• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
RetailSecurity
Europe

Too scared to shop? Why retail is a prime target for criminals

By
Andrew Busby
Andrew Busby
Down Arrow Button Icon
By
Andrew Busby
Andrew Busby
Down Arrow Button Icon
June 5, 2025, 3:58 AM ET
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.d3sign via Getty

Harrods, Co-op, Marks & Spencer (M&S) and now Adidas have all experienced damaging cyber attacks in recent weeks, which have sent shock waves through the retail industry. M&S alone has warned of a £300 million ($405 million) hit on profits. The attack, which began over the Easter weekend, also wiped more than £750 million ($1 billion) off its market capitalization.

Recommended Video

On 30th April, the Co-op also fell victim, reporting a few days later that hackers had accessed a “significant” amount of customer data. Then on 2nd May, Harrods also experienced a cyber attack, although in this instance, they managed to prevent any malicious intrusion. 

101

Co-op Group rank on the Fortune 500 Europe

In the M&S incident, third-party service provider Tata Consultancy Services (TCS) has reportedly launched an internal investigation to determine whether it was the gateway by which the hackers gained access.

It all points to a vulnerability amongst retail businesses, despite the fact that the threat from cyber attacks has existed for many years. But why are retail businesses being targeted?

252

Marks & Spencer rank on the Fortune 500 Europe

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage. For malicious actors, access to this data is like gold dust: highly valuable and potentially extremely lucrative” Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team at Kaspersky, told Fortune. 

On 27th May, Adidas became the latest victim of a cyber attack when it reported that, similar to M&S, hackers had accessed customer data through a third-party service provider.

In the case of M&S, according to Vaibhav Chechani, a Mumbai-based analyst at brokerage Nirmal Bang, if the attack did originate from the Indian company, “it will definitely impact their brand image”. TCS also works as a “strategic partner” to Co-op.

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage…”

Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team, Kaspersky

Rivero commented, “As seen in the M&S attack, social engineering allows attackers to bypass sophisticated cybersecurity measures by exploiting human error. These ‘human hacking’ tactics manipulate users into clicking malicious links, disclosing sensitive information, or granting access to restricted systems”.

“Simply put, data opens doors. It enables fraud, fuels targeted phishing campaigns, and can even be leveraged to infiltrate other businesses within the supply chain. This makes retailers not just lucrative targets, but also strategically valuable within the broader digital ecosystem”. 

M&S CEO Stuart Machin confirmed this, blaming the attack on “human error” rather than a weakness in its cybersecurity measures and added that, “it is a moment in time, and we are now focused on recovery, with the aim of exiting this period a much stronger business. There is no change to our strategy and our longer-term plans to reshape M&S for growth, and if anything, the incident allows us to accelerate the pace of change as we draw a line and move on”.

Despite this optimistic outlook, Retail Technology Magazine publisher and retail expert, Miya Knights, believes that other retailers could also be targeted, believing that those most vulnerable would be “those that have a sizable business with large tier one scale turnover across many channels”.

Speaking to Fortune, she added, “Cybersecurity has been a basic requirement for as long as retailers have deployed IT and transacted online. But, just as e-commerce has become a major growth driver, safeguarding the digital systems they now rely on must become as core to their business as it is for financial services companies.”

This should be the wake-up call that the retail industry needed in order to treat these threats in the same way as financial services institutions. Actions to combat the threat appear to be happening within the industry, with one prominent retail CTO saying that he is collaborating with several other retailers, including some direct competitors, to mitigate the risk of future cyber attacks.

M&S CEO Stuart Machin [blamed] the attack on “human error” rather than a weakness in its cybersecurity measures…

According to Rivero, the retail sector is under mounting pressure from cyber groups persistently probing for vulnerabilities to access large volumes of data. He said that, “Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.

“Retailers must adopt a multi-layered approach to cybersecurity, acknowledging that no single measure can provide complete protection. This approach should begin with staff education. Training employees to recognize phishing attempts and suspicious behavior is critical, with human error remaining one of the most common entry points for attackers”, he continued.

However, it’s not all the responsibility of retailers, Rivero believes that to feel more secure, consumers should take a proactive approach to their digital safety. Regularly update passwords, enable multi-factor authentication where possible, remain cautious of suspicious messages or emails, and monitor financial activity closely, “reporting any unusual behavior immediately”, adding that, “a cautious, informed approach remains the best line of defense”.

