{"id":459893,"date":"2026-04-17T16:37:00","date_gmt":"2026-04-17T15:37:00","guid":{"rendered":"https:\/\/www.drapersonline.com\/?p=459893"},"modified":"2026-04-20T14:32:28","modified_gmt":"2026-04-20T13:32:28","slug":"how-is-fashion-retail-recovering-from-cyber-attacks","status":"publish","type":"post","link":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks","title":{"rendered":"Cyber-attacks one year on: is fashion retail more secure?"},"content":{"rendered":"<p><span data-contrast=\"auto\">One year after a wave of cyber-attacks sent shockwaves through UK fashion retail \u2013 and Marks &amp; Spencer shut down some operations to contain the effects of a targeted infiltration \u2013 the industry is still reckoning with the fallout.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">High-profile breaches at some of the industry\u2019s biggest retailers, including Marks &amp; Spencer, Harrods, LVMH, Adidas\u00a0and Victoria\u2019s Secret, and in the wider business world, the Co-op Group and Jaguar Land Rover, among others, exposed vulnerabilities in the safekeeping of customer and staff data, alongside disrupting supply chains and internal systems \u2013 highlighting just how vulnerable some fashion retail businesses are to a new era of cyber-crime.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>Drapers conducted an online survey between 13 February and 17 March, to explore the extent to which cyber-attacks had affected fashion retail. Given the nature of the vulnerability, responses must be kept anonymous, but our findings nevertheless paint a worrying picture of an industry playing catch-up.<\/p>\n<p>The government&#8217;s Cyber Security Breaches Survey 2025 found that 43% of businesses had reported having experienced any kind of cyber-security breach or attack in the 12 months to June 2025.<\/p>\n<div class=\"factfile\">\n<h4><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-451608 alignleft\" src=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/11\/20141200\/DFOF26_Index-300x200.webp\" alt=\"\" width=\"300\" height=\"200\" srcset=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/11\/20141200\/DFOF26_Index-300x200.webp 300w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/11\/20141200\/DFOF26_Index-185x123.webp 185w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/11\/20141200\/DFOF26_Index-230x153.webp 230w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/11\/20141200\/DFOF26_Index-150x100.webp 150w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>Join fashion retail&#8217;s tech transformers<\/h4>\n<p>Drapers Future of Fashion is a one-day conference and networking event, bringing together industry experts in fashion retail to focus on the role of technology and innovation. The event examines the key technologies, trends and topics driving transformation within the sector.<\/p>\n<p>This year, it is free to attend for fashion retailers and brands for the first time. <a href=\"https:\/\/future.drapersonline.com\/dfof2026\/en\/page\/home\">Register your interest to attend<\/a><\/p>\n<\/div>\n<p><span data-contrast=\"auto\">The pressure to strengthen defences is reflected in rising investment:<\/span><span data-contrast=\"auto\"> 85% of UK businesses across all sectors plan to increase their cyber-security budgets in 2026, PWC\u2019s 2026 Global Digital Trust Insights survey published in October 2025 found.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>Executive-level chief information security officer (CISO) titles now dominate, and a larger share hold executive roles than vice-president or director titles for the first time, rising in large enterprises from 33% in 2023 to 47% in 2025, IANS and Artico Search\u2019s 2026 State of the CISO Benchmark Report, published on 15 January 2026, shows.<strong>\u00a0<\/strong><\/p>\n<p><span data-contrast=\"auto\">Moreover, nearly two-thirds of retailers increased their focus on cyber-resilience in 2025, including system upgrades and board-level planning, <\/span><span data-contrast=\"auto\">while 58% of retail leaders ranked cyber-security as a top-three priority, ahead of financial and operational risks, in June 2025 research <\/span><span data-contrast=\"auto\">by Retail Economics and Barclays UK Corporate Banking.\u00a0Despite this, only one in four\u00a0of the 117 surveyed retail executives\u00a0felt\u00a0\u201chighly prepared\u201d for a major attack.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Fashion retailers must act early, train relentlessly and be on ever-escalating levels of alert to combat future incidents and protect their operations, staff and customers from bad actors. However, fashion retail businesses tell <\/span><span data-contrast=\"auto\">Drapers that budgets,<\/span>\u00a0relationships with suppliers<span data-contrast=\"auto\">\u00a0and\u00a0the fast-moving evolution of cyber-crime techniques<\/span><b><span data-contrast=\"auto\">\u00a0<\/span><\/b><span data-contrast=\"auto\">continue to<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">keep them on their toes.