Retail and security experts have urged fine food purveyors to take steps to protect their businesses and customers from cyber-attacks in the wake of major incidents involving high street grocers.
Marks & Spencer is still reeling from a “cyber incident” first disclosed in April, which has disrupted its website, app and phoneline orders. The retailer has warned the outage could cost it £300m, with some services not expected to resume until July. Meanwhile, more than 300 customers have reportedly joined a class action over the incident, which is alleged to involve compromised payment data.
The Co-op also confirmed in May that hackers had accessed and extracted information from one of its systems, affecting a “significant number” of past and present members.
The incidents have sparked warnings for smaller, independent businesses to be on their guard.
Darran Lindley, business development director at Fresh Retail, said the specialist consultancy had recently run an approved test where it had been able to hack into fine food firms’ systems.
“With a computer, YouTube and artificial intelligence, it is easy to set up an authentic phishing email that gains data,” he said.
“You can have a security plan in place but you don’t know how good it is until you test it. Marks & Spencer and the Co-op would have thought they had bulletproof systems but it just takes one phonecall.”
Lindley said collecting customer data was a valuable tool for increasing loyalty and spending but warned that it must be protected.
“The average hack is said to lead to losses of £4,000 and comes with obligations to report,” he added.
Emmeline Taylor, professor of criminology at City St George’s, University of London, said retailers were in the sights of cyber criminals.
“With e-commerce burgeoning and loyalty programmes expanding, the range and nature of sensitive data held by businesses is growing,” she added. “This makes an attractive proposition for offenders who will try to access this data to commit fraud or to leverage money from the business.
“Cyber-attacks can have a big impact – not just in the immediate aftermath as services and operations are disrupted but in the potential for irreversible reputational and brand damage.”
Mike Gillespie, chief executive of information security consultancy Advent IM, said many independent retailers did not have the benefit of large IT budgets or access to dedicated specialists.
But he warned: “It is vital that organisations of all sizes do the basics and do them well.”
This article first appeared in the June-July 2025 issue of Fine Food Digest.



