By NHI Mgmt Group Editorial TeamBased on 1Kosmos: “What the Marks & Spencer Breach Tells Us About the Next Era of Identity Attacks” (June 27, 2025)

TL;DR: Scattered Spider exploited weak service desk processes and privileged access paths at a third-party IT provider to pivot into Marks & Spencer and other retailers, with the M&S campaign leading to months of undetected access, ransomware deployment, and more than $400 million in lost profit, according to 1Kosmos. The breach shows that inherited vendor trust, not perimeter controls, is the failure point in modern retail identity governance.


At a glance

What this is: This is an analysis of how Scattered Spider used third-party service desk weakness and privileged access to move into retail environments, with Marks & Spencer as the clearest example.

Why it matters: It matters because retail IAM teams have to govern vendor trust chains, help desk processes, and privileged access as one attack surface, not separate controls.

By the numbers:

  • More than $400 million in lost profit followed the Marks & Spencer campaign.
  • More than 60% of consumers would stop shopping with a brand that suffered a security incident, according to the article.
  • IBM estimates the average cost of a data breach is now $4.88 million per incident.

Context

Scattered Spider exploited a retail identity chain that depended on a third-party service desk, privileged access inheritance, and help desk trust. The central problem is not that retailers lacked authentication tools, but that they treated vendor access as trusted once it was issued.

For retail IAM programmes, this is a supply chain identity problem. Once a provider can reset, approve, or extend access on behalf of a client, compromise of that provider becomes a direct path into the retailer's environment.

Marks & Spencer is the clearest case in the article, but the pattern is broader than one brand. The same trust failure logic can apply wherever outsourced support functions sit inside the access path.


Key questions

Q: What breaks when a service desk can reset privileged access for vendors?

A: The access chain breaks when help desk staff can validate identity too weakly and extend privilege on behalf of another party. In that model, compromise of the service desk becomes equivalent to compromise of the client access path, because recovery, reset, and approval workflows inherit trust they should have verified.

Q: Why do third-party service desks increase lateral movement risk?

A: They increase risk because one provider can hold rights across multiple client environments, so a single compromise can be reused for repeated privileged actions. That turns delegated support into a scalable pivot point, especially when access is standing rather than task-scoped.

Q: What are the warning signs that vendor trust is too broad?

A: Watch for reset, approval, or re-enrolment workflows that can be completed by a small support group without strong reauthentication or separate approval. If the same support path works across several customer environments, the trust boundary is already too wide.

Q: How should retailers respond when a provider's privileged access is abused?

A: Containment should start by disabling inherited paths from the provider, not by focusing only on endpoint cleanup. Then review every client environment the provider could reach, because the real exposure is often the full span of delegated privilege, not the first compromised account.


Technical breakdown

How service desk trust becomes an access path

A service desk is not just a support function. It often acts as an identity authority, able to reset passwords, approve privileged requests, or broker access for users and vendors. In a third-party model, that authority extends into client environments, so compromise of the provider can translate into delegated access without any perimeter breach. Scattered Spider exploited that structure by targeting weak processes rather than malware defences. The key technical failure is not simply credential theft, but trust inheritance across identity boundaries. If the service desk can validate identity weakly, then every downstream access decision inherits that weakness.

Practical implication: Map every service desk action that can create or extend access and treat it as a privileged control point, not an administrative convenience.

Why MFA can fail when the authentication chain is social-engineered

The article describes SIM swapping and help desk impersonation bypassing traditional MFA. That matters because many MFA deployments secure the factor, but not the identity authority behind factor reset, recovery, or re-enrolment. If an attacker can convince support staff to rebind a device, register a new factor, or approve a recovery flow, the control collapses even when the login prompt looks strong. This is why identity proofing and recovery governance sit upstream of MFA strength. The attack does not need to break cryptography if it can socially engineer the control plane around the cryptography.

Practical implication: Review recovery, factor reset, and device re-enrolment paths with the same rigor as primary authentication.

How privileged access turns vendor compromise into lateral movement

Once the attackers gained privileged access through the provider, they could pivot into client systems and eventually exploit Microsoft Active Directory at the retailer. That is a classic delegated-access problem: a third party is granted rights that are valid in multiple environments, so compromise of the provider creates a blast radius well beyond its own network. Privileged access management is only effective if the privilege boundary is enforced at use time, not just at assignment time. In this pattern, standing vendor trust becomes the transport mechanism for lateral movement.

Practical implication: Constrain third-party privilege to reauthenticated, task-scoped sessions and review where inherited access crosses tenant or domain boundaries.


Threat narrative

Attacker objective: The objective was to use inherited vendor trust to reach retail systems, deploy ransomware, and maximise operational and financial disruption.