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2>Ripple effect of breaches in cyber-security<\/h2>\n<p><span data-contrast=\"auto\">A wave of high-profile cyber-attacks last year exposed just how vulnerable even the most established retailers have become. Among the hardest hit was Marks &amp; Spencer, which\u00a0in April 2025\u00a0was forced to suspend parts of its ecommerce operations for\u00a0six\u00a0weeks, disrupting online orders and denting\u00a0sales, particularly in its clothing and home division,\u00a0<\/span><span data-contrast=\"auto\">by\u00a0<\/span><span data-contrast=\"auto\">\u00a3136m<\/span><span data-contrast=\"auto\">, it\u00a0revealed\u00a0in its\u00a0interim\u00a0results\u00a0for the 26 weeks to 27 September 2025<\/span><span data-contrast=\"auto\">.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Only weeks later, hackers targeted luxury players Harrods and Dior, while US-based lingerie retailer Victoria\u2019s Secret also experienced a breach affecting customer data in May 2025.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<div id=\"attachment_438063\" class=\"wp-caption alignnone\" style=\"max-width: 2570px;\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-438063 size-full\" src=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-scaled.webp\" alt=\"Dior store from Shutterstock\" width=\"2560\" height=\"1798\" srcset=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-scaled.webp 2560w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-300x211.webp 300w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-1024x719.webp 1024w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-768x539.webp 768w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-1567x1100.webp 1567w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-1709x1200.webp 1709w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-1536x1079.webp 1536w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-2048x1438.webp 2048w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-230x162.webp 230w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/05\/15080112\/Dior-store-from-Shutterstock-150x105.webp 150w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><p class=\"wp-caption-text\">Dior was targeted in a cyber-attack in May 2025<\/p>\n\t<p class=\"inline_image_source\" style=\"max-width: 2570px;\"><p class=\"empty_inline_source\"><\/p><\/p><\/div>\n<p><span data-contrast=\"auto\">The impact extended beyond fashion: supermarket chain Co-op faced significant operational disruption following a cyber-incident in April 2025 that cost \u00a3206m in lost sales, and car manufacturer Jaguar Land Rover was forced to halt production at multiple sites late August and September 2025 after systems were compromised. <\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">For brands\u00a0operating\u00a0within larger retail ecosystems, the consequences of a cyber-attack can be immediate \u2013 and severe.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">A leader a<\/span><span data-contrast=\"auto\">t\u00a0<\/span><span data-contrast=\"auto\">one\u00a0womenswear brand sold through M&amp;S<\/span><span data-contrast=\"auto\">\u00a0describes the experience a<\/span><span data-contrast=\"auto\">s\u00a0challenging<\/span><span data-contrast=\"auto\">,\u00a0particularly given the brand\u2019s reliance on the retailer\u2019s platform.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIt was quite painful f<\/span><span data-contrast=\"auto\">or us as a small brand, because we had a relatively large exposure. Over the last few weeks, though, we\u2019ve started to see some really positive signs [of a sales rebound]. It\u2019s not back to where it was before \u2013 not completely \u2013 but it\u2019s much, much better.<\/span><\/p>\n<div class=\"factfile\">\n<h4>The cyber-security threat by numbers<\/h4>\n<p>43% of businesses experienced a cyber-security breach or attack in the 12 months to June 2025<\/p>\n<p style=\"text-align: right;\">Source: Government&#8217;s Cyber Security Breaches Survey 2025<\/p>\n<p><span data-contrast=\"auto\">85% of UK businesses across all sectors plan to increase their cyber-security budgets in 2026<\/span><\/p>\n<p style=\"text-align: right;\">Source: <span data-contrast=\"auto\">PWC\u2019s 2026 Global Digital Trust Insights survey<\/span><\/p>\n<p><span data-contrast=\"auto\">58% of retail leaders ranked cyber-security as a top-three priority, ahead of financial and operational risks\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Two-thirds of retailers have increased their focus on cyber-resilience<\/span><\/p>\n<p><span data-contrast=\"auto\">One in four retail executives feel \u201chighly prepared\u201d for a major attack<\/span><\/p>\n<p style=\"text-align: right;\">Source: <span data-contrast=\"auto\">Retail Economics and Barclays UK Corporate Banking survey June 2025<\/span><\/p>\n<\/div>\n<p><span data-contrast=\"auto\">\u201c[The team at M&amp;S] have all worked incredibly hard. It is such a shame that something that&#8217;s outside of their control had had such a massive impact.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p>A spokesperson for M&amp;S told Drapers last week: &#8220;[We] can confirm that brands have started to receive automated sales and stock reports again from this week.&#8221;<\/p>\n<p><span data-contrast=\"auto\">The experience highlights a key theme echoed across the industry: cyber-incidents rarely affect just one business. Instead, they cascade through supply chains, marketplaces and partnerships, amplifying the damage.