M&S, Co-op, JLR and ASOS: what the UK’s biggest cyber attacks teach a small business
Short answer: the M&S cyber attack, the Co-op cyber attack, the Jaguar Land Rover shutdown and now the ASOS data breach all happened within eighteen months. None of those businesses was short of money or IT staff. Look at how they were hit and the same few patterns keep coming up: a person talked into resetting a password, a third party with a way in, and weeks of disruption that cost far more than any ransom. Every one of those patterns applies to a business of five or fifty people, and the fixes for a small firm are cheap.
Want to know how your business would stand up to the same tricks? Ring 0151 452 3060 and a person picks up, or start with the Free Cyber Health Check: six questions and a written fix list.
The four cyber attacks at a glance
| Who and when | How it started | What it cost | Customer data |
|---|---|---|---|
| M&S, April 2025 | “Sophisticated impersonation” that also involved a third party (M&S chairman, to MPs); widely reported as a password reset requested from an outside service desk | About £300m off operating profit before insurance; online orders paused for weeks | Personal data taken; not usable payment details or passwords |
| Co-op, April 2025 | Reported: staff impersonated to the IT help desk | £206m in lost sales and £80m off half-year profit (Co-op’s results) | All 6.5 million members’ names, contact details, addresses and dates of birth; not passwords or bank details |
| Jaguar Land Rover, Aug to Oct 2025 | Not disclosed | More than five weeks without full production; up to £1.5bn government-backed loan guarantee; £1.9bn estimated cost to the UK economy | Not the main story: the damage was the shutdown |
| ASOS, October 2026 | Not disclosed; unauthorised activity on third-party platforms used to message customers | Too early to say; shares fell as much as 15% on the day (Bloomberg) | Names and contact details may have been accessed; not card details or passwords, per ASOS |
The M&S cyber attack: one phone call to a help desk
What happened. In April 2025, M&S was hit by an attack that stopped online orders, disrupted stores and took systems offline. Its chairman, Archie Norman, later told the Business and Trade Committee that the initial entry on 17 April came through “sophisticated impersonation”, and that “part of the point of entry in our case also involved a third party”. It was widely reported that the attackers posed as an M&S employee and got an outside service desk to reset a password.
What it cost. In its full-year results in May 2025, M&S said it expected a hit of around £300 million to operating profit before insurance and other mitigations. It also confirmed customer personal data had been taken, though not usable payment details or passwords. In July 2025 the National Crime Agency arrested four people over the M&S, Co-op and Harrods attacks.
What it means for a small business. No software was “hacked” at the front door. A person was convinced over the phone. Small businesses reset passwords all the time, usually by ringing the IT provider or asking the one person who knows the admin login. So the question is simple: if someone rang your IT support pretending to be you, what would they have to prove before your password was reset or your two-step sign-in removed?
The Co-op cyber attack: the decision that limited the damage
What happened. Days after M&S, the Co-op found attackers in its network. It was widely reported that they too got in by impersonating staff to the IT help desk. The Co-op took parts of its own IT offline to stop them, which left gaps on shelves and problems with payments for a while. Its chief executive later confirmed the attackers had taken data on all 6.5 million members: names, contact details, addresses and dates of birth, but not passwords, bank or card details.
What it cost. The Co-op’s half-year results put the hit at £206 million in lost sales and £80 million off operating profit. The attackers themselves complained to journalists that the Co-op “yanked their own plug” before they could encrypt its systems. Painful as the shutdown was, it’s widely seen as the reason the Co-op avoided something worse.
What it means for a small business. Somebody had the authority, and the nerve, to switch things off fast. In a small firm, that decision usually falls to whoever’s in the office. Decide now who’s allowed to say “unplug it”, and make sure they know they won’t be blamed for doing it.
The JLR cyber attack: when the business stops, so do the suppliers
What happened. Jaguar Land Rover was hit at the end of August 2025 and shut down its systems, stopping production from 1 September at sites including its Halewood plant on Merseyside. Vehicle production didn’t begin a phased restart until early October, more than five weeks later. JLR hasn’t said publicly how the attackers got in.
What it cost. The government backed a loan guarantee of up to £1.5 billion to give JLR’s supply chain certainty, amid fears that suppliers, including small businesses, could go under. The independent Cyber Monitoring Centre estimated the total cost to the UK economy at £1.9 billion. It said the JLR cyber attack “appears to be the most economically damaging cyber event to hit the UK”, and that up to 5,000 organisations in JLR’s supply chain may have been affected.
What it means for a small business. Many of the hardest-hit businesses weren’t JLR at all. They were small suppliers whose biggest customer stopped ordering overnight. If you rely on one or two large customers, their cyber security is your cash flow. And if you’re the supplier, expect them to start asking about yours: our guide to when your customers check your cyber security covers what they’ll ask.
The ASOS data breach: a message the company didn’t send
What happened. On 6 October 2026, ASOS app users received a push notification from attackers, addressed to the company’s data protection officer, claiming to hold customer data. In a statement to the stock exchange, ASOS said it was investigating unauthorised activity on third-party platforms it uses to message customers, and that names and contact details may have been accessed, but not card details or passwords. How the attackers got in hasn’t been disclosed. The detail is in our write-up of the ASOS data breach.
What it means for a small business. The website and checkout weren’t the way in. A tool used to talk to customers was. Every small business has those: email marketing, invoice reminders, booking confirmations. Anyone with the login can message your customers as you.
The same protections, sized for a small office
Multi-factor sign-in on every account. Alerts and automatic lock-out when an account is used from somewhere it shouldn’t be. Email filtering and short phishing practice for your team. Backups that are tested by restoring them. It’s all in our managed IT support at £55 a person a month, and moving to us takes a week with nothing for your team to prepare.
