• Skip to main content
  • Skip to header right navigation
  • Skip to after header navigation
  • Skip to site footer
MyZA

MyZA

News, Directory, Events and Other Stuff

  • Social Media
  • Sport
  • World News
  • Home
  • Submit News
  • Directory
  • Events
  • Stratlec
  • TFSA
  • News
    • APO
    • Today’s Sport News
    • Todays Social Media and Tech Headlines
    • Today’s World News
    • Today’s SA Financial News
  • Contact
You are here: Home / News / London to Lagos: Why Retailers Everywhere Must Prepare for the Next Wave of Cyberattacks

London to Lagos: Why Retailers Everywhere Must Prepare for the Next Wave of Cyberattacks

15 July 2025 by Guest
KnowBe4

In April, two of Britain’s biggest retailers got hit by a massive cyberattack by the notorious Scattered Spider group, leading to substantial financial losses, operational disruptions and compromised customer data (http://apo-opa.co/40O1faD). M&S suffered losses of £300 million (http://apo-opa.co/40O1gLJ) (roughly R7.3 billion) due to the attack, with supply chains affected for weeks. On top of the direct losses, over £1 billion was stripped from the organisation's market value (http://apo-opa.co/4lPmMb3). Similarly, the Co-op experienced data breaches (http://apo-opa.co/4524lud) affecting customers’ personal information, while Harrods reported attempted cyberattacks (http://apo-opa.co/3GIeSl3), but managed to maintain online operations.

“These attacks aren’t just about stolen data,” says Anna Collard, SVP of Content Strategy & Evangelist at KnowBe4 Africa. “They took whole systems offline.

“In retail, downtime is a critical threat – it affects sales, customer trust, and brand loyalty, instantly.”

A new kind of threat actor

Unlike traditional ransomware gangs, Scattered Spider is decentralised, native English-speaking, and highly adaptive. “Scattered Spider aren’t mere opportunistic hackers,” explains Collard. “They operate more like well-funded, well-organised crime syndicates.”

With some members as young as 19, they coordinate their activities on platforms like Discord and Telegram. “They’re agile, patient and disturbingly good at blending in,” she says. Added to this, they have great expertise in human psychology, as showcased during their attacks on Las Vegas casinos in 2023 (http://apo-opa.co/4nPvtnM).

Their primary weapons, therefore, aren’t just digital – they’re human. “They’ve mastered social engineering,” says Collard. “They specialise in exploiting human trust. From vishing (voice phishing) to impersonating internal staff and triggering what’s referred to as ‘MFA fatigue’; they’re skilled manipulators who understand both systems and people.”

MFA fatigue is one of the growing tactics they’re known for which involves triggering repeated multi-factor authentication (MFA) prompts, hoping the bombarded employees eventually click “approve” just to make the interruptions stop.

“Legacy systems, shadow IT, and poorly enforced policies create entry points. Attackers don’t need to break in if they can just log in.”

Another alleged tactic Scattered Spider used in its latest attacks involved calling IT helpdesks to reset credentials, gaining access to their target’s infrastructure and subsequently deploying a ransomware-as-a-service tool. The outcome? Encrypted systems, stalled operations, and a long road to recovery.

Why Africa should be paying close attention

Retailers across Africa – particularly in South Africa, Nigeria, and Kenya – are digitally transforming at a rapid pace. Cloud-based POS systems, centralised inventory platforms, and data-driven loyalty programmes are now standard. But these digital advancements also expand attack surfaces.

High employee turnover, remote workforces, and under-resourced helpdesks can compound exposure. And while business English is common in South Africa, this linguistic advantage also makes local teams more susceptible to social engineering by fluent English-speaking attackers.

“Our local executives aren’t naïve,” Collard notes. “Many are acutely aware of the risks. What’s needed now is clarity on what really matters – and cutting through the noise.”

Pepkor IT’s CISO, Duncan Rae, delivered an insightful talk at the ITWeb Security Summit in May where he warned that cybersecurity teams are often overwhelmed – not just by threats, but by too many competing priorities. Teams are bombarded with shiny, new tools and threat reports spreading fear, uncertainty, and doubt (FUD) which sometimes makes organisations lose sight of the basics, he warned.

“These basics include managing human risk, addressing third-party exposure, and hardening vulnerabilities,” according to Rae.

What needs to change?