<\/span><\/p>\n<h2>Cyber-vulnerability from under-investment<\/h2>\n<p><span data-contrast=\"auto\">For those tasked with protecting retail businesses, the past year has exposed deeper structural issues.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">A head of information security at one medium-sized fashion retailer, which was targeted in a cyber-attack in the early 2020s, says the industry is still dealing with the consequences of years of under-investment: \u201cWe\u2019re now trying to catch up while the threat landscape is getting more serious.<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cA lot of retailers have strengthened their own businesses quite significantly over the last year, but what we don\u2019t have great control over is the standards within the supply chain.&#8221;<\/span><\/p>\n<p><span data-contrast=\"auto\">One respondent to Drapers\u2019 survey says they had invested \u201csignificantly\u201d and remained confident. <\/span><\/p>\n<p><span data-contrast=\"auto\">However, another is as \u201cconfident as can be\u201d with the measures they are taking, but \u201cstill feel exposed to new methods\u201d.<\/span><\/p>\n<p><span data-contrast=\"auto\">Respondents cited ransomware, phishing and social engineering and\u00a0customer data breaches as posing the\u00a0greatest risks to their organisation.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This growing reliance on third-party providers is creating new entry points for attackers, while the scale of the threat is also evolving. As in other sectors, retailers are increasingly facing artificial intelligence-driven phishing, whereby cyber-criminals use AI to create highly convincing emails \u2013 such as fake supplier invoices \u2013 messages and even voice calls that match genuine formatting and tone.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<blockquote><p><span data-contrast=\"auto\">Why can\u2019t the BTs, Virgins\u00a0and Skys of the world be proactively\u00a0blocking more of\u00a0[bot and other malicious actors]\u00a0traffic?<\/span><\/p>\n<p><span data-contrast=\"auto\">Head of information security, fashion retailer<\/span><\/p><\/blockquote>\n<p><span data-contrast=\"auto\">The\u00a0head of information security\u00a0tells Drapers:\u00a0\u201cIf a supplier is compromised, you\u2019re suddenly in a much more vulnerable position because there\u2019s already trust between the businesses.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">More\u00a0should\u00a0be done at a systemic level to reduce exposure, he adds:\u00a0\u201cOne of the biggest things\u00a0government\u00a0could do is put more pressure on internet service providers to moderate what\u00a0they\u2019re\u00a0allowing through their networks. Why can\u2019t the BTs, Virgins\u00a0and Skys of the world be proactively\u00a0blocking more of\u00a0[bot and other malicious actors]\u00a0traffic?\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The UK government already has significant enforcement powers when it comes to cyber-security, primarily through the Information Commissioner\u2019s Office, which can issue fines of up to \u00a317.5m or 4% of global turnover, whichever is higher, the system remains largely reactive, relying on companies to assess and manage their own risk. <\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Newer legislation, including the proposed <span class=\"NormalTextRun CommentStart CommentHighlightPipeClicked CommentHighlightClicked CommentImportant SCXW108024627 BCX0\">Cyber Security and Resilience Bill<\/span><span class=\"NormalTextRun CommentHighlightClicked CommentImportant SCXW108024627 BCX0\">, which had its second reading in January<\/span>, is expected to strengthen oversight and give government greater powers to intervene during active threats, such as by directing companies to isolate systems, share information and take urgent remedial action.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2>Recovery:\u00a0slow but transformative<\/h2>\n<p><span data-contrast=\"auto\">For businesses that have experienced a cyber-attack first hand, recovery is rarely quick.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIt took us about six months just to get to a point where we were getting by again,\u201d says the same security lead. \u201cIt took around 18 months before we were really firing on all cylinders.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Even then, the process does not end: \u201cThe long-term drag is the mop-up: the ICO [Information Commissioner&#8217;s Office] conversations, the card providers and the legal fallout.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Following the incident, the retailer took steps to block any website traffic from countries where it does not trade, including China and Russia, to reduce malicious bot traffic.