  1. Entry began with Scattered Spider targeting the third-party IT provider's service desk processes, using social engineering and SIM swapping to obtain or rebind trusted access paths.
  2. Credential access came through help desk weakness, where identity proofing and recovery controls failed to stop the attacker from becoming an accepted requester of privileged actions.
  3. Escalation and lateral movement followed when the provider's privileged access was used to pivot into client environments, including the retailer's Active Directory estate.
  4. Impact arrived months later when DragonForce ransomware encrypted VMware ESXi hosts on April 24, after the initial February compromise had remained undetected.
  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Vendor trust is now an attack surface, not a procurement detail: The article shows that a compromise of the service desk provider became a direct route into the retailer's environment. That means the security boundary is no longer the retailer alone, but the identity authority shared with suppliers. Retail IAM teams should treat third-party operational trust as a governed control plane, not a contractual assumption.

Service desk recovery is the weak link in many MFA programmes: The attack chain bypassed traditional multifactor controls through SIM swapping and help desk manipulation. That means organisations are still overestimating the strength of login factors while underestimating the identity proofing behind recovery and reset workflows. Practitioners should view factor re-enrolment as privileged access, because that is how attackers turn support into bypass.

Inherited privilege creates a supply chain identity blast radius: Once vendor access exists across client environments, one compromise can spread laterally with little friction. This is where privileged access management, third-party governance, and tenant boundary design converge. The practical lesson is that delegated rights need expiry, re-authentication, and environment separation, or the provider becomes a conduit rather than a control.

Retail security is being judged by trust failures, not just breach speed: The article ties the incident to months of undetected access, large financial loss, and brand damage. That is a sign that resilience now depends on how quickly identity relationships can be narrowed, not merely how fast malware can be contained. Retailers need to measure vendor-access exposure as a board-level identity risk.

Identity blast radius is the right concept for retail third parties: This pattern should be described as the spread between one compromised support relationship and the number of client environments it can reach. The stronger the reuse of privileged workflows, the larger the blast radius. Security teams should assess every supplier by how much identity authority it can amplify if compromised.

From our research library:

What this signals

Vendor trust is the new retail attack surface: When a third-party service desk can reset, approve, or broker access, the provider's identity controls become part of the retailer's own security boundary. Retail programmes need to measure supplier privilege as an exposure multiplier, not a procurement checkbox.

Identity proofing must sit upstream of MFA: If an attacker can manipulate recovery, device binding, or support verification, the login factor itself is no longer the decisive control. Teams should reclassify help desk reset flows as privileged operations and govern them accordingly.


For practitioners

  • Harden help desk recovery workflows Require strong identity proofing before any password reset, factor re-enrolment, or privileged access recovery action, especially where the requester is a vendor or contractor.
  • Revoke standing vendor privilege Replace inherited third-party access with task-scoped, reauthenticated sessions that expire after each approved action and cannot be reused across client environments.
  • Separate provider access domains Ensure a compromise in one supplier account cannot open the same privileged path across multiple retail tenants, directories, or management planes.
  • Audit vendor-facing reset paths Review every process that lets a service desk rebind devices, approve exceptions, or recover access on behalf of another identity.

Key takeaways

  • The breach exposed a supply chain identity failure, not a simple perimeter intrusion, because the attackers used a third-party service desk to reach retail systems.
  • The article ties the Marks & Spencer campaign to more than $400 million in lost profit and more than $1 billion in market value loss, showing the scale of identity-driven disruption.
  • Retailers need to narrow vendor trust, reauthenticate privileged actions, and govern recovery workflows as access controls rather than support processes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIThe article centers on compromise of a third-party service desk used to reach client environments.
NHI-04 — Insecure AuthenticationSIM swapping and help desk manipulation bypassed the authentication chain.
NHI-05 — Overprivileged NHIThe provider's access became a pivot into retailer systems because privilege was too broad.
Recommendation — Assess third-party support identities for inherited access paths and restrict their reach into client environments. Harden recovery and re-enrolment flows so weak identity verification cannot bypass primary authentication. Reduce provider privilege to task-scoped access and remove standing rights across tenants and directories.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe breach exploited weaknesses in credential recovery and factor reassignment.
Recommendation — Apply authenticator management controls to recovery, reset, and re-binding workflows.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe incident shows why inherited third-party entitlements need tighter authorization boundaries.
Recommendation — Review third-party entitlements and enforce authorization boundaries that prevent inherited access from spreading.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe campaign combined social engineering, credential access, and movement into client environments.
Recommendation — Map the attack chain to credential access and lateral movement tactics to improve detection and response.

Key terms

  • Service Desk Identity Authority: The effective power a help desk has to reset, recover, approve, or rebind access on behalf of users and vendors. In practice, it becomes an identity control plane, so weaknesses in verification or escalation can be used to inherit privilege across client environments.
  • Inherited Vendor Trust: Access that is accepted because it came from a trusted supplier relationship rather than from fresh verification at the moment of use. For retail and other outsourced environments, inherited trust is dangerous because compromise of the provider can immediately widen the attacker’s reach.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Recovery Workflow: A recovery workflow is the sequence of checks and actions used to restore access after a credential issue or account lockout. It includes verification, credential issuance, synchronization, and audit logging. Weak recovery workflows are attractive to attackers because they often sit outside the strongest authentication controls.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org