Lessons for London SMEs from the Recent High-Profile UK Cyber Breaches

The cyber incidents that disrupted M&S, Co-op and Harrods in 2025 showed that even well-funded organisations can suffer serious operational and financial damage. M&S’s 2025/26 results recorded £131.3 million of incident-related costs and £100 million of insurance proceeds. Co-op estimated that its attack reduced sales by £285 million and affected its bottom line by £86 million. A separate Harrods supplier breach disclosed in September 2025 affected about 430,000 customer records, although Harrods said its own systems were not compromised and no passwords or payment details were taken.

For London SMEs, the lesson is that weaknesses in identities, suppliers and incident response can quickly interrupt trading, expose information and damage trust.

What the 2025 attacks showed

Public reporting connected the retail incidents with ransomware and social engineering, but the precise initial access route used against M&S has not been officially confirmed. The National Cyber Security Centre noted speculation about attackers manipulating IT helpdesks into resetting passwords or multi-factor authentication.

On 10 July 2025, the National Crime Agency arrested 4 people aged 17 to 20 in connection with attacks targeting M&S, Co-op and Harrods. The arrests were made on suspicion of offences including computer misuse, blackmail and money laundering. An arrest is not proof of guilt.

The September Harrods incident highlights a separate risk: customer data can be exposed through a third-party provider even when the organisation’s own network is not breached.

Risk exposed Practical lesson
Social engineering Verify identities before password or MFA resets
Stolen credentials Use MFA, monitor unusual logins and disable dormant accounts
Ransomware Maintain tested backups and a recovery process
Supplier compromise Limit vendor access and assess suppliers before sharing data

The current UK risk picture

The Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses identified a breach or attack in the previous 12 months, equivalent to approximately 612,000 UK businesses. Phishing affected 38% of all businesses and 88% of businesses that had identified any breach or attack.

The survey does not support the claim that an average small-business breach costs more than £25,000. The median perceived cost of the most disruptive incident was £0, while the 95th-percentile figure for micro and small businesses was £4,000. Most incidents are contained cheaply, but a small number create severe losses.

What London SMEs should do now

Start by controlling identities. A managed IT support company in London can help enforce MFA, remove unused accounts and monitor suspicious sign-ins. Dark web monitoring services in London may identify exposed credentials, but they should support strong passwords and MFA. Review what to do if company credentials appear on the dark web and reset affected credentials promptly.

Train people continuously. Anti-phishing testing in London and regular phishing simulations can help staff recognise suspicious password resets, payment changes and executive impersonation.

Review third parties and cloud services. Give suppliers only the access they need, remove it when contracts end and agree incident-notification responsibilities.

Check whether your business has Cyber Essentials accreditation and maintain a tested business continuity plan covering the first 24 to 72 hours. Business managed IT support services should include monitoring, secure backups, patching and recovery planning, not only reactive troubleshooting.

Frequently asked questions

Are SMEs genuinely targeted?

Yes. Cyber criminals target organisations of every size. The survey found that 46% of small businesses identified a breach or attack.

What is dark web monitoring?

Dark web security monitoring searches known criminal sources for exposed business credentials or data. It can provide an early warning, but it cannot guarantee every leak will be found.

What should we prioritise?

Use MFA, strengthen helpdesk verification, patch systems, restrict supplier access, test backups and rehearse an incident response plan.

Concerned about your current exposure? Get in touch with Northern Star for a practical review based on your business size, systems and risk.