Supply Chain Digital Magazine June 2025 | Page 135

RICHARD ALLEN
RISK & RESILIENCE

RICHARD ALLEN

TITLE: CYBERSECURITY EXPERT COMPANY: PA CONSULTING INDUSTRY: CONSULTING
Richard is a business manager with 30 years of experience in adding value to organisations through leadership, change and innovation. He combines a strong strategic and analytical capability with a hands-on operational approach.

“IT’ S ALSO POSSIBLE THAT THEY SHARE A COMMON THIRD-PARTY SUPPLIER OR COMPROMISED TECHNOLOGY”

RICHARD ALLEN, CYBERSECURITY EXPERT, PA CONSULTING full-blown chaos, leading to online orders being paused and automated stock management stopped – even routine tasks like monitoring fridge temperatures had to be done by hand.
Customers, urged by Chief Executive Stuart Machin to shop in person while staff worked“ day and night” to restore operations, found bare shelves in food halls and limited sizing in fashion departments. Refunds and returns were eventually restored, along with contactless payments and gift cards, but the damage was done.
Behind the scenes, investigators believe the culprit may be Scattered Spider, a cybercrime group known for using social engineering, manipulating people rather than systems, to reset admin credentials and slip past multi-factor authentication.
That said, it is still under investigation by the National Cyber Security Centre( NCSC), which is working with the Metropolitan Police and National Crime Agency.
The NCSC’ s National Resilience Director, Jonathon Ellison – and Chief Technology Officer, Ollie Whitehouse – have described these attacks as both“ opportunistic and indiscriminate.” They warn that the rise in“ ransomware as a service”, a model that allows relatively unskilled criminals to buy access to powerful hacking tools, is making it easier for attacks to be launched across sectors.
“ Cyber criminality, including extortion and ransomware, is one of the most pervasive cyber threats facing UK organisations,” they write.“ It affects
supplychaindigital. com 135