His advice to retailers using third-party service providers: “Adopt a proactive approach: regularly conducting thorough risk assessments of all vendors, enforcing strict access controls, and requiring regular security audits. Ongoing employee training is also essential – not just for non-IT staff, but also for IT teams, who are frequently targeted by social engineering tactics”.

And as he puts it, “In a landscape where cybercriminals exploit every weak link, resilience must extend beyond the organization itself to encompass the entire supply chain and all vendors”.

The Fortune 500 Innovation Forum will convene Fortune 500 executives, U.S. policy officials, top founders, and thought leaders to help define what’s next for the American economy, Nov. 16-17 in Detroit. Apply here.
About the Author
By Andrew Busby
See full bioRight Arrow Button Icon

Latest in Retail

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Lists Calendar
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Lists Calendar
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon
Andrew Busby is Senior Industry Adviser at BOXTEC, Board Adviser at The Industrious and founder of Redline Retail Consulting (formerly Retail Reflections), a retail consultancy firm that provides strategic advice and insights to the industry community.

Latest in Retail

The man who helped put meat at the top of RFK Jr.’s new food pyramid is Steak ’n Shake’s new ‘Chief MAHA Officer’
HealthFood and drink
The man who helped put meat at the top of RFK Jr.’s new food pyramid is Steak ’n Shake’s new ‘Chief MAHA Officer’
By Catherina GioinoApril 23, 2026
7 hours ago
Keurig Dr Pepper rises as cold drinks drives earnings beat
RetailKeurig Dr Pepper
Keurig Dr Pepper rises as cold drinks drives earnings beat
By Kristina Peterson and BloombergApril 23, 2026
14 hours ago
Lululemon names former Nike executive O’Neill its next CEO
C-SuiteLululemon Athletica
Lululemon names former Nike executive O’Neill its next CEO
By Lily Meier and BloombergApril 22, 2026
1 day ago
Best Buy CEO Corie Barry is stepping down: Why the comeback she executed fizzled out
C-SuiteFortune 500
Best Buy CEO Corie Barry is stepping down: Why the comeback she executed fizzled out
By Phil WahbaApril 22, 2026
1 day ago
David’s Bridal exec has a warning for every CEO obsessed with AI’s return-on-investment
Retailinvestments
David’s Bridal exec has a warning for every CEO obsessed with AI’s return-on-investment
By Alex Vuocolo and Retail BrewApril 22, 2026
1 day ago
A man helps a woman pick meat in the grocery store
EconomyFood and drink
Beef is becoming a luxury as prices stay at record highs. They likely won’t come down until 2028, says Farm Bureau
By Jacqueline MunisApril 22, 2026
1 day ago

Most Popular

When interest on national debt overtook military spending, it triggered a limit where the U.S. may ‘cease to be a great power,’ warns Hoover historian
Economy
When interest on national debt overtook military spending, it triggered a limit where the U.S. may ‘cease to be a great power,’ warns Hoover historian
By Eleanor PringleApril 23, 2026
17 hours ago
Officials will flush 50,000 toilets to flood a Utah lake in order to generate electricity
Environment
Officials will flush 50,000 toilets to flood a Utah lake in order to generate electricity
By Mead Gruver, Dorany Pineda and The Associated PressApril 22, 2026
1 day ago
Cursor’s 25-year-old CEO is a former Google intern who just inked a $60 billion deal with SpaceX
AI
Cursor’s 25-year-old CEO is a former Google intern who just inked a $60 billion deal with SpaceX
By Marco Quiroz-GutierrezApril 22, 2026
1 day ago
Despite nearing their 60s, nearly four in 10 Americans heading towards the end of their careers don’t even have a retirement account
Success
Despite nearing their 60s, nearly four in 10 Americans heading towards the end of their careers don’t even have a retirement account
By Emma BurleighApril 23, 2026
13 hours ago
Craving work-life balance is a huge red flag, says Fortune 500 Europe CEO—and like Barack Obama, he happily works through weekends
Success
Craving work-life balance is a huge red flag, says Fortune 500 Europe CEO—and like Barack Obama, he happily works through weekends
By Orianna Rosa RoyleApril 22, 2026
2 days ago
The Iran war is pushing Southeast Asia to debate the once unthinkable: Whether ships will need to pay to transit the Strait of Malacca
Economy
The Iran war is pushing Southeast Asia to debate the once unthinkable: Whether ships will need to pay to transit the Strait of Malacca
By Angelica AngApril 23, 2026
17 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.