Vendor Ecosystem Risk: What the 2025 M&S and Co-op Ransomware Attacks Actually Reveal
In spring 2025, two of the UK’s most recognized retail brands — Marks and Spencer and Co-op — were hit by ransomware attacks that halted operations, exposed customer data, and dominated business headlines for weeks. Neither company was negligent. Yet both suffered serious, public damage. The real lesson inside both incidents is not about patching schedules or password policies. It is about vendor ecosystem risk — the exposure that lives inside your supplier and technology partner network, beyond the reach of your own internal controls. That lesson applies directly to a 40-person professional services firm in South Jersey, not just billion-dollar UK retailers.
Table of Contents
- What Actually Happened at M&S and Co-op
- The Vendor Door: How Vendor Ecosystem Risk Enters Without Touching Your Perimeter
- Why SMBs Face the Same Vendor Ecosystem Risk
- What a Well-Managed Vendor Ecosystem Risk Program Actually Has in Place
- The Board and Leadership Conversation You Should Be Having
- Understanding Your Vendor Ecosystem Risk Surface: A Practical Starting Point
- The Quiet Firms Are the Ones Paying Attention
What Actually Happened at M&S and Co-op
Reports from the UK’s National Cyber Security Centre and investigative journalists confirmed that the attacks were carried out by a group operating under the Scattered Spider umbrella, using ransomware infrastructure linked to the DragonForce group. The attackers did not walk through a front door. They exploited the trust relationships, credentials, and system access woven throughout each retailer’s vendor and technology partner network — a direct, real-world example of vendor ecosystem risk at scale.
For M&S, the disruption was severe enough to take down online ordering for several weeks — a meaningful operational and revenue hit for a retailer of that scale. Co-op attempted to limit the damage by proactively shutting down portions of its own systems, which itself disrupted operations. Customer data was confirmed stolen. These were not quick smash-and-grab incidents. Attackers spent extended time inside both environments before deploying ransomware.
That extended dwell time is the detail that matters most. It means the attackers understood the environment well enough to move laterally and position themselves for maximum damage before anyone noticed. That kind of access does not come from a single brute-forced password. It comes from trust — specifically, the trust that business systems extend to vendors, contractors, and third-party tools.
The Vendor Door: How Vendor Ecosystem Risk Enters Without Touching Your Perimeter

Modern businesses run on interconnected systems. A retail operation the size of M&S or Co-op connects to logistics providers, payment processors, marketing platforms, HR software vendors, facilities management systems, and dozens of other third parties — each holding some level of authenticated access into the core environment.
This is not unique to large retailers. A professional services firm with 30 employees in Cherry Hill might connect to an external payroll provider, a cloud-based document management platform, an outsourced bookkeeper with access to accounting software, a benefits administrator, and an IT vendor. Every one of those relationships is a potential entry point that exists entirely outside the firm’s own network perimeter.
Attackers understand this. Compromising a smaller, less-defended vendor — then using that vendor’s trusted credentials to reach the real target — is a well-documented technique. The Cybersecurity and Infrastructure Security Agency (CISA) has published extensive guidance on supply chain and third-party risk precisely because this attack vector has become one of the dominant methods for gaining initial access into otherwise well-defended organizations.
The hard truth: your security posture is only as strong as the weakest link among every entity with authenticated access to your systems. Strong internal controls do not protect you from a vendor who has none.
Why SMBs Face the Same Vendor Ecosystem Risk
A common reaction from business owners reading about M&S or Co-op is: “That’s a massive company. Attackers want the big fish.” That thinking is outdated and dangerous. Attackers increasingly target smaller firms because they offer an easier path to the larger organizations those smaller firms serve.
Consider these scenarios:
- A pharmaceutical consulting firm with 18 employees holds client data for three large pharma companies. The consulting firm is the path of least resistance to sensitive research data.
- A regional accounting firm handles payroll and tax records for 200 local businesses. Compromising the accounting firm yields access to data across all 200 clients.
- A professional services company uses a third-party IT vendor whose remote management credentials, if stolen, provide authenticated access to dozens of client environments simultaneously.
The M&S and Co-op attacks are a high-visibility illustration of a structural problem that exists at every business size. The complexity of a vendor ecosystem scales down with the business — but vendor ecosystem risk does not disappear. A 25-person firm with five cloud-based tools, an outsourced payroll provider, and a managed IT partner has a vendor ecosystem. That ecosystem carries risk that internal controls alone cannot close.
Ransomware groups are also increasingly opportunistic and automated in how they identify targets. They are not manually selecting victims the way a burglar cases a neighborhood. They run automated scans, purchase stolen credentials from criminal marketplaces, and exploit known vulnerabilities at scale. Being small does not make you invisible. In some cases it makes you more attractive — the defenses are lower and the ransom demand can still be significant relative to the victim’s resources.
What a Well-Managed Vendor Ecosystem Risk Program Actually Has in Place
The question for any business leader is not “could this happen to us?” It almost certainly could. The real questions are: Would an attacker find it easy or hard to get in? And if they did, could they move freely?