What the four cyber attacks have in common
- People, not code. At M&S the first step was what its chairman called “sophisticated impersonation”, and at the Co-op it was reportedly a convincing call to the help desk. After the retail attacks, the NCSC urged organisations to review how their help desks check who they’re talking to before resetting passwords. DSIT’s 2025 survey found phishing was involved in 85% of the attacks UK businesses identified, and help-desk impersonation is the same trick by phone.
- Somebody else’s door. M&S’s way in involved a third-party service desk. ASOS’s involved third-party messaging platforms. JLR’s suppliers were hurt by somebody else’s attack. Your security includes everyone who can reach your systems or depends on them, which is the theme of our three real supply chain attacks.
- Disruption costs more than data. The big numbers came from weeks of lost trading: no online orders, no stock, no cars. For a small firm, a week without email or the accounts system can do the same damage in proportion.
- The data comes back as phishing. Names and contact details from M&S, the Co-op and ASOS are exactly what criminals need for believable follow-up emails and texts, to your staff as much as anyone.

Seven things a small business can do
- Agree how your IT support checks it’s really you. Before any password reset or two-step sign-in change, they should ring you back on a number they already hold, or check something an impersonator wouldn’t know. Ask them what they do today.
- Turn on two-step sign-in everywhere, starting with admin accounts and email. DSIT found only 40% of businesses use it on email.
- Get told when an account is misused. A sign-in from an unexpected country, a new forwarding rule, an admin change at 2am: those should raise an alert, and ideally lock the account automatically.
- List your third parties. Who can log in to your systems, who holds your data, and which tools can message your customers. Our guide to checking your suppliers has the questions to ask, and managing supplier access covers the logins.
- Prove your backups. Restore a file from them this month, and keep a copy where ransomware can’t reach it. A backup nobody has tested is a hope, not a plan.
- Decide who can pull the plug, and write a one-page plan: who decides, who tells customers, who tells the ICO (within 72 hours if personal data’s involved) and who rings the insurer. Our business continuity page covers keeping working while it’s fixed.
- Warn your team after every headline breach. The follow-up phishing is predictable. A two-minute word at a team meeting costs nothing.
What a cyber attack costs a small business
The headline figures are in the hundreds of millions because the businesses are huge. For a small firm, the government’s Cyber Security Breaches Survey 2025 put the average cost of the most disruptive breach at £8,260, and 43% of UK businesses reported a breach or attack in the previous year. That’s enough to hurt a ten-person business badly, and it’s far more than the basics cost.
Most of the list above is habits and settings rather than software. Our cyber security guide for small businesses covers the five controls that stop most attacks. If you hold cyber insurance, our guide to cyber insurance requirements shows what the insurer will ask you to prove.
M&S, Co-op, JLR and ASOS cyber attacks: questions people ask
How did the M&S cyber attack happen?
M&S’s chairman told MPs that the initial entry on 17 April 2025 came through “sophisticated impersonation” and also involved a third party. It was widely reported that the attackers posed as an employee and got an outside service desk to reset a password.
How much did the M&S cyber attack cost?
M&S said in May 2025 that it expected a hit of around £300 million to operating profit, before insurance and other mitigations.
What happened in the Co-op cyber attack?
In April 2025 the Co-op found attackers in its network and took parts of its IT offline to stop them, which disrupted stores. Data on all 6.5 million members was taken. Its half-year results put the cost at £206 million in lost sales and £80 million off operating profit.
How much did the JLR cyber attack cost?
The Cyber Monitoring Centre estimated the cost to the UK economy at £1.9 billion. The government backed a loan guarantee of up to £1.5 billion to protect JLR’s supply chain.
What happened in the ASOS data breach?
On 6 October 2026, attackers sent a push notification to ASOS app users. ASOS said it was investigating unauthorised activity on third-party platforms it uses to message customers, and that names and contact details may have been accessed, but not card details or passwords.
What can a small business learn from these cyber attacks?
Agree how your IT support verifies you before resetting a password, turn on two-step sign-in everywhere, get alerts when an account is misused, list the third parties with access, prove your backups, decide who can switch things off, and warn your team after every headline breach.
Written by Eric Lonsdale
I’ve spent twenty years securing systems for hospitals, government and national infrastructure, and now I look after small offices across Liverpool, the Wirral and Cheshire. We work to the NCSC’s frameworks and run to Cyber Essentials standards, and new clients are Secured in 7 Days, or that month is on us.
Start with the help-desk question. Ring Eric this week on 0151 452 3060 and we’ll go through how your password resets, sign-ins and backups would hold up against the tricks that caught M&S and the Co-op. Or start with the Free Cyber Health Check: six questions, a written fix list.
Sources
- House of Commons Business and Trade Committee, oral evidence from M&S, July 2025.
- Marks and Spencer Group plc, full-year results announcement, May 2025.
- National Crime Agency, “NCA arrest four for attacks on M&S, Co-op and Harrods”, July 2025.
- Co-op Group, interim results, 25 September 2025.
- TechRadar, “Data of all 6.5 million Co-op members stolen”, July 2025; Computer Weekly, “Co-op shuts off IT systems to contain cyber attack”; TechRepublic, “They yanked their own plug”.
- Jaguar Land Rover, statement on cyber incident, September 2025.
- Department for Business and Trade, “Government backs Jaguar Land Rover with £1.5 billion loan guarantee”, September 2025.
- Cyber Monitoring Centre assessment, 22 October 2025, as reported by Prolific North.
- ASOS plc, “Update regarding cyber incident”, 6 October 2026; Bloomberg via Insurance Journal, 6 October 2026.
- National Cyber Security Centre, “Incidents impacting retailers: recommendations from the NCSC”, May 2025.
- Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025.
Facts as at 7 October 2026. We’ll add to this page as new incidents and details come out.
