The Inditex breach saw nearly 200,000 Zara customers impacted but is just one example as the retail sector is actively targeted.
By Northdoor CCO AJ Thompson
The last few months have highlighted the threat that the retail sector is facing from cybercriminals. It has been actively targeted with some of the largest brands being impacted. Marks and Spencer, Co-op, Harrods and most recently, Inditex, owner of Zara.
The ransomware attack on Inditex has seen nearly 200,000 Zara customers impacted with group reportedly behind the attack, the ShinyHunters cybercrime group, releasing the data they had stolen after the deadline for payment passed. However, this attack was just the latest in a long line hitting the retail sector.
Supply chain attacks
This latest retail breach has also followed in the trend of attacks that have been targeting the retail sector. Instead of trying to get through the front-line defences of their primary target, cybercriminals have been trying to get in through the ‘back-door’ via third parties and supply chains.
As supply chains are now so interconnected, by gaining access to one, cybercriminals can infiltrate multiple systems with just one breach. This means that no matter how much budget is spent on front-line defences by allowing vulnerabilities that lie within supply chains to remain open all of that spend is essentially negated.
In the case of Inditex cybercriminals breached a third-party technology provider to gain access to the details of Zara’s customers. Likewise, the huge attacks in 2025 on M&S, Co-op and Harrods also appear to have been similar sources with cybercriminals taking advantage of gaps in security within the supply chain.
The task for the retail sector looks huge.
Understanding vulnerabilities in supply chains
The nature of supply chains means that they are often huge and complex. Therefore, understanding where vulnerabilities might lie within partner’s networks seems like an immense, if not impossible task. However, identifying where gaps in security lie, talking to partners and closing them before cybercriminals can take advantage is now a critical step all in the retail sector have to make. This knowledge can also be an important function when signing or embedding new partners in. Using AI-powered solutions gaining a 360-degree overview of vulnerabilities within supply chains is now very much achievable
Seeing gaps in security and dealing with them before them join a network saves time and money further down the line.
Indeed, the cost of a breach is now huge. The UK’s Cyber Monitoring Centre estimated that last year’s attacks on the country’s retail sector cost between £270 million and £440 million. The average cost of a data breach per company in the UK was according to the Cost of a Data Breach report 2025 standing at £3.39 million. This cost does not consider the impact a high-profile breach has on a company’s reputation, its ability to adhere to regulations or whether it can carry on with its day-to-day activities post-breach.
Quantum computing adding to risk
Another emerging technology that will impact the retail sector is quantum computing. Quantum combines computer science and engineering that harnesses the qualities of quantum mechanics. The danger of quantum is that it could be utilised by cybercriminals.
Current encryption techniques aim to make data unusable for even if stolen during a breach. However, the advent of quantum means that the simultaneous processing of multiple layers of encryption is possible, negating current data encryption efforts.
Quantum is not there yet but will be in a matter of years with experts calling the moment it becomes a reality Y2Q.
Resilience alongside prevention is key
With cyber-attacks increasing in volume and sophistication all the time and quantum sitting on the horizon as a future threat, it is no longer the case if a breach happens but more likely when it does. Therefore, companies must prepare for the worst.
Whilst prevention is still a critical element in a retail company’s defensive strategy building resilience is now a critical piece of the jigsaw. Without resilience companies will struggle to get back to business as usual. We saw in the wake of the attacks on Co-op, Harrods and M&S that all three struggled to get back-up-to-speed. The M&S Click and Collect service was out of action for 15 weeks. Co-op proactively shut-down systems when it detected the hack which meant services went down quickly but they saved themselves time in the long-run by preventing cybercriminals access to all their systems. Their built-in level of resilience paid off as it meant Co-op was able to return to business as normal relatively quickly and certainly quicker than M&S.
Prevention is obviously still critical element, ensuring cybercriminals cannot easily gain access through front-line defences or via the supply chain is important. Having resilience built into the everyday activity means that if, or when, prevention fails, you are able recover quickly, reducing the impact.
The cyber threat to the retail sector is increasing in sophistication and regularity. Cybercriminals will up their efforts to infiltrate retail firms through supply chains over the coming months. Retailers must ensure that vulnerabilities are closed across their supply chain and that layers of resilience are built into everyday activity.
Click here to sign up to Retail Gazette‘s free daily email newsletter

