• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
RetailSecurity
Europe

Too scared to shop? Why retail is a prime target for criminals

By
Andrew Busby
Andrew Busby
Down Arrow Button Icon
By
Andrew Busby
Andrew Busby
Down Arrow Button Icon
June 5, 2025, 3:58 AM ET
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.
“Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.d3sign via Getty

Harrods, Co-op, Marks & Spencer (M&S) and now Adidas have all experienced damaging cyber attacks in recent weeks, which have sent shock waves through the retail industry. M&S alone has warned of a £300 million ($405 million) hit on profits. The attack, which began over the Easter weekend, also wiped more than £750 million ($1 billion) off its market capitalization.

Recommended Video

On 30th April, the Co-op also fell victim, reporting a few days later that hackers had accessed a “significant” amount of customer data. Then on 2nd May, Harrods also experienced a cyber attack, although in this instance, they managed to prevent any malicious intrusion. 

101

Co-op Group rank on the Fortune 500 Europe

In the M&S incident, third-party service provider Tata Consultancy Services (TCS) has reportedly launched an internal investigation to determine whether it was the gateway by which the hackers gained access.

It all points to a vulnerability amongst retail businesses, despite the fact that the threat from cyber attacks has existed for many years. But why are retail businesses being targeted?

252

Marks & Spencer rank on the Fortune 500 Europe

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage. For malicious actors, access to this data is like gold dust: highly valuable and potentially extremely lucrative” Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team at Kaspersky, told Fortune. 

On 27th May, Adidas became the latest victim of a cyber attack when it reported that, similar to M&S, hackers had accessed customer data through a third-party service provider.

In the case of M&S, according to Vaibhav Chechani, a Mumbai-based analyst at brokerage Nirmal Bang, if the attack did originate from the Indian company, “it will definitely impact their brand image”. TCS also works as a “strategic partner” to Co-op.

“Retailers are prime targets for cybercriminals due to the vast amounts of personal, financial, and other sensitive data they manage…”

Marc Rivero, Lead Security Researcher in the Global Research & Analysis Team, Kaspersky

Rivero commented, “As seen in the M&S attack, social engineering allows attackers to bypass sophisticated cybersecurity measures by exploiting human error. These ‘human hacking’ tactics manipulate users into clicking malicious links, disclosing sensitive information, or granting access to restricted systems”.

“Simply put, data opens doors. It enables fraud, fuels targeted phishing campaigns, and can even be leveraged to infiltrate other businesses within the supply chain. This makes retailers not just lucrative targets, but also strategically valuable within the broader digital ecosystem”. 

M&S CEO Stuart Machin confirmed this, blaming the attack on “human error” rather than a weakness in its cybersecurity measures and added that, “it is a moment in time, and we are now focused on recovery, with the aim of exiting this period a much stronger business. There is no change to our strategy and our longer-term plans to reshape M&S for growth, and if anything, the incident allows us to accelerate the pace of change as we draw a line and move on”.

Despite this optimistic outlook, Retail Technology Magazine publisher and retail expert, Miya Knights, believes that other retailers could also be targeted, believing that those most vulnerable would be “those that have a sizable business with large tier one scale turnover across many channels”.

Speaking to Fortune, she added, “Cybersecurity has been a basic requirement for as long as retailers have deployed IT and transacted online. But, just as e-commerce has become a major growth driver, safeguarding the digital systems they now rely on must become as core to their business as it is for financial services companies.”

This should be the wake-up call that the retail industry needed in order to treat these threats in the same way as financial services institutions. Actions to combat the threat appear to be happening within the industry, with one prominent retail CTO saying that he is collaborating with several other retailers, including some direct competitors, to mitigate the risk of future cyber attacks.

M&S CEO Stuart Machin [blamed] the attack on “human error” rather than a weakness in its cybersecurity measures…

According to Rivero, the retail sector is under mounting pressure from cyber groups persistently probing for vulnerabilities to access large volumes of data. He said that, “Retailers must regularly reassess their cybersecurity strategies and continue to invest in robust defense mechanisms”.

