• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
RetailSecurity
Europe

Too scared to shop? Why retail is a prime target for criminals

By
Andrew Busby
Andrew Busby
Down Arrow Button Icon
By
Andrew Busby
Andrew Busby
Down Arrow Button Icon
June 5, 2025, 3:58 AM ET
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.d3sign via Getty

Harrods, Co-op, Marks & Spencer (M&S) and now Adidas have all experienced damaging cyber attacks in recent weeks, which have sent shock waves through the retail industry. M&S alone has warned of a £300 million ($405 million) hit on profits. The attack, which began over the Easter weekend, also wiped more than £750 million ($1 billion) off its market capitalization.

Recommended Video

On 30th April, the Co-op also fell victim, reporting a few days later that hackers had accessed a “significant” amount of customer data. Then on 2nd May, Harrods also experienced a cyber attack, although in this instance, they managed to prevent any malicious intrusion. 

101

Co-op Group rank on the Fortune 500 Europe

In the M&S incident, third-party service provider Tata Consultancy Services (TCS) has reportedly launched an internal investigation to determine whether it was the gateway by which the hackers gained access.

It all points to a vulnerability amongst retail businesses, despite the fact that the threat from cyber attacks has existed for many years. But why are retail businesses being targeted?

252

Marks & Spencer rank on the Fortune 500 Europe

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage. For malicious actors, access to this data is like gold dust: highly valuable and potentially extremely lucrative” Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team at Kaspersky, told Fortune. 

On 27th May, Adidas became the latest victim of a cyber attack when it reported that, similar to M&S, hackers had accessed customer data through a third-party service provider.

In the case of M&S, according to Vaibhav Chechani, a Mumbai-based analyst at brokerage Nirmal Bang, if the attack did originate from the Indian company, “it will definitely impact their brand image”. TCS also works as a “strategic partner” to Co-op.

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage…”

Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team, Kaspersky

Rivero commented, “As seen in the M&S attack, social engineering allows attackers to bypass sophisticated cybersecurity measures by exploiting human error. These ‘human hacking’ tactics manipulate users into clicking malicious links, disclosing sensitive information, or granting access to restricted systems”.

“Simply put, data opens doors. It enables fraud, fuels targeted phishing campaigns, and can even be leveraged to infiltrate other businesses within the supply chain. This makes retailers not just lucrative targets, but also strategically valuable within the broader digital ecosystem”. 

M&S CEO Stuart Machin confirmed this, blaming the attack on “human error” rather than a weakness in its cybersecurity measures and added that, “it is a moment in time, and we are now focused on recovery, with the aim of exiting this period a much stronger business. There is no change to our strategy and our longer-term plans to reshape M&S for growth, and if anything, the incident allows us to accelerate the pace of change as we draw a line and move on”.

Despite this optimistic outlook, Retail Technology Magazine publisher and retail expert, Miya Knights, believes that other retailers could also be targeted, believing that those most vulnerable would be “those that have a sizable business with large tier one scale turnover across many channels”.

Speaking to Fortune, she added, “Cybersecurity has been a basic requirement for as long as retailers have deployed IT and transacted online. But, just as e-commerce has become a major growth driver, safeguarding the digital systems they now rely on must become as core to their business as it is for financial services companies.”

This should be the wake-up call that the retail industry needed in order to treat these threats in the same way as financial services institutions. Actions to combat the threat appear to be happening within the industry, with one prominent retail CTO saying that he is collaborating with several other retailers, including some direct competitors, to mitigate the risk of future cyber attacks.

M&S CEO Stuart Machin [blamed] the attack on “human error” rather than a weakness in its cybersecurity measures…

According to Rivero, the retail sector is under mounting pressure from cyber groups persistently probing for vulnerabilities to access large volumes of data. He said that, “Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.

“Retailers must adopt a multi-layered approach to cybersecurity, acknowledging that no single measure can provide complete protection. This approach should begin with staff education. Training employees to recognize phishing attempts and suspicious behavior is critical, with human error remaining one of the most common entry points for attackers”, he continued.

