Executive Risk & Board Advisory

Fifteen Months, One Phone Call: How the Same Attack Went From Marks & Spencer to Apollo Global Management

Blog Meta Icon
Dipan Mann
Founder, CEO & CTO
Blog Meta Icon
August 31, 2026
Blog Meta Icon
10 minute read
Blog Main Image

In April 2025, someone called the Marks & Spencer IT help desk, impersonated an employee, and got a multi-factor authentication reset. In July 2026, someone called Apollo Global Management employees pretending to be internal IT and captured their credentials. Between those two events sit £1.9 billion in UK manufacturing losses, a 275-million-record education breach, and a Google threat advisory naming Blackstone, Bridgewater, and Bain Capital.

April 2025: the demonstration

On April 22, 2025, Marks & Spencer confirmed a cyber incident. Within days it had suspended all online and telephone orders and sent warehouse staff home. On April 30 the Co-operative Group detected suspicious activity and proactively shut down critical IT systems. On May 1 Harrods restricted internet access across its stores.

Three of Britain's most recognizable retailers, nine days.

The access method was the same at each. An attacker called an outsourced IT help desk, impersonated an employee, and convinced the agent to reset multi-factor authentication on a privileged account. At M&S that produced domain administrator access, the customer database, and the operational capability to deploy ransomware.

M&S was offline for 46 days. The Cyber Monitoring Centre assessed the combined M&S and Co-op impact at £270 to £440 million and classified it a Category 2 systemic event. In July, the National Crime Agency arrested four people aged 17 to 20.

Two things about that arrest record deserve attention. The first is that this tradecraft required no nation-state resources, no zero-day, and no exceptional technical skill. The second is that arresting four people did not stop the technique, because the technique is not a person.

The full account of the UK retail wave is in the Breach Library.

What the NCSC said in May 2025

On May 6, 2025, the UK National Cyber Security Centre issued updated guidance on defending against social engineering. It emphasized two things specifically: stronger verification protocols for help desks, and phishing-resistant multi-factor authentication.

That guidance was correct, published fifteen months before Apollo, and largely not acted on.

💡 Key Insight

Nobody needed a zero-day. From Marks & Spencer to Apollo Global Management, the entry point was a phone call to someone whose job is to be helpful.

September 2025: the escalation

On September 1, 2025, Jaguar Land Rover detected an intrusion and shut its IT systems down. Production stopped across Solihull, Halewood, and Wolverhampton and did not restart for five weeks.

The Cyber Monitoring Centre assessed the total economic loss at £1.9 billion, the most damaging cyber event in UK history. JLR reported roughly $350 million in direct loss. Q3 wholesale volumes fell 43.3 percent year over year. Around 5,000 supply chain businesses were affected, some of them facing insolvency because their largest customer had stopped ordering.

A group calling itself Scattered Lapsus$ Hunters claimed it. Security researchers noted the plausibility that data from earlier CRM and database compromises had been used to make a vishing campaign against JLR more targeted — employee directories stolen in one attack becoming the raw material for the next.

JLR had an £800 million cybersecurity and IT contract with Tata Consultancy Services. Full account here.

March through July 2026: the industrialization

In March 2026, Aura — a company that sells identity theft protection — lost approximately 900,000 records when an attacker vished an employee. ShinyHunters claimed it.

In April and May, Canvas / Instructure was compromised twice, exposing 275 million student and staff records.

In June, DentaQuest declined to pay and 234 gigabytes covering 2.6 million people went public.

In July, RingCentral declined to pay and 1.6 million customer records went public.

Each of these was reported as a discrete event. They were not discrete. They were the same technique, refined against progressively higher-value targets, over sixteen months, in public.

15 months
From the first Marks & Spencer helpdesk call in April 2025 to Apollo Global Management's disclosure in August 2026
17 to 20
The ages of the four people arrested by the National Crime Agency for the UK retail attacks
£2.8 billion
Combined assessed impact of the UK retail wave and Jaguar Land Rover alone, before Wall Street

July 2026: Wall Street

Between July 6 and July 10, 2026, attackers accessed Apollo Global Management's cloud platforms and exfiltrated names, dates of birth, home addresses, contact details, and Social Security numbers. Apollo's forensic team confirmed the exfiltration on August 12. The company disclosed publicly on August 21.

The method, per Apollo's own notice: advanced social engineering rather than software vulnerability exploits. Attackers called employees posing as internal IT help desk, walked them to lookalike sign-in portals, and captured credentials and MFA codes.

Google's Threat Intelligence Group had publicly warned weeks earlier that a coordinated vishing campaign was targeting private equity and financial firms. Reuters reported the target list includes Blackstone, Bridgewater Associates, and Bain Capital.

Apollo manages roughly $700 billion. Blackstone manages a trillion. Bridgewater manages around $150 billion. Bain manages roughly $185 billion.

All of them were reachable by the technique that took Marks & Spencer offline fifteen months earlier. Full account.

Why fifteen months of warning produced no defense

The technique was public. The NCSC published guidance in May 2025. Every incident was covered by the trade press and most by the mainstream press. The controls that stop it — phishing-resistant MFA and hardened help desk verification — are neither novel nor expensive.

Three reasons the warning did not convert.

Every organization read the wrong lesson. The coverage framed M&S as a retail story, JLR as a manufacturing story, Aura as an irony story, and Apollo as a Wall Street story. Sector framing let every reader outside that sector conclude the story was not about them. It was about the help desk, and everyone has one.

"We have MFA" felt like an answer. It is not, and the distinction is technical enough that it did not land. MFA verifies the login. The attack steals the session token the login produces, or has the help desk reset the factor entirely. Every victim organization in this sequence had MFA deployed.

The help desk is not where security attention goes. It is a cost center, frequently outsourced, measured on resolution speed. Nobody's security roadmap has help desk verification procedure on it. It is now the most consequential control most organizations have not examined.

Conclusion

The four people the National Crime Agency arrested in July 2025 were aged 17 to 20. Between the technique they used and Apollo Global Management sat fifteen months, a £1.9 billion manufacturing shutdown, an NCSC advisory nobody actioned, and roughly $2 trillion in assets under management at the firms that were targeted next. The exploit was a phone call. It is still a phone call. The only question a board should be asking this week is whether their own help desk would take it.

CLOUDSKOPE VIEW

Cloudskope advises PE deal teams, portfolio company boards, and general counsel on identity exposure and cyber diligence. SARTUS is our fixed-fee six-day engagement: three days of assessment across identity, cloud posture, credential exposure, and active-compromise indicators, three days of done-for-you remediation.

TAGS