Collard points to gaps in access controls, third-party risk management, and cloud security as common weaknesses – not just in the UK, but globally. “Legacy systems, shadow IT, and poorly enforced policies create entry points,” she warns. “Attackers don’t need to break in if they can just log in.”

For African retail leaders, this is a call to fortify the human layer.

“Train your frontline teams, especially in helpdesk and customer support. Teach them to detect manipulation. Make secure behaviour the norm – not the exception.”

Equally important, she says, is embedding cybersecurity into leadership conversations. “Cybersecurity is not just an IT function. It’s a board-level business risk.

“Executives must ask tough questions about readiness, incident response, and accountability.”

From awareness to action

Too often, security training is treated as a box-ticking exercise. Collard urges a more thoughtful approach: “Training must resonate. It should be contextual, culturally relevant, and delivered in local languages where appropriate.”

She challenges business leaders with the following:

  • Could an attacker trick your helpdesk into a password reset?
  • Would your staff recognise a social engineering attempt?
  • Do you test these scenarios regularly?

“If the answer is ‘no’ to any of these, your organisation is vulnerable,” Collard says. “But the good news is that change is possible – and fast – when you start investing in the human element.”

“Cyber resilience is a collective responsibility,” she concludes. “And in an interconnected world, learning from each other’s crises is one of the smartest defences we have.”

Distributed by APO Group on behalf of KnowBe4.

Contact details:
KnowBe4:
Anne Dolinschek 
anned@knowbe4.com

Red Ribbon:
TJ Coenraad 
tayla@redribboncommunications.co.za

Media files
KnowBe4
Download logo

In April, two of Britain’s biggest retailers got hit by a massive cyberattack by the notorious Scattered Spider group, leading to substantial financial losses, operational disruptions and compromised customer data. M&S suffered losses of £300 million (roughly R7.3 billion) due to the attack, with supply chains affected for weeks. On top of the direct losses, over £1 billion was stripped from the organisation’s market value. Similarly, the Co-op experienced data breaches affecting customers’ personal information, while Harrods reported attempted cyberattacks, but managed to maintain online operations.

“These attacks aren’t just about stolen data,” says Anna Collard, SVP of Content Strategy & Evangelist at KnowBe4 Africa. “They took whole systems offline.

“In retail, downtime is a critical threat – it affects sales, customer trust, and brand loyalty, instantly.”

A new kind of threat actor

Unlike traditional ransomware gangs, Scattered Spider is decentralised, native English-speaking, and highly adaptive. “Scattered Spider aren’t mere opportunistic hackers,” explains Collard. “They operate more like well-funded, well-organised crime syndicates.”

With some members as young as 19, they coordinate their activities on platforms like Discord and Telegram. “They’re agile, patient and disturbingly good at blending in,” she says. Added to this, they have great expertise in human psychology, as showcased during their attacks on Las Vegas casinos in 2023.

Their primary weapons, therefore, aren’t just digital – they’re human. “They’ve mastered social engineering,” says Collard. “They specialise in exploiting human trust. From vishing (voice phishing) to impersonating internal staff and triggering what’s referred to as ‘MFA fatigue’; they’re skilled manipulators who understand both systems and people.”

MFA fatigue is one of the growing tactics they’re known for which involves triggering repeated multi-factor authentication (MFA) prompts, hoping the bombarded employees eventually click “approve” just to make the interruptions stop.

“Legacy systems, shadow IT, and poorly enforced policies create entry points. Attackers don’t need to break in if they can just log in.”

Another alleged tactic Scattered Spider used in its latest attacks involved calling IT helpdesks to reset credentials, gaining access to their target’s infrastructure and subsequently deploying a ransomware-as-a-service tool. The outcome? Encrypted systems, stalled operations, and a long road to recovery.

Why Africa should be paying close attention

Retailers across Africa – particularly in South Africa, Nigeria, and Kenya – are digitally transforming at a rapid pace. Cloud-based POS systems, centralised inventory platforms, and data-driven loyalty programmes are now standard. But these digital advancements also expand attack surfaces.

High employee turnover, remote workforces, and under-resourced helpdesks can compound exposure. And while business English is common in South Africa, this linguistic advantage also makes local teams more susceptible to social engineering by fluent English-speaking attackers.

“Our local executives aren’t naïve,” Collard notes. “Many are acutely aware of the risks. What’s needed now is clarity on what really matters – and cutting through the noise.”

