• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
RetailSecurity
Europe

Too scared to shop? Why retail is a prime target for criminals

By
Andrew Busby
Andrew Busby
Down Arrow Button Icon
June 5, 2025, 3:58 AM ET
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.d3sign via Getty

Harrods, Co-op, Marks & Spencer (M&S) and now Adidas have all experienced damaging cyber attacks in recent weeks, which have sent shock waves through the retail industry. M&S alone has warned of a £300 million ($405 million) hit on profits. The attack, which began over the Easter weekend, also wiped more than £750 million ($1 billion) off its market capitalization.

Recommended Video

On 30th April, the Co-op also fell victim, reporting a few days later that hackers had accessed a “significant” amount of customer data. Then on 2nd May, Harrods also experienced a cyber attack, although in this instance, they managed to prevent any malicious intrusion. 

101

Co-op Group rank on the Fortune 500 Europe

In the M&S incident, third-party service provider Tata Consultancy Services (TCS) has reportedly launched an internal investigation to determine whether it was the gateway by which the hackers gained access.

It all points to a vulnerability amongst retail businesses, despite the fact that the threat from cyber attacks has existed for many years. But why are retail businesses being targeted?

252

Marks & Spencer rank on the Fortune 500 Europe

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage. For malicious actors, access to this data is like gold dust: highly valuable and potentially extremely lucrative” Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team at Kaspersky, told Fortune. 

On 27th May, Adidas became the latest victim of a cyber attack when it reported that, similar to M&S, hackers had accessed customer data through a third-party service provider.

In the case of M&S, according to Vaibhav Chechani, a Mumbai-based analyst at brokerage Nirmal Bang, if the attack did originate from the Indian company, “it will definitely impact their brand image”. TCS also works as a “strategic partner” to Co-op.

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage…”

Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team, Kaspersky

Rivero commented, “As seen in the M&S attack, social engineering allows attackers to bypass sophisticated cybersecurity measures by exploiting human error. These ‘human hacking’ tactics manipulate users into clicking malicious links, disclosing sensitive information, or granting access to restricted systems”.

“Simply put, data opens doors. It enables fraud, fuels targeted phishing campaigns, and can even be leveraged to infiltrate other businesses within the supply chain. This makes retailers not just lucrative targets, but also strategically valuable within the broader digital ecosystem”. 

M&S CEO Stuart Machin confirmed this, blaming the attack on “human error” rather than a weakness in its cybersecurity measures and added that, “it is a moment in time, and we are now focused on recovery, with the aim of exiting this period a much stronger business. There is no change to our strategy and our longer-term plans to reshape M&S for growth, and if anything, the incident allows us to accelerate the pace of change as we draw a line and move on”.

Despite this optimistic outlook, Retail Technology Magazine publisher and retail expert, Miya Knights, believes that other retailers could also be targeted, believing that those most vulnerable would be “those that have a sizable business with large tier one scale turnover across many channels”.

Speaking to Fortune, she added, “Cybersecurity has been a basic requirement for as long as retailers have deployed IT and transacted online. But, just as e-commerce has become a major growth driver, safeguarding the digital systems they now rely on must become as core to their business as it is for financial services companies.”

This should be the wake-up call that the retail industry needed in order to treat these threats in the same way as financial services institutions. Actions to combat the threat appear to be happening within the industry, with one prominent retail CTO saying that he is collaborating with several other retailers, including some direct competitors, to mitigate the risk of future cyber attacks.

M&S CEO Stuart Machin [blamed] the attack on “human error” rather than a weakness in its cybersecurity measures…

According to Rivero, the retail sector is under mounting pressure from cyber groups persistently probing for vulnerabilities to access large volumes of data. He said that, “Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.

“Retailers must adopt a multi-layered approach to cybersecurity, acknowledging that no single measure can provide complete protection. This approach should begin with staff education. Training employees to recognize phishing attempts and suspicious behavior is critical, with human error remaining one of the most common entry points for attackers”, he continued.

However, it’s not all the responsibility of retailers, Rivero believes that to feel more secure, consumers should take a proactive approach to their digital safety. Regularly update passwords, enable multi-factor authentication where possible, remain cautious of suspicious messages or emails, and monitor financial activity closely, “reporting any unusual behavior immediately”, adding that, “a cautious, informed approach remains the best line of defense”.

His advice to retailers using third-party service providers: “Adopt a proactive approach: regularly conducting thorough risk assessments of all vendors, enforcing strict access controls, and requiring regular security audits. Ongoing employee training is also essential – not just for non-IT staff, but also for IT teams, who are frequently targeted by social engineering tactics”.

And as he puts it, “In a landscape where cybercriminals exploit every weak link, resilience must extend beyond the organization itself to encompass the entire supply chain and all vendors”.

Join us at the Fortune Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
By Andrew Busby
See full bioRight Arrow Button Icon

Latest in Retail

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Andrew Busby is Senior Industry Adviser at BOXTEC, Board Adviser at The Industrious and founder of Redline Retail Consulting (formerly Retail Reflections), a retail consultancy firm that provides strategic advice and insights to the industry community.

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Most Popular

placeholder alt text
Economy
The $38 trillion national debt is to blame for over $1 trillion in annual interest payments from here on out, CRFB says
By Nick LichtenbergDecember 17, 2025
2 days ago
placeholder alt text
AI
'Robots are going to be amongst us': Qualcomm exec says buckle up for the next 5 years. Your car is going to be the first shoe to drop
By Nino PaoliDecember 17, 2025
2 days ago
placeholder alt text
C-Suite
Red Lobster CEO Damola Adamolekun says the key to being a better leader is being a better person: ‘Leadership is self-improvement’
By Sydney LakeDecember 17, 2025
2 days ago
placeholder alt text
Success
As millions of Gen Zers face unemployment, McDonald's CEO dishes out some tough love career advice for navigating the market: ‘You've got to make things happen for yourself’
By Preston ForeDecember 16, 2025
3 days ago
placeholder alt text
Success
Britain’s defense chief calls on Gen Z grads leaving university to skip corporate jobs and join the military as war with Russia becomes a growing risk
By Emma BurleighDecember 17, 2025
2 days ago
placeholder alt text
Future of Work
LinkedIn CEO says it's 'outdated' to have a five-year career plan: It's a 'little bit foolish' considering the pace AI is changing the workplace
By Sydney LakeDecember 18, 2025
15 hours ago

Latest in Retail

RetailWomen
Walmart’s women truckers surge thanks to $115,000 starting pay and other perks bringing in nontraditional candidates
By Marco Quiroz-GutierrezDecember 18, 2025
8 hours ago
Nathaniel Ru
RetailRestaurants
Sweetgreen co-founder is stepping down from executive role
By Redd Brown and BloombergDecember 17, 2025
1 day ago
A woman holds a colorful pink and green Birkin bag in front of her legs.
RetailLuxury
Gen Z’s reality check: Birkin resale prices slump as aspirational luxury takes a hit
By Sasha RogelbergDecember 17, 2025
1 day ago
Trump
EconomyTariffs and trade
Tariffs take a bite out of mom-and-pop stores as small business profit growth turns negative for first time in 18 months, BofA says
By Nick LichtenbergDecember 17, 2025
2 days ago
Walmart
LawCrime
33-year-old woman charged with attempted mayhem after Mississippi Walmart sells razorblade bread
By The Associated PressDecember 17, 2025
2 days ago
Shoppers in a grocery store
RetailGrocery
As Americans continue to feel the pain from tariffs and inflation, Lidl launches holiday meal deal for less than $4 per person
By Nino PaoliDecember 16, 2025
2 days ago