However, it’s not all the responsibility of retailers, Rivero believes that to feel more secure, consumers should take a proactive approach to their digital safety. Regularly update passwords, enable multi-factor authentication where possible, remain cautious of suspicious messages or emails, and monitor financial activity closely, “reporting any unusual behavior immediately”, adding that, “a cautious, informed approach remains the best line of defense”.

His advice to retailers using third-party service providers: “Adopt a proactive approach: regularly conducting thorough risk assessments of all vendors, enforcing strict access controls, and requiring regular security audits. Ongoing employee training is also essential – not just for non-IT staff, but also for IT teams, who are frequently targeted by social engineering tactics”.

And as he puts it, “In a landscape where cybercriminals exploit every weak link, resilience must extend beyond the organization itself to encompass the entire supply chain and all vendors”.

The Fortune 500 Innovation Forum will convene Fortune 500 executives, U.S. policy officials, top founders, and thought leaders to help define what’s next for the American economy, Nov. 16-17 in Detroit. Apply here.
About the Author
By Andrew Busby
See full bioRight Arrow Button Icon

Latest in Retail

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon
Andrew Busby is Senior Industry Adviser at BOXTEC, Board Adviser at The Industrious and founder of Redline Retail Consulting (formerly Retail Reflections), a retail consultancy firm that provides strategic advice and insights to the industry community.

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Latest in Retail

gamestop
RetailM&A
‘Neither credible or attractive’: eBay slaps down GameStop’s $56 billion takeover bid
By Michelle Chapman and The Associated PressMay 12, 2026
2 days ago
amazon
RetailAmazon
Amazon’s promise of 30-minute delivery collides with memories of Domino’s drivers crashing in the late 1980s
By Anne D'Innocenzio and The Associated PressMay 12, 2026
2 days ago
India’s Gen Z turned Diet Coke into a status symbol. A can shortage just made it a luxury
Asiadiet coke
India’s Gen Z turned Diet Coke into a status symbol. A can shortage just made it a luxury
By Brendan Cosgrove and Morning BrewMay 11, 2026
3 days ago
Content creator Logan Walter
SuccessJobs
This Gen Zer dropped out of college to become an influencer—now he’s a millionaire from selling products like Medicube and Neutrogena on TikTok Shop
By Emma BurleighMay 11, 2026
3 days ago
Investors are betting big on senior housing. There’s just one problem—the baby boomers they’re chasing can’t pay the rent
Real Estatebaby boomers
Investors are betting big on senior housing. There’s just one problem—the baby boomers they’re chasing can’t pay the rent
By Sydney LakeMay 9, 2026
5 days ago
Vincent Clerc speaks in front of a picture of a port.
EnergyShipping
The CEO of Maersk, which ships 14% of everything you buy, said the Iran war is adding $500 million in monthly costs it’s trying not to pass down
By Sasha RogelbergMay 8, 2026
6 days ago

Most Popular

Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that
Success
Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that
By Preston ForeMay 13, 2026
1 day ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
2 days ago
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
Travel & Leisure
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
By Catherina GioinoMay 12, 2026
2 days ago
It’s not just Canadian tourists snubbing U.S. cities. Business leaders are cancelling more trips to America as geopolitical tensions continue
North America
It’s not just Canadian tourists snubbing U.S. cities. Business leaders are cancelling more trips to America as geopolitical tensions continue
By Sasha RogelbergMay 12, 2026
2 days ago
I spent 8 years building Google Sheets. Now I think apps are on their way out
Commentary
I spent 8 years building Google Sheets. Now I think apps are on their way out
By Zach LloydMay 13, 2026
1 day ago
The airplane fuel shortage is a myth propagated by airlines who want to cancel unprofitable flights, says private jet CEO
Energy
The airplane fuel shortage is a myth propagated by airlines who want to cancel unprofitable flights, says private jet CEO
By Jim EdwardsMay 14, 2026
12 hours ago