What is vishing? The helpdesk attack that cost M&S £300m

The helpdesk is the new perimeter

Twenty years of security spending went on the front door. The modern attacker rings the doorbell instead. They phone your IT helpdesk, sound convincing, and ask for a password reset. In the most expensive UK retail breach of the decade, that is exactly how it began.

The technique has a name, and most boards cannot define it. It is vishing, and it has quietly become the softest way into a well-defended company.

What is vishing?

Vishing (short for “voice phishing”) is a social engineering attack carried out over the phone. The attacker calls a person with authority to grant access, usually the IT helpdesk or service desk, poses as an employee who has lost access, and talks their way to a password or a multi-factor reset. No malware, no exploit, no breached firewall. Just a convincing conversation.

It sits in the same family as phishing and smishing. Phishing arrives via email, smishing via text, and vishing via phone. The difference matters because most awareness training is built for the inbox, and the phone call walks straight past it. Vishing usually combines two older tricks: pretexting (inventing a believable story and identity) and impersonation (borrowing a real employee’s name and role, often lifted from LinkedIn).

What happened at Marks & Spencer

In April 2025, someone phoned the helpdesk run by Marks & Spencer’s technology outsourcing provider and posed as an employee who had lost access. They answered a few verification questions of the kind anyone can piece together from a public profile and asked for an administrative password reset. They got it.

Within days, the contactless tills started failing. Within weeks, the website was offline, and other retailers, including the Co-op and Harrods, were dealing with the same criminal group. M&S told the market the incident would cost it around £300m in profit. The attackers, linked to the group known as Scattered Spider, did not defeat a firewall. They had a conversation. Four suspects, aged 17 to 20, were later arrested by the National Crime Agency, and the NCSC used the episode to warn every UK organisation that the helpdesk had become a primary target.

The part most boards still get wrong is the bit before the tills failed. It started with a phone call, and the controls were never designed to refuse it.

Why does the vishing call work?

The helpdesk, or service desk, is a strange animal in the security model. It is staffed to be helpful. It is measured by how quickly it resolves calls, not by how well it resists an adversary. It often sits with a third party because the cost of running it in-house was driven out of scope years ago. And it holds the operational authority to reset privileged credentials, because that is the job the business pays it to do.

None of the attacks requires a zero-day. It requires a plausible name, a believable reason for urgency, and verification questions that can be answered from public information. The agent on the other end is being measured on first-call resolution. If they refuse, the next call escalates to a furious “executive” demanding to know why their team cannot work. The manager is not in the room. The fraud team is not on the line. “Be sceptical of social engineering” is a losing instruction against an incentive structure that pays the agent to be helpful and punishes them for friction.

Why “train them better” is the wrong answer

The common board response is to send the service desk staff for more training and show the audit committee a completion certificate. It treats the failure as a lapse of attention rather than a flaw in the control structure. Training does not change the incentives that made the reset the easy choice. Proving your agents are trained is not the same as proving your process makes refusal the cheaper option. The attacker is not betting that your people will be careless. They are betting on your process being polite.

How to prevent helpdesk and service desk social engineering

The fix is not a product you can buy. It is a small, deliberate change to who confirms what before a credential moves. For any privileged or MFA reset, put four controls in place:

  • Callback verification on every privileged reset, using a number already held on record, never one the caller provides.
  • Out-of-band confirmation through a known channel, such as a separate app or a manager, not a continuation of the same call.
  • Manager sign-off before any elevation of access, so the lonely decision stops being lonely.
  • A named “this looks wrong” route that a helpdesk agent can use without being marked down on call-handling time.

None of these is expensive. All of them make the reset the hard path and the refusal the safe one, which is the exact inversion of the incentive that cost M&S £300m. Identity-first controls (phishing-resistant MFA, stronger identity proofing at reset) help, but they are the tools. The decision about who is allowed to move a credential, and on what evidence, is under control.

The supplier boards keep missing

There is a second lesson, and it is usually filed under the wrong heading. The government’s Cyber Security Breaches Survey has repeatedly found that only around one in six UK businesses formally reviews the cyber risk of its immediate suppliers. Read that the other way. Roughly 85% do not. In the M&S case, the supplier that mattered most was the helpdesk itself.

If you outsource the function that can reset your passwords, its control structure is your control structure, regardless of what the contract says about liability. This is the same exposure that underlies supplier and NIS2 risk, and it belongs in the board’s cyber risk reporting, not buried in an operational runbook.

The questions for your next executive committee

You do not need a penetration test to close this gap. The pen test tells you whether the firewall held. This is not a firewall problem. It is an operating-model problem, and only the people who set the operating model can fix it.

So put four questions on the agenda, and do not accept “we take security very seriously” as an answer to any of them. If a confident voice rings your service desk at three o’clock on a Tuesday and asks to reset a privileged credential, what actually happens next? Has anyone tested that path in the last six months, with a real call rather than a tabletop? When an agent last refused a suspicious request, were they thanked, or quietly marked down for handling time? And who, by name, owns this risk on the board?

If you cannot answer all four cleanly, you have found your work for the quarter. It is cheaper than the alternative. M&S can tell you the exact figure.

Written by Daniel J. Jacobs, fractional and interim CIO and CISO.

Digital Disruption Digest

Not ready to talk yet? Get the thinking first.

Practical technology leadership insight for boards and leaders, delivered through the newsletter.

Subscribe on LinkedIn Prefer to talk? Book a conversation  ·  Read past editions