inside CISA’s Phishing-Resistant MFA Playbook, ID Dataweb