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<div id=\"attachment_445741\" class=\"wp-caption alignnone\" style=\"max-width: 2110px;\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-445741 size-full\" src=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index.webp\" alt=\"M&amp;S CEO Stuart Machin The Drapers Interview 2025\" width=\"2100\" height=\"1400\" srcset=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index.webp 2100w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-300x200.webp 300w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-1024x683.webp 1024w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-768x512.webp 768w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-1000x666.webp 1000w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-748x499.webp 748w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-492x328.webp 492w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-1600x1067.webp 1600w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-1800x1200.webp 1800w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-391x260.webp 391w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-1536x1024.webp 1536w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-2048x1365.webp 2048w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-185x123.webp 185w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-230x153.webp 230w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/09\/04103213\/Drapers_StuartMachin-index-150x100.webp 150w\" sizes=\"(max-width: 2100px) 100vw, 2100px\" \/><p class=\"wp-caption-text\"><a href=\"https:\/\/www.drapersonline.com\/people\/the-drapers-interview\/marks-spencer-ceo-stuart-machin-reveals-his-masterplan\">Read how Mark &amp; Spencer&#8217;s Stuart Machin dealt with the cyber-attack<\/a> Photography by Benjamin McMahon<\/p>\n\t<p class=\"inline_image_source\" style=\"max-width: 2110px;\"><p class=\"empty_inline_source\"><\/p><\/p><\/div>\n<p><span data-contrast=\"auto\">It now also requires all suppliers to meet a UK government-backed audited cyber-security assessment Cyber Essentials \u201cas a baseline\u201d:\u00a0<\/span><span data-contrast=\"auto\">\u201cIt gives retailers a way of holding themselves to\u00a0account, but\u00a0also holding the people they work with to account.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Yet, amid the disruption, a dreaded cyber-attack can provide an opportunity to scale investment into cyber-security, to ensure a situation like this never happens again:<\/span> <span data-contrast=\"auto\">\u201cIn some ways, an attack can be the biggest opportunity you\u2019ll ever have to modernise. You suddenly have more support from the board and more money to spend than you\u2019ve ever had before.<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIf you can survive the financial hit [of a cyber-attack], you often come out much stronger.\u201d<\/span><\/p>\n<h2>The culture gap<\/h2>\n<p><span data-contrast=\"auto\">Despite increased awareness of cyber-security through mandated employee tests and phishing exercises, a gap remains between policy and practice, particularly at an operational level.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The<\/span><b><span data-contrast=\"auto\">\u00a0<\/span><\/b><span data-contrast=\"auto\">wholesale manager of a womenswear brand that was impacted <\/span><span data-contrast=\"auto\">through a third-party stockist<\/span><b> <\/b><span data-contrast=\"auto\">says that<\/span><b><span data-contrast=\"auto\">\u00a0<\/span><\/b><span data-contrast=\"auto\">in many businesses, cyber-security still lacks urgency: <\/span><span data-contrast=\"auto\">\u201cA lot of people assume cyber-security is under control \u2013 until something happens that proves it isn\u2019t.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">He describes last year\u2019s fashion retail <\/span><span data-contrast=\"auto\">cyber-attacks\u00a0as<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">\u201ca real wake-up call \u2013 it made businesses sit up and take notice&#8221;.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">However, internal training and engagement are inconsistent: \u201cThe training was there, but it didn\u2019t always feel like a priority \u2026\u00a0 it\u2019s easy for people to just tick the box and move on.\u201d<\/span><\/p>\n<p><span data-contrast=\"auto\">Standardised training programmes, while useful, can fall short in practice:\u00a0<\/span><span data-contrast=\"auto\">\u201cYou watch the video, answer a few questions, pass the course\u00a0\u2013\u00a0and then\u00a0it\u2019s\u00a0done. It becomes quite a tick-box exercise.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Hybrid working has added another layer of complexity.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cWith hybrid working, it\u2019s much harder to reinforce how important this is when you\u2019re not all in the same room.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Crucially, responsibility\u00a0over keeping a business secure\u00a0is often misunderstood.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIt can\u2019t just sit with IT\u00a0\u2013\u00a0everyone in the business has a role to play,\u201d\u00a0he tells Drapers.\u00a0\u201cEveryone can click a link.\u00a0That\u2019s\u00a0why everyone\u00a0has to\u00a0be part of the solution.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2>Independents in the firing line<\/h2>\n<p><span data-contrast=\"auto\">While large retailers dominate headlines, independent fashion retailers are also increasingly targeted. Recent victims include Sandersons Department Stores, Jules B and The Dressing Room, alongside up to 300 independent fashion, home and outdoor retailers that were customers of retail operations supplier Swan Retail, which was hit by a ransomware attack in August 2023.