Pepkor IT’s CISO, Duncan Rae, delivered an insightful talk at the ITWeb Security Summit in May where he warned that cybersecurity teams are often overwhelmed – not just by threats, but by too many competing priorities. Teams are bombarded with shiny, new tools and threat reports spreading fear, uncertainty, and doubt (FUD) which sometimes makes organisations lose sight of the basics, he warned.

“These basics include managing human risk, addressing third-party exposure, and hardening vulnerabilities,” according to Rae.

What needs to change?

Collard points to gaps in access controls, third-party risk management, and cloud security as common weaknesses – not just in the UK, but globally. “Legacy systems, shadow IT, and poorly enforced policies create entry points,” she warns. “Attackers don’t need to break in if they can just log in.”

For African retail leaders, this is a call to fortify the human layer.

“Train your frontline teams, especially in helpdesk and customer support. Teach them to detect manipulation. Make secure behaviour the norm – not the exception.”

Equally important, she says, is embedding cybersecurity into leadership conversations. “Cybersecurity is not just an IT function. It’s a board-level business risk.

“Executives must ask tough questions about readiness, incident response, and accountability.”

From awareness to action

Too often, security training is treated as a box-ticking exercise. Collard urges a more thoughtful approach: “Training must resonate. It should be contextual, culturally relevant, and delivered in local languages where appropriate.”

She challenges business leaders with the following:

  • Could an attacker trick your helpdesk into a password reset?
  • Would your staff recognise a social engineering attempt?
  • Do you test these scenarios regularly?

“If the answer is ‘no’ to any of these, your organisation is vulnerable,” Collard says. “But the good news is that change is possible – and fast – when you start investing in the human element.”

“Cyber resilience is a collective responsibility,” she concludes. “And in an interconnected world, learning from each other’s crises is one of the smartest defences we have.”

Per Kind Favour of APO

Africa Fact: African Continental Free Trade Agreement went into force May 30th 2019. As of July 2019, 27 African countries had ratified the agreement and all African countries besides Eritrea had signed the CFTA.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Print (Opens in new window) Print
  • Email a link to a friend (Opens in new window) Email
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
Category: NewsTag: APO, Fraud

If you feel strongly about this article then feel free to send MyZA a ‘Letter to the Editor’ using the submission form below:


Letter to the Editor

This field is for validation purposes and should be left unchanged.
If this is in response to an article please include that article title here or as the lead in for the first paragraph of your Letter below.

Separate tags with commas

Localise your letter by naming the city your words are about. Add relevant words describing your subject. Single comma separated words of no more than 5
Your Name(Required)
Your Name will be linked to the website below.
Your personal, business or social media web site
Choose NO to not set up a user account on MyZA. User Accounts will allow you to submit letters under your own Author Name

3 Latest Letters to the Editor:

  • Fun South African fact

    Dear Editor Fun South African fact: towns like Franschhoek and Stellenbosch are home to world-class wine farms set in stunning, scenic surroundings. Regards Aressa Smith In Response to/From: Luxury Properties Seized in New Lottery Crackdown

    27 January 2026
  • Condolences on the Passing of Lusanda Dumke

    Statement by Leander Kruger MPL – DA Buffalo City Constituency Leader: The Democratic Alliance in Buffalo City Metropolitan Municipality mourns the passing of Springbok Women’s rugby player and Mdantsane trailblazer, Lusanda Dumke, who lost her battle with cancer at the age of 28. South Africa has lost an exceptional athlete, a leader, and a source…

    17 December 2025
  • Rape Kits Delivered, But…

    Statement by Nicholas Gotsell MP – DA NCOP Member on Security & Justice: The DA can confirm that 2 840 rape kits arrived in Cape Town on Monday, following sustained DA oversight and pressure after multiple police stations across the Western Cape were found to be without this critical forensic evidence tool. While this delivery…

    17 December 2025

About Guest

Previous Post:Public Land Must Serve the Public, Not Just the Privileged
Next Post:Mayor of Cape Town to Appear in Court Over Alleged Abuse of Power

Reader Interactions

Comments

  1. ship whip

    15 July 2025 at 12:42 pm

    South Africa: You have two cows. The one with more white patches has more privileges.

  2. Sunvolt

    15 July 2025 at 12:42 pm

    Afrikaans knock knock joke.

    Klop klop.

    Wie is daar?

    Bon Joe.

    Bon Joe Wie?

Copyright © 2026 · MyZA · All Rights Reserved · Powered by Reach Trust