
This article is by Michael Downs, VP, global sales at SecurEnvoy
For UK retailers in 2025, cyber security has shifted from an IT concern to a direct business risk affecting revenue, customer loyalty and operational continuity
Retailers are particularly appealing targets for cybercriminals for a number of reasons. They often have a series of third-party dependencies and legacy systems, and work in fast-paced operating environments – factors that can result in security issues or oversights that provide threat actors with a range of potential entry points.
As a result, the retail sector is now among the three sectors hardest hit by cybercrime, according to Allianz’s analysis of large cyber claims over the past five years.
We’ve recently seen some of the country’s most established retail brands have their stability tested. Late April and early May saw Marks & Spencer, the Co-Operative Group and Harrods all hit by attacks that crippled various business functions, from ecommerce platforms to payment processing.
For threat actors, retailers represent highly monetisable targets. From deploying ransomware and stealing payment data to acquiring and threatening to leak personally identifiable information (PII), there are several routes through which they can apply pressure to targets to benefit financially. The greater the damage that they can inflict on a company, the more likely they are to be able to extort money from it.
The rise of MFA bombing in retail
The recent M&S cyber attack highlighted a technique proliferated by the infamous Scattered Spider hacker collective known as Multi-Factor Authentication (MFA) bombing.
Rather than bypassing technology, MFA bombing exploits the fragilities in the human psyche. Once attackers acquire login credentials through phishing or dark-web purchases, they unleash automated tools to bombard individuals with authentication prompts. In a sector where teams work across stores, warehouses, head offices and third-party environments, the sheer volume of valid users makes this approach especially effective.
Constantly flooding employees with notifications can lead to MFA fatigue, leaving them frustrated and, in turn, more likely to accidentally approve a fraudulent request. In some cases, hackers may also call or message individuals pretending to be IT support to pressure them into approving a login.
All it takes is one accidental approval. A single click can expose payment systems, customer data, and operational platforms – leading to ransom demands, ecommerce outages, regulatory consequences and reputational damage.
Yet, despite the scale of this risk, organisations remain underprepared. The 2025 UK Cyber Security Breaches Survey found that businesses are lagging on multi-factor authentication. Only 40% of businesses have rolled out two-factor authentication (2FA), for example. This is a gap that must be bridged.
Strengthening MFA through multi-layered protection
To counter the rise of MFA-related phishing attacks used by the Scattered Spider group, several national cybersecurity bodies, including CISA, released a joint advisory, outlining key actions for organisations to take.
Aligning closely with established best practices, it includes strong password hygiene, since MFA bombing requires your credentials first, passwords are a critical first line of defence.
User awareness is also equally important; educating and training users to recognise suspicious MFA activity and the risks associated with approving suspicious login requests is therefore important. If an unexpected prompt is received, it’s vital to deny it and report it to the IT department immediately.
Enhanced MFA systems should also be considered. This can include the location of login attempts; the device, operating system and browser used. By combining multiple authentication proof points, MFA can make smarter authentication decisions, flag suspicious logins while enabling legitimate users to proceed without additional verification.
Adopt phishing-resistant MFA – the next level of defence
To further reduce risks, retailers can adopt phishing-resistant MFA that uses cryptography to stop attackers from stealing or intercepting your login credentials, even if they trick you into entering them on a fake website.
By using authentication methods such as FIDO2 security or biometrics, MFA bombing becomes even more difficult to execute. One effective example is origin binding, where credentials are bound to the specific website domain. If you are tricked into trying to log in on a fake phishing site, the cryptographic check will fail automatically, and the credentials cannot be used.
For retailers, going the extra mile has never been more important. When strengthened with adaptive, phishing-resistant technologies, MFA can evolve from a basic security requirement to a strategic enabler. It protects users, protects critical systems, safeguards customer data, reinforces brand trust and supports shareholder value.
Retailers that treat it as business-critical infrastructure will be better prepared to navigate today’s evolving cyber threat landscape.