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Deryane Tadd, owner of St Albans womenswear independent The Dressing Room, says her business \u201clost in the region of \u00a3500,000 in turnover\u201d during an attack that affected its website, EPoS and stock systems in early 2024.<\/span><\/p>\n<p><span data-contrast=\"auto\">Tadd took the incident as an opportunity to patch gaps in preparedness and protection: The Dressing Room\u2019s website underwent a full security audit, blocked any malicious websites from linking to the store and started rebuilding its online presence with content, SEO, strong copywriting, blog content and link building to return to the top of Google search results.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<div id=\"attachment_435709\" class=\"wp-caption aligncenter\" style=\"max-width: 730px;\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-435709 size-full\" src=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2.webp\" alt=\"Deryane Tadd, The Dressing Room. Photograph by Roger Bool, 2025\" width=\"720\" height=\"480\" srcset=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2.webp 720w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2-300x200.webp 300w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2-492x328.webp 492w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2-391x260.webp 391w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2-185x123.webp 185w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2-230x153.webp 230w, https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2025\/03\/09154222\/Deryane-Tadd-The-Dressing-Room-2025-2-150x100.webp 150w\" sizes=\"(max-width: 720px) 100vw, 720px\" \/><p class=\"wp-caption-text\">Deryane Tadd, photographed by Roger Bool<\/p>\n\t<p class=\"inline_image_source\" style=\"max-width: 730px;\"><p class=\"empty_inline_source\"><\/p><\/p><\/div>\n<blockquote><p><span data-contrast=\"auto\">It would be good to ensure that general shop and business insurances cover cyber-security rather than having to take a separate policy <\/span><\/p>\n<p><span data-contrast=\"auto\">Deryane Tadd, owner of St Albans womenswear independent The Dressing Room<\/span><\/p><\/blockquote>\n<p><span data-contrast=\"auto\">Following the experience, Tadd emphasises the importance of internal capability: \u201cA broader understanding of how to check your website\u2019s health is beneficial. Relying solely on third parties can be problematic when you encounter an issue.<\/span><\/p>\n<p><span data-contrast=\"auto\">She adds: \u201cIt would be good to ensure that general shop and business insurances cover cyber-security rather than having to take a separate policy \u2013 it often doesn\u2019t occur to you that you will need it until you do.\u201d<\/span><\/p>\n<p><span data-contrast=\"auto\">This comes at a cost: depending on the size of the retailer and the level of cyber-risk it faces, insurance packages can range from \u00a3800 a year for small businesses (11 to 50 employees) to more than \u00a310,000 for high-risk large corporations, UK-based insurance broker JMG Group suggests. Insurance costs are on the rise: 70% of 750 security leaders surveyed by cyber-security provider Delinea in late 2025 reported cost increases when applying for or renewing their cyber-insurance policies \u2013 up from 50% in the previous year.<\/span><\/p>\n<p><span data-contrast=\"auto\">The head of information security at one fashion retailer tells Drapers that he has seen a year-on-year increase of 5% to 12% in insurance costs, but the business has <\/span>been able to successfully negotiate a lower rate: <span data-contrast=\"auto\">\u201c<\/span>We have seen some price increases through investments in new tech, some AI-based defences like data loss prevention.<\/p>\n<p><span data-contrast=\"auto\">\u201c<\/span>I also think on the back of the last year there is a possibility that some retailers have more heavily invested in disaster recovery and 24\/7 capabilities,<span data-contrast=\"auto\">\u201d<\/span>\u00a0he adds.<\/p>\n<h2>Legal reality:\u00a0\u2018not a question of if, but when\u2019<\/h2>\n<p><span data-contrast=\"auto\">Mark Chapman, partner at law firm\u00a0Herrington Carmichael, says retailers can no longer afford to treat cyber-risk as a secondary concern:\u00a0<\/span><span data-contrast=\"auto\">\u201cCyber-attacks\u00a0are no longer a question of if, but when\u00a0\u2013\u00a0and retailers that aren\u2019t prepared are already on the back foot.\u201d<a href=\"https:\/\/www.drapersonline.com\/insight\/legal-advice-for-mitigating-cyber-risks\"><b> Read Mark Chapman&#8217;s legal advice here<\/b><\/a><\/span><\/p>\n<p><span data-contrast=\"auto\">Preparedness, he argues, must be proactive:\u00a0\u201cYou cannot wait until an incident happens to decide how you\u2019re going to respond.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Regulatory pressure adds urgency. Under UK GDPR rules, businesses have just 72 hours to report certain breaches.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<div class=\"factfile\">\n<h4>What triggers the 72-hour reporting rule?<\/h4>\n<p>Under UK GDPR, you must report to the Information Commissioner&#8217;s Office within 72 hours if there has been a personal data breach.