Social engineering against the help desk appears at the centre of attacks on British retailers
Reuters reported information pointing to employee impersonation directed at support services to obtain password resets during the Marks & Spencer and Co-op incidents.

News summary
Reuters reported information pointing to employee impersonation directed at support services to obtain password resets during the Marks & Spencer and Co-op incidents. The NCSC called for a review of help desk processes.
MFA does not resolve a weak account recovery process. Resetting passwords or registering a new factor must require identity controls equivalent to standard access.
Source: Reuters — 6 May 2025
What happened
In May 2025 reporting by Reuters pointed to attacks on Marks & Spencer and Co-op relying on impersonating employees to support services, aiming to secure password resets or the registration of new authentication factors. The UK's National Cyber Security Centre (NCSC) urged organisations to review their help desk processes.
The pattern described does not exploit a software vulnerability: attackers pose as a legitimate employee and convince support staff they need their access restored, without always facing sufficiently rigorous identity verification.
What it means for a mid-sized business
The case shows that two-factor authentication offers no protection if the process to reset it is weak: requiring MFA for daily access is pointless if a convincing phone call is enough to disable it or register a new device.
For any business, this means reviewing the weakest link in the identity chain, which is usually the access-recovery process itself rather than the authentication mechanism.
What to review
Controls that harden the access-recovery process against impersonation:
- Strengthened identity verification (beyond easily obtainable data) before resetting passwords or MFA factors.
- Calling back a previously registered number, rather than trusting the number the requester calls from.
- Logging and auditing every access-reset request made to the help desk.
- Periodic training for support staff on known social-engineering techniques.
Frequently Asked Questions
- What did the NCSC ask organisations to do?
- Review their help desk processes to reduce the risk that employee impersonation allows access resets without sufficient verification.
- So is MFA not enough?
- MFA remains necessary, but it does not fix a weak account-recovery process: resetting passwords or registering a new factor must demand the same rigour as normal access.
- What should a small business with outsourced support do?
- Require its support provider to have a documented identity-verification procedure and periodically audit the reset requests it handles.
At Seintec, we can help you review how a similar scenario would affect your business and define the most appropriate technical measures. Contact us and an expert will study your case.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.