Phishing, Ransomware, Data Leaks: Lessons from Recent UK Cyber Attacks Copy for Testing

John Doe

17 June 2025 • 2 min read

Explore what the recent cyberattacks on M&S, Co-op and West Lothian schools have in common and how your organisation can avoid the same mistakes.

Following data breaches at Marks & Spencer and the Co-op, the education sector has become the latest target.

In April, two major UK retailers made headlines for all the wrong reasons.

Cyber-attack-m&s

Marks & Spencer was affected by a data breach when attackers impersonated IT help desk staff and tricked employees into handing over their login credentials and multi-factor authentication (MFA) codes.

This gave the criminals direct access to internal systems and sensitive data.

Meanwhile, the Co-op narrowly avoided a full-scale crisis. Hackers infiltrated its network and attempted to deploy ransomware. But the Co-op's IT team acted quickly, disconnecting internal systems and preventing full encryption. Although this caused a short-term disruption, it ultimately minimised damage and sped up recovery.

Then, in May, the threat came closer to home when it impacted the education sector.

What Was Affected?

Cyber-attack

The ransomware attack primarily targeted internal school documents, including lesson plans and operational data. However, West Lothian Council has since confirmed that some personal and sensitive data was stolen, too.

While confidential pupil records, financial data and social care systems are stored separately, officials have not ruled out the possibility that medical or social work information may have been compromised.

The council has contacted parents, carers and staff at over 140 sites to inform them of the breach and offer support.

According to BBC reports, a group known as Interlock has claimed responsibility for the attack and is threatening to publish the stolen data unless a ransom is paid.

Cyber-attack2

What Ties These Attacks Together?

Different targets. Different tactics. But they all have the same underlying issues.

  • Phishing and social engineering
  • Compromised credentials
  • Delayed patching
  • Weak network segmentation
  • Lack of early detection

 

 

Recent Posts

Five Reasons Every SME Needs a CRM in 2026

Discover why SMEs need a CRM in 2026 for better customer management, streamlined operations and improved sales and marke...

Break The Myth: “Dynamics 365 is Not For Everyone”

Dynamics 365 doesn’t have to be complex or expensive. Learn how small teams can start with Lite packages for sales, proj...

Copilot Business brings Microsoft’s AI to smaller teams

Microsoft Copilot Business brings AI into Outlook, Word, Excel and Teams for growing organisations, with enterprise-grad...

Building Resilience for 2026: Recent Cyber Security Events

Discover what recent Azure and WhatsApp security events mean for SMEs and how small, practical steps can strengthen your...

Union

Empower your business with secure, expert-led solutions.

Talk to us about people-focused technology that drives results.

Start a conversation
Woman in White longsleeve polo