\u00a0That means a breach involving personal data, such as:<\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Customer data (names, emails, addresses, payment info)<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Employee data (HR records, payroll, IDs)<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Supplier\/partner contact details<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Any data that can\u00a0identify\u00a0a living individual<\/li>\n<\/ul>\n<p>This\u00a0includes:<\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Data being accessed without authorisation<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Data being lost or deleted<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Data being sent to the wrong person<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\">Systems being unavailable (e.g. ransomware) if personal data is affected<\/li>\n<\/ul>\n<\/div>\n<p><span data-contrast=\"auto\">Even in uncertain situations, action is\u00a0required.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIf you\u2019re not sure what\u2019s happened, you still need to notify [the ICO] and update as you learn more.\u201d<\/span><\/p>\n<h2>A turning point for the industry?<\/h2>\n<p><span data-contrast=\"auto\">One year on from a series of disruptive attacks, there are signs of progress\u00a0\u2013\u00a0but also\u00a0clear evidence\u00a0that the industry still has work to do.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Investment is increasing. Awareness is rising. But gaps\u00a0remain\u00a0in culture, supply chain\u00a0oversight\u00a0and internal accountability<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">As one retail professional put it: \u201cThe hardest thing is convincing people it could actually happen to them.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The challenge now is to move from reactive to proactive. Cyber-attacks are no longer a distant threat: they are a present, persistent reality and successful retailers will prioritise preparedness, invest at board level and build resilience, across their own operations and their supply chains.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One year after a wave of cyber-attacks sent shockwaves through UK fashion retail \u2013 and Marks &amp; Spencer shut down some operations to contain the effects of a targeted infiltration \u2013 the industry is still reckoning with the fallout.\u00a0 High-profile breaches at some of the industry\u2019s biggest retailers, including Marks &amp; Spencer, Harrods, LVMH, Adidas\u00a0and &#8230;<\/p>\n","protected":false},"author":100686,"featured_media":461603,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_oasis_is_in_workflow":0,"_oasis_original":0,"ep_exclude_from_search":false,"footnotes":""},"categories":[963,7742,76780],"tags":[],"class_list":["post-459893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-and-tech","category-digital-and-tech-topics","category-subscriber-only-content","editorial-digital-tech","editorial-technology"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.7 (Yoast SEO v26.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cyber-attacks one year on: is fashion retail more secure?<\/title>\n<meta name=\"description\" content=\"Last year\u2019s cyber-attacks on some of the industry\u2019s biggest names\u00a0have forced fashion retail to take security seriously \u2013\u00a0but\u00a0despite greater investment, there remains a lack of confidence in their defences.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber-attacks one year on: is fashion retail more secure?\" \/>\n<meta property=\"og:description\" content=\"Last year\u2019s cyber-attacks on some of the industry\u2019s biggest names\u00a0have forced fashion retail to take security seriously \u2013\u00a0but\u00a0despite greater investment, there remains a lack of confidence in their defences.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks\" \/>\n<meta property=\"og:site_name\" content=\"Drapers\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-17T15:37:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-20T13:32:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1-560x315.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"560\" \/>\n\t<meta property=\"og:image:height\" content=\"315\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sabina Weston\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sabina Weston\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks\"},\"author\":{\"name\":\"Sabina Weston\",\"@id\":\"https:\/\/www.drapersonline.com\/#\/schema\/person\/5b1aa19432ac14a74880f38584a12593\"},\"headline\":\"Cyber-attacks one year on: is fashion retail more secure?\",\"datePublished\":\"2026-04-17T15:37:00+00:00\",\"dateModified\":\"2026-04-20T13:32:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks\"},\"wordCount\":2536,\"commentCount\":0,\"image\":{\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp\",\"articleSection\":[\"Digital + tech\",\"Digital and Tech\",\"Subscriber-only content\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks\",\"url\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks\",\"name\":\"Cyber-attacks one year on: is fashion retail more secure?\",\"isPartOf\":{