Cybercriminals are shifting their sights. No longer are their attacks limited to banks and governments sectors. Retail and aviation are now firmly in the firing line and it’s changing all the time.
From household names on the high street to global airlines, recent cyberattacks have exposed the evolving tactics used by threat actors and the growing vulnerabilities across industries.
This article explores who’s being targeted, how, and what Business & IT leaders must do to stay ahead.
From Casinos to Retail to Airlines: The Sector Shift
It started with casinos. In late 2023, MGM and Caesars were hit hard, with claims of 6 terabytes of data stolen and $15 million reportedly paid in ransom. The attackers were said to have exploited a third-party IT provider via social engineering, showing just how easily human error can bypass technical safeguards.
Then the focus shifted. Retail giants including Marks & Spencer, Co-op and Harrods were next. While some responded quickly and limited the damage, others suffered losses in the hundreds of millions. Now, the airline industry is under siege, with Qantas and even Aeroflot reporting breaches.
The pattern is clear: cybercriminals are going after sectors with:
- Large customer databases
- High-value transactions
- Critical operational systems
- Less mature cybersecurity compared to regulated industries
Who’s Behind It?
There are two key groups thought to be behind many of these attacks:
- Scattered Spider: A loose group of Western, mostly teenage hackers, fluent in English and experts in social engineering. They impersonate IT staff or employees and trick service desks into giving access.
- DragonForce: A politically motivated group, offering “ransomware-as-a-service” and infrastructure to others on the dark web. Often linked to state-aligned or hacktivist operations.
Together, they use a “double extortion” model, stealing data and encrypting systems, then demanding ransom payments not just to restore access but to avoid public leaks.
The M&S Example: A Cautionary Tale
One of the most revealing cases involved Marks & Spencer. The attackers are said to have impersonated an employee and convinced the service desk (run by a third party) to reset a password. No malware. No phishing email. Just one convincing phone call.
From there, the attackers moved laterally, exploited Active Directory, and encrypted key systems supporting e-commerce, logistics, and payments, knocking out online orders and contactless payments.
This is how modern attacks bypass even sophisticated defences: by exploiting the human layer.
What Can You Do?
Here are the key takeaways for Business & IT leaders:
1. Don’t underestimate social engineering
- Most successful breaches start with a simple human mistake.
- Train all staff, especially those on the service desk, to spot suspicious requests, and use out-of-band verification processes.
2. Review your out-of-hours procedures
- Many attacks happen when defences are down or internal staff are offline.
- Make sure identity verification is robust 24/7, not just during office hours.
3. Embrace phishing-resistant multi-factor authentication
- SMS-based MFA or email codes are increasingly vulnerable.
- Use authentication apps, passkeys, or biometric verification wherever possible.
4. Limit privileged access with Just-In-Time administration
- Give admin rights only when needed and only for as long as required.
5. Monitor your logs like a hawk
- Real-time monitoring of identity and access logs (via SIEM platforms like Splunk) helps detect unusual behaviour before it becomes a breach.
6. Backups are your last line of defence
- Ensure regular, secure backups are in place and tested. If attackers strike, you need a fast recovery plan.
Final Thought: It’s Not “If”, It’s “When”
With cyberattacks probing public-facing systems within minutes of going live, and malicious emails hitting inboxes every hour, it’s never been more critical to take a proactive stance.
Cybercriminals are getting smarter. Your defences and your team need to be smarter too.
Ready to Strengthen Your IT Defences?
At IT Naturally, we help all our customers put in place a clear set of minimum security standards to reduce risk from day one. We support businesses through Cyber Essentials and Cyber Essentials Plus certification and for those looking to go further, we offer advanced protection for a more robust security posture.
Whether you want to meet compliance standards or take your cyber maturity to the next level, we’ll work with you to minimise the risk of attacks that could damage your reputation and your bottom line.
The smartest way to protect your business is to start now.
Download our free guide — How to Get Compliant & Cyber Smart: The Security Playbook Every Growing Business Needs — and discover the 10 steps we use to help our customers secure their IT, protect their reputation, and stay ahead of evolving cyber threats.
[Get the Guide]
Prefer to talk it through? Call Richard, our CEO, for a no-pressure chat about where to start and what your cybersecurity journey could look like, all of course tailored to your business.