Expert view: CND’s Andy Cuff on high-profile UK cyber-attacks
With a multi-million turnover, Corsham-based cyber security business Computer Network Defence CND employs 70 staff around the globe.
CEO Andy Cuff established the business in 2004 and has a wealth of experience in the sector, helping clients to protect their systems against cyber-attacks and data breaches.
We asked Andy for his take on the recent high-profile incidents in the UK:
There has been a plethora of high-profile cyber-attacks on the retail sector recently, namely, Co-op, Harrods and M&S. The UK National Cyber Security Centre (NCSC) hasn’t attributed these attacks to a single threat actor.
However, the tactics, techniques and procedures (TTP) appear to align with a threat actor (attacker) known as Scattered Spider, who are native English-speaking attackers. It is understood that they may have used voice calls to the IT help desks requesting password resets for shop staff, which is referred to as social engineering.
Attackers will try to extort money from their victims, and in addition to encrypting computers, they will often download sensitive information such as customer data and threaten to release this if a ransom isn’t paid.
This customer data may be used by the attackers themselves, or if they release it onto the Dark Web, any number of other attackers.
Our advice to affected customers is to consider what information has been shared with the online store and consider changing the data so that it cannot be exploited, such as passwords etc, especially if the same password has been used on several sites. In the case of M&S, they have confirmed that passwords and useable payment information have not been disclosed, which is a great relief, although telephone numbers, addresses and dates of birth have been.
Depending on what information has actually been disclosed, customers should be on their guard for social engineering or phishing attacks, which may be in the form of phone calls or emails. Attackers may attempt to use the information to trick the customer into disclosing additional information or taking control of their computers by visiting other websites.
We would recommend that everyone use multi-factor authentication for as many online services as possible, especially email, banking and social media. Wherever possible, use an authentication app on your phone rather than SMS messaging, as the latter can be intercepted – although SMS authentication is better than nothing!It is also recommended that everyone regularly update their computers and browsers and install a good antivirus product.

