The retail sector isn’t ready for the next scattered spider attack, but it could be says Simon Pamplin

The ransomware group known as Scattered Spider has already left a deep mark on the retail sector, with disruptive attacks on high-profile organizations such as Marks & Spencer and the Co-Op. But retail was never the group’s only target. It deliberately focused on critical service providers and third-party suppliers connected to these businesses, understanding that supply chains often provide the easiest route in.

What made Scattered Spider particularly effective was its ability to exploit people and processes: the group specialized in social engineering, impersonating help desk staff, carrying out SIM swapping, and manipulating multi-factor authentication (MFA) resets. Their objective was simple. They did not need to break through technical defenses. They just logged in using legitimate credentials.

Once inside, they could move quietly through systems, accessing sensitive data and disrupting operations with alarming speed.

More of the same, but more efficient

Over the past year, Scattered Spider has not fundamentally changed its methods, but instead, the group has become more efficient. Its operators refined their ability to impersonate staff convincingly, exploit trust and move laterally inside networks using valid credentials. They executed familiar tactics faster and more aggressively, taking advantage of the fact that many organizations still depend heavily on perimeter controls and identity verification as their primary line of defense.

Law enforcement activity has disrupted parts of the group, but it has not halted its operations. Its decentralized structure makes it difficult to dismantle entirely, and its reliance on human manipulation rather than complex malware means its methods remain hard to block.

For retailers, this should be a sobering reality.

The real lesson retail must learn

The fallout from retail attacks was severe. Millions were lost, and operations were disrupted for weeks. Customer trust was understandably shaken. Yet despite this, many organizations have responded by rein-forcing the same controls that failed in the first place.

There has been a focus on tightening access management, retraining staff and improving detection. These are important steps, but they miss a more fundamental issue.

In each case, the attackers did not break through security systems; they used them exactly as intended. The perimeter remained intact and the authentication checks passed, yet the data was still lost.

an abstract digital artwork depicting a cosmic light vortex or tunnel

This highlights a difficult truth. Most retail security strategies are still designed to protect systems rather than the data those systems hold. As long as data remains accessible and readable once attackers gain entry, the damage will always be severe.

Why data protection changes the outcome

Consider the widely covered incident at Marks & Spencer. Attackers reportedly entered through a third-party supplier, triggering over £300 million in losses and operational disruption lasting weeks. Even if that initial compromise had still happened, the outcome could have been very different if the data itself had been protected. Customer records, financial information and operational data would have been inaccessible and unusable.

The same applies to the Co-Op incident. Their response limited operational damage, but any accessible data would still have represented a valuable asset for attackers.

This is why the focus must shift. Protecting access is no longer enough. Retailers must protect the value attackers are seeking.

A data-centric approach, such as Data Protection and Risk Mitigation (DPRM) applies persistent encryption and strict policy controls directly to the data. This means that even if attackers gain access to systems, the information they find cannot be used against the organization.

It is like storing your most valuable assets inside a vault encased in 12 inches of solid steel. An intruder might break into the building and even haul the vault away, but without the key, they cannot see or use what is inside. All they are left with is a heavy, useless container. In the same way, quantum-safe encrypted data without the proper keys holds no practical value to an attacker.

When stolen data has no value, the ransomware business model begins to break down.

The stakes are higher than ever

There is also a growing regulatory dimension that retailers cannot ignore. Under frameworks such as GDPR, DORA and NIS2, organizations are expected to demonstrate that they are protecting sensitive data properly. Failure to do so carries not just financial penalties but legal and executive consequences.

This shifts cybersecurity firmly into the boardroom.

The threat is still active

Perhaps the most important point is this. Scattered Spider has not gone away.

The group has broadened its focus beyond retail into sectors such as aviation, transport, technology providers and managed service providers. It continues to exploit the same weaknesses, targeting organizations where trust in identity and network location still determines access.

And it is watching closely.

Attackers understand that many organizations struggle to change entrenched security models. They rely on that hesitation.

A different future is possible

Retailers do not need to accept this cycle of breach, disruption and recovery.

The path forward requires a shift in thinking. Security must be designed on the assumption that attackers will eventually get in. The priority must be ensuring they gain nothing of value when they do.

This means protecting data directly, reducing reliance on perimeter controls and ensuring sensitive information remains unreadable and unusable under all circumstances. When attackers cannot monetize stolen data, their incentive disappears.

The way forward requires a critical shift in thinking. Retailers need to accept that attackers may eventually get in, and design security so that when they do, they find nothing of value. That means protecting the da-ta itself, not just the systems around it, ensuring sensitive information always remains unreadable and un-usable. When stolen data cannot be monetized, the attacker’s leverage disappears and the damage can be contained.

The next attack is not a question of if, but when. The methods are already known. The vulnerabilities are understood. What remains is a choice. Retailers can continue relying on the same approaches and hope for a different outcome. Or they can adopt a strategy that makes their data worthless to attackers.

Only one of those options changes the ending.

Simon Pamplin

certes.ai

Simon Pamplin is CTO at Certes. Certes provides Data Protection and Risk Mitigation solutions that secure data in transit across cloud, physical and virtual environments. By protecting the data itself rather than re-lying solely on infrastructure defenses, Certes helps organizations reduce risk, support compliance and retain control of their most valuable information.