Executive Summary
The first half of 2025 has seen a significant surge in cyber attacks targeting well-known brands including Marks & Spencer, Harrods, and Qantas. These incidents, involving advanced ransomware-as-a-service (RaaS) groups such as DragonForce, are not isolated. They signal a growing, sophisticated threat landscape where no organisation, regardless of size or sector, is off limits.
This article explores why these attacks are happening, what they reveal about the modern cyber threat environment, and what practical steps organisations must take to protect themselves and their customers. It’s written not for the tech-savvy, but for business professionals across departments who want to understand what’s going wrong, what’s at stake, and how organisations can prepare.
The Landscape Has Changed
Cyber security is no longer just a concern for large financial institutions or tech companies. In 2025, traditional retail, hospitality, and logistics businesses are now prime targets for threat actors. In recent weeks, Harrods suffered a cyber breach that forced them to restrict internet access across their business. Marks & Spencer experienced a ransomware attack so severe that it disabled online trading for weeks. Qantas, the Australian airline, also confirmed a compromise linked to a broader turf war between cyber criminal groups.
These incidents point to a significant trend: attackers are becoming more organised, more financially motivated, and more persistent. They are not simply opportunistic hackers, but part of an industrialised ecosystem of cyber crime.
Why Are These Attacks Happening?
The primary motive behind these attacks is financial gain—data is a highly valuable commodity. Modern threat actors are often not lone individuals, but syndicated groups selling ransomware toolkits and access to compromised networks. The model is disturbingly efficient.
In many of the recent breaches, attackers targeted the supply chain or impersonated third-party contractors. For instance, in the case of M&S, investigators believe the hackers gained access through a trusted vendor, then deployed ransomware that crippled both the front-end ecommerce platform and back-office systems.
These attackers aren’t necessarily interested in the contents of a single customer’s order. They are after much more:
- Customer PII (personally identifiable information)
- Payment data
- Employee login credentials
- Operational data that can be resold or used to extort
Once inside a network, they often move laterally, quietly escalating privileges until they control systems that, if encrypted or erased, would bring operations to a halt. Then comes the ransom demand—often with threats to publish data unless paid.
Are Small and Medium-Sized Businesses at Risk?
Absolutely. The myth that cyber attackers only pursue large, global brands is no longer supported by evidence. Smaller businesses are often considered easier targets due to limited budgets, understaffed IT teams, or a lack of formal cyber security policy.
Furthermore, small businesses increasingly serve as stepping stones into larger corporate ecosystems. A compromised small vendor can provide attackers with access to more lucrative targets. This ‘island hopping’ strategy is now commonplace.
What Do These Attacks Reveal About the State of Business IT?
Several common issues have emerged:
- Legacy systems remain widespread, often unsupported or unpatched, making them prime entry points.
- Lack of segmentation means attackers can move freely once inside.
- Poor visibility over user activity and data flows makes detection and response difficult.
- Over-reliance on cyber insurance can create a false sense of security, especially as insurers begin to limit payouts or require higher standards of resilience.
The core problem is that many businesses still view cyber security as an IT-only problem. In reality, it’s a business-wide risk issue—akin to financial compliance or health and safety.
What Can Organisations Do?
Protecting your organisation from today’s dynamic threat landscape doesn’t require a seven-figure budget—but it does demand vigilance, discipline, and a strong commitment to cybersecurity best practices. Based on recent incidents, the following actions are essential:
- Assess Third-Party Risk
Ensure all vendors and partners adhere to minimum cybersecurity standards. Limit their access to only what’s necessary and continuously monitor their activity. - Modernise Legacy Infrastructure
Retire or isolate systems that are no longer supported by vendors. Unsupported technology is a common entry point for attackers. - Enforce Multi-Factor Authentication (MFA)
Apply MFA across all accounts, including internal systems, cloud platforms, and remote access tools. This is one of the most effective defences against credential-based attacks. - Segment and secure
Prevent attackers from moving laterally by implementing strong network and device access controls. - Test Disaster Recovery and Incident Response Plans
Operate under the assumption of compromise. Regularly rehearse your ability to restore operations quickly and effectively under pressure. - Educate and Empower Employees
Human error remains a leading cause of breaches. Provide ongoing training to help staff recognise phishing attempts, use strong passwords, and avoid unauthorised software.
While no single solution guarantees immunity, businesses that plan and prepare fare significantly better than those that react only once breached.
The Role of Leadership
Ultimately, cyber resilience must be led from the top. Board members, directors, and business leaders must understand that investment in IT security isn’t just about prevention—it’s about maintaining operational continuity, protecting brand reputation, and honouring customer trust.
The lesson from M&S and others is clear: even the most established businesses can be brought to their knees by a single digital compromise. But equally, organisations that prepare can recover quickly and avoid the worst-case scenarios.
Closing Thoughts
Cyber attacks in 2025 are not abstract, distant events. They are happening right now, across sectors, and often within companies with familiar names. But they also happen quietly, to companies that go unreported, with consequences that include lost revenue, reputational damage, regulatory fines, and prolonged downtime.
As organisations move further into cloud-first, hybrid, and digitally reliant models, the need for secure, efficient IT foundations has never been greater. Protection isn’t a luxury, it’s the cost of doing business in a connected world.