A well-run IT and security environment addresses vendor ecosystem risk through several layers:
- Vendor access controls: Third-party vendors receive only the minimum access required to do their job, reviewed on a regular schedule. Unused credentials are removed. Vendor sessions are monitored — not assumed safe simply because they carry a trusted identity.
- Identity verification protocols: Multi-factor authentication is enforced for every account accessing company systems from outside the network perimeter, including vendors and contractors. A credential alone does not open a session.
- Network segmentation: Systems are architected so a breach in one area cannot move freely into adjacent areas. An attacker who compromises a vendor’s access to the marketing platform should not automatically gain a path to financial records or operational systems.
- Continuous monitoring: Unusual behavior — logins at odd hours, large data transfers, access to systems a user or vendor does not typically touch — triggers review. Extended dwell time, the factor that made M&S and Co-op so damaging, is only possible when monitoring is absent or inadequate.
- Incident response readiness: A tested, documented plan exists before an incident occurs, covering communication protocols, containment procedures, and backup systems verified to work. A plan that lives in a document no one has rehearsed is not a plan.
- Vendor security questionnaires and assessments: Before granting a third party access to company systems, there is a defined process to evaluate their security posture. This does not require a lengthy audit for every software tool — but it does require deliberate questions about how vendors protect credentials, handle breaches, and what controls they maintain.
None of these are enterprise-only capabilities. They are the baseline of a well-managed IT environment, achievable for any business working with the right partner. The firms that maintain them are the ones that do not make headlines.
For a closer look at how Xact IT structures managed environments to address these layers, see our cybersecurity services overview.
The Board and Leadership Conversation You Should Be Having
If you are a CEO, COO, or executive director, the M&S and Co-op incidents give you a specific conversation starter for your next leadership or board meeting. The question is not “are we secure?” That question invites a yes-or-no answer that is almost always misleading. The questions that matter are:
- Which vendors, contractors, or software tools currently have authenticated access to our systems or data?
- When did we last review whether each of those access relationships is still necessary and appropriately scoped?
- If one of our vendors was compromised tomorrow, what could an attacker reach through that vendor’s credentials?
- Do we have monitoring in place that would detect unusual behavior from a trusted third-party account?
- Have we actually tested our backup and recovery process, or are we assuming it works?
These questions require no technical expertise. They require the same accountability mindset a board member brings to financial controls, legal compliance, or operational risk. Cybersecurity risk — and specifically vendor ecosystem risk — belongs in that same conversation. The executives at M&S and Co-op are having it now. The question is whether you have it before or after an incident.
The personal accountability dimension matters here too. When a ransomware attack disrupts operations, exposes client data, or triggers regulatory scrutiny, the individuals responsible for governance are the ones answering for it. The business leader who can demonstrate that vendor access was actively managed and monitored is in a materially different position than the one who assumed the IT vendor was handling it.
Understanding Your Vendor Ecosystem Risk Surface: A Practical Starting Point
One of the most consistent gaps we find when working with a new client is the absence of a complete vendor access inventory. Most business leaders can name their primary IT vendor and their payroll platform. Far fewer can produce a current list of every third party holding active credentials or authenticated access to their systems. That gap is precisely where vendor ecosystem risk lives.
Building a vendor risk surface map does not have to be a months-long project. A structured discovery process starts with three questions: Who has access? What can they reach? When did you last verify that access is still appropriate?
The answers are often surprising. Credentials from a departed contractor that were never revoked. A legacy software integration still pulling data from a core system. A vendor whose security practices have never been evaluated. Each finding is manageable — but only once it is visible.
According to NIST’s Cybersecurity Framework, the “Identify” function — knowing what assets, data flows, and access relationships exist in your environment — is the foundational step before any other control can be meaningfully applied. You cannot protect what you have not mapped. The same principle applies directly to vendor ecosystem risk: visibility comes first, then control.
For organizations looking to get a clearer picture of their current exposure, our managed IT services include a structured onboarding assessment that surfaces vendor access gaps as a first step. It has become one of the most consistently valuable exercises we run with new clients — not because the findings are always alarming, but because mapping the surface gives leadership a concrete, actionable starting point.
The Quiet Firms Are the Ones Paying Attention
The 2025 attacks on M&S and Co-op will not be the last high-profile ransomware incidents of the year. The pattern is established, the tools are accessible to a widening pool of threat actors, and the vendor ecosystem attack vector has proven effective enough that it will keep being used. What these incidents reveal is not that good security is impossible. They reveal that good security requires looking beyond your own perimeter.
The firms that come through this period without an incident are not necessarily the ones with the largest IT budgets. They are the ones that mapped their vendor exposure, built controls around it, and put monitoring in place to catch problems while they are still containable. They reviewed access, enforced identity controls, and tested recovery plans before they needed them. That work does not make the news. That is precisely the point.
If you want to know where your vendor exposure actually stands, Book a Free Cybersecurity Strategy Call. It is a 20-minute conversation — no pressure, no obligation — and it starts with the questions that matter.
Frustrated With Your Current IT Provider?
If your current MSP isn’t catching the things this post describes, that’s a signal worth acting on. Book a strategy call and we’ll walk through what an honest IT partnership looks like for a business your size.