Skip to content
All industries
Retail and Luxury

Guest-facing speed without exposing your brand to Scattered Spider.

M&S took an estimated £300M hit to annual profit. Scattered Spider is still active, still social-engineering helpdesks, still ransoming retailers. Blacklight monitors the identity vectors and helpdesk workflows they exploit, and flags the social-engineering pattern before MFA bypass.

Incidents and active campaigns in your sector

The pattern is published.

Notable incidents and active campaigns in your sector. The attacker techniques are documented. The regulator timelines are running. Blacklight contains the same patterns autonomously, before the disclosure window opens.

  • Marks & Spencer
    Scattered Spider ransomware
    ~£300M profit impact / 46-day outage
  • Harrods
    UK retailer cyberattack
    ~430K customers
  • Louis Vuitton
    Data breach
    ~419K customers
  • Cartier
    Data breach
    Customer PII
  • Chanel
    ShinyHunters Salesforce theft
    Data stolen
  • Auchan
    Data breach
    Hundreds of thousands
Case in point

Marks & Spencer, April 2025: ~£300M profit impact, Scattered Spider

A helpdesk social-engineering call, 11 minutes, MFA reset on a privileged admin. That was the start. 46 days of outage followed. Online orders frozen, physical stores impacted, an estimated £300M wiped from annual profit. The attack pattern was known to the industry by the time it hit. No one stopped it because alerts were queued behind 1,200 other low-priority events. Blacklight flags the Scattered Spider helpdesk-reset pattern within 3 minutes of the call. The anomalous MFA reset on a privileged account from an unknown device and IP is auto-contained: tokens revoked, session killed, privileged group membership frozen pending human review. Loss avoided: tens of millions in the first hour alone.

The Blacklight difference
  • Correlated against live threat intel in seconds, not hours.
  • Contained autonomously, before the human analyst arrives.
  • Regulator-ready evidence, bundled and pre-drafted.
What Blacklight would do

Four moves,
on autopilot.

Every action is logged, explained, and reversible. The analyst always has the last word, but they get the case ready-made.

  • Flag Scattered Spider helpdesk social engineering patterns before MFA reset
  • Detect Salesforce / SaaS data-theft patterns used by ShinyHunters in real time
  • Autonomous containment of loyalty-database exfil before customer data moves
  • Protect against POS and e-commerce payment skimming across every store and channel
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.