TL;DR: Recent UK retail breaches show how social engineering, SIM swapping, and help-desk compromise can still bypass traditional MFA and expose customer data, with Marks & Spencer losing more than $80 million in profit and $1.3 billion in market value, according to 1Kosmos and the BBC. The lesson is that identity programmes built on credentials and devices alone cannot withstand impersonation-driven access theft.
Editorial analysis by NHI Mgmt Group, based on content published by 1Kosmos: “âSpiderâ Strikes Britain: The Hacks at M&S, Co-Op & How to Stop Them”.
Practitioner guidance
- Harden account recovery controls Require step-up verification, out-of-band approval, and fraud-resistant checks before any password reset, SIM change, or device rebind can complete.
- Separate support from privilege administration Restrict help-desk staff from making identity state changes unless the request passes a higher assurance workflow with explicit escalation and audit.
- Review supplier and telecom trust paths Inventory every third-party path that can alter user authentication state, then remove any route that can approve resets without verified business need.
Bottom line: Social engineering remains effective because attackers exploit the recovery and support layers around identity, not only the authentication factor itself.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Social engineering has become an identity-layer bypass, not just a fraud problem: The article shows that attackers are no longer trying to defeat MFA in the abstract. They are targeting the operational steps around identity verification, especially help desks, telecom providers, and reset workflows. That means identity governance has to treat recovery paths as part of the control plane, not as administrative afterthoughts. Practitioners should assume that any process able to rebind trust can also be weaponised.
👉 Read our full editorial: Social engineering and MFA bypass are still breaking enterprise identity