Understanding the Aftermath of Cyber Attacks: Lessons for Marks & Spencer and Other Businesses
As Marks & Spencer (M&S) grapples with the impact of a major cyber attack, it is not alone in facing the challenges that arise when hackers target businesses. Other organizations that have endured similar attacks are sharing their experiences, offering valuable insights into the disruptive nature of cybercrime and how to respond effectively.
A Personal Account of Cyber Extortion
Sir Dan Moynihan, who runs the Harris Federation, a group of 55 schools across London and Essex, recalls the chaos his organization faced after falling victim to a ransomware attack four years ago. The cybercriminals behind the attack were part of the notorious Russian ransomware group, REvil. Their demand? A staggering $4 million (£3 million) in cryptocurrency, to be paid within 10 days.
“If we didn’t pay in 10 days, they wanted $8 million,” Sir Dan explained in a BBC interview.
The attack wreaked havoc on the school group’s operations. Financial systems were crippled, leaving staff salaries and bills unpaid. The disruption also extended to vital academic and administrative systems, with lesson plans, teaching materials, and even medical and fire records all being compromised.
Resisting the Ransom Demand
Facing the potential loss of sensitive data and ongoing disruptions, Sir Dan chose not to give in to the hackers’ demands. Instead, the Harris Federation sought the help of cyber specialists, who enlisted a hostage negotiator. The negotiator adopted the persona of an inexperienced school bursar, pretending not to understand the gravity of the situation, in an attempt to stall the hackers and buy time for the school group to rebuild its systems.
“They [the hackers] threatened to put this stuff up on the dark web and cause us great embarrassment, and secondly they would lock down our systems,” Sir Dan explained on BBC Radio 4’s Today programme.
Ultimately, the Federation managed to restore its systems after three months of intense recovery efforts, costing £750,000. The process involved cleaning 30,000 affected devices.
Was there ever a thought of paying the ransom? Sir Dan was adamant: “The money we have is for disadvantaged young people, and secondly had we paid, we would have opened the door for other school groups to be attacked.”
Personal Impact: A Business’s Digital Nightmare
The consequences of cyber attacks are not confined to large organizations. For smaller businesses, the impact can be just as devastating. Wedding dress designer Catherine Deane shared her experience of having her company’s Instagram account hacked. As a business heavily reliant on social media for marketing, the breach was deeply disruptive.
“It felt like the rug had been pulled from under us. Instagram is our primary social platform, and we’ve invested the most amount of time and business resources into it,” Catherine said.
The challenge of resolving the issue with Instagram’s parent company, Meta, proved to be “almost traumatising,” Catherine revealed, as her business struggled to regain control of its social media presence.
A Ripple Effect Across the Healthcare Sector
Cyber attacks on essential services, such as healthcare, can have severe consequences, as witnessed by the ransomware attack on pathology firm Synnovis in June of the previous year. This attack led to critical disruptions in hospital services, including blood transfusions at Guy’s and St Thomas’ Hospital and King’s College Hospital in London.
Dr. Anneliese Rigby, a consultant anaesthetist at KCH, described the challenges faced by staff, explaining that they had to manually process blood samples, a time-consuming task that required additional personnel. “We’re having to get extra people to help with that,” she said, highlighting the strain placed on already limited resources.
M&S Faces Ongoing Disruptions
As M&S continues to deal with the fallout from its cyber attack, it has been cautious with the information it releases publicly, offering limited details and not making any officials available for interviews. However, employees on social media, some of whom have identified themselves as M&S workers (though not verified by the BBC), have shared their experiences.
According to one employee, most of the company’s internal systems were impacted, and staff resorted to “resuming operations manually with paper and pen.” Another commenter likened the experience to “going back in time” as the organization faced the overwhelming task of recovering from the attack. Employees have also reported issues like shortfalls in stock and food waste due to overstocking.
Cybersecurity: A Growing Concern for Businesses
M&S is not the only retailer facing these challenges. The Co-op recently had to shut down several of its IT systems in response to a separate cyber attack, demonstrating the growing concern over the vulnerability of businesses to cybercrime.
“We’re patching like mad,” one retailer told the BBC, referring to efforts to update software and strengthen defenses against cyber threats.
Sir Charlie Mayfield, former chairman of John Lewis, emphasized the growing threat, noting that the increasing reliance on technology for online shopping makes businesses more susceptible to cyber attacks. “As technology becomes more pervasive, the risk of this kind of attack rises with it,” he explained.
Rising Threats: Statistics on Cyber Attacks
The scale of the threat is underscored by data from the UK government’s Cyber Security Breaches Survey, which found that 74% of large businesses reported being targeted by cyber attacks in the previous year. This statistic paints a clear picture of the widespread nature of cybercrime and its increasing prevalence in the digital age.
For M&S and other companies, it seems that the road to recovery will be a long one. But the lessons learned from other organizations, such as the Harris Federation and others, offer valuable insights into how businesses can respond to and recover from such attacks.
Additional reporting by Zoe Kleinman, Chris Vallance, Joe Tidy, and Tom Gerken.






0 Comments