Google warns that British retail attackers are setting their sights on the United States
Google noted that actors linked to attacks against British retailers were turning their attention towards US companies, highlighting their use of social engineering techniques.

News summary
Google noted that actors linked to attacks against British retailers were turning their attention towards US companies, highlighting their use of social engineering techniques.
Security cannot rely solely on tools. Training, support processes, identity verification and rapid response are fundamental when attackers seek to deceive people.
Source: Reuters — 14 May 2025
What happened
In May 2025 Google said that actors linked to attacks on major British retailers, such as Marks & Spencer and Co-op, were shifting their focus towards US companies, and highlighted the use of social engineering as their main entry method.
According to Google, the usual pattern involved impersonating legitimate employees to the help desk or support services in order to secure password resets or the registration of new authentication factors.
What it means for a mid-sized business
The warning confirms these groups are not confined to one sector or country: they switch targets when they meet resistance. Their technique does not require a technical vulnerability, only convincing a person with the ability to reset access.
This shifts much of the security burden onto support processes, whether internal or outsourced, which must verify a caller's identity with the same rigour they would demand to grant access from scratch.
What to review
Measures that reduce the effectiveness of social engineering against support teams:
- A strengthened identity-verification procedure before resetting passwords or authentication factors.
- Specific training for support staff on known impersonation techniques.
- Phishing-resistant two-factor authentication on administrative and support access.
- Logging and periodic review of access-reset requests.
Frequently Asked Questions
- Which groups are behind these attacks?
- Google did not publicly attribute the attacks to a single group with enough detail to name here; the warning focused on the shift of activity towards US companies and the social-engineering pattern.
- Why call it social engineering rather than a technical flaw?
- Because access was gained by convincing support staff to reset credentials, not by exploiting a software vulnerability.
- What can a company that isn't a large retailer do?
- Apply the same identity-verification rigour to its own support, whether in-house or outsourced, and enforce phishing-resistant two-factor authentication.
Every company has different risks and needs. At Seintec we can analyse your infrastructure and propose a tailored solution, without oversizing or complicating your environment. Contact us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.