“Retailers must adopt a multi-layered approach to cybersecurity, acknowledging that no single measure can provide complete protection. This approach should begin with staff education. Training employees to recognize phishing attempts and suspicious behavior is critical, with human error remaining one of the most common entry points for attackers”, he continued.

However, it’s not all the responsibility of retailers, Rivero believes that to feel more secure, consumers should take a proactive approach to their digital safety. Regularly update passwords, enable multi-factor authentication where possible, remain cautious of suspicious messages or emails, and monitor financial activity closely, “reporting any unusual behavior immediately”, adding that, “a cautious, informed approach remains the best line of defense”.

His advice to retailers using third-party service providers: “Adopt a proactive approach: regularly conducting thorough risk assessments of all vendors, enforcing strict access controls, and requiring regular security audits. Ongoing employee training is also essential – not just for non-IT staff, but also for IT teams, who are frequently targeted by social engineering tactics”.

And as he puts it, “In a landscape where cybercriminals exploit every weak link, resilience must extend beyond the organization itself to encompass the entire supply chain and all vendors”.

The Fortune 500 Innovation Forum will convene Fortune 500 executives, U.S. policy officials, top founders, and thought leaders to help define what’s next for the American economy, Nov. 16-17 in Detroit. Apply here.
About the Author
By Andrew Busby
See full bioRight Arrow Button Icon

Latest in Retail

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon
Andrew Busby is Senior Industry Adviser at BOXTEC, Board Adviser at The Industrious and founder of Redline Retail Consulting (formerly Retail Reflections), a retail consultancy firm that provides strategic advice and insights to the industry community.

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Latest in Retail

C-SuiteFood and drink
‘I didn’t want anybody shooting me’: Five Guys CEO gave away $1.5 million bonus to employees over botched BOGO burger birthday celebration
By Catherina GioinoMarch 25, 2026
58 minutes ago
Brian Niccol speaks and gestures in front of a blue and green background.
C-SuiteStarbucks
Starbucks CEO admits the chain ‘ran like a manufacturing facility’
By Sasha RogelbergMarch 23, 2026
2 days ago
Toilet paper on empty supermarket shelves, lockdown panic buying
EconomyIran
The great toilet paper panic is back as Japan starts stockpiling
By Eva RoytburgMarch 23, 2026
2 days ago
RetailCostco
Costco CEO promises the $1.50 hot dog isn’t going away: ‘The price will not change as long as I’m around’
By Sydney LakeMarch 21, 2026
4 days ago
AsiaPepsiCo
Three Asias, three different playbooks: How PepsiCo’s Anne Tse views the world’s fastest-growing snack market
By Nicholas GordonMarch 20, 2026
5 days ago
A man walks between two luxury cars with the skyline of Dubai in the background.
RetailLuxury
The Middle East is one of the world’s fastest growing luxury markets—and the war in Iran may cut its sales in half, analysts say
By Sasha RogelbergMarch 20, 2026
5 days ago

Most Popular

Magazine
The youngest-ever female CEO of a Fortune 500 company is fighting Trump's cuts to keep Medicaid strong
By Fortune EditorsMarch 24, 2026
2 days ago
Commentary
The Treasury just declared the U.S. insolvent. The media missed it
By Fortune EditorsMarch 23, 2026
2 days ago
Success
Palantir’s billionaire CEO says only two kinds of people will succeed in the AI era: trade workers — ‘or you’re neurodivergent’
By Fortune EditorsMarch 24, 2026
1 day ago
Energy
Nobel laureate Paul Krugman calls it 'treason': $580 million in suspicious oil futures traded minutes before Trump's Iran reversal
By Fortune EditorsMarch 24, 2026
1 day ago
Success
The job market is so bad that ‘reverse recruiters’ are charging $1,500 a month just to help people look for jobs
By Fortune EditorsMarch 25, 2026
13 hours ago
Success
JPMorgan has started monitoring the keystrokes, video calls, and meetings of its junior investment bankers—and they say it's for employee well-being
By Fortune EditorsMarch 24, 2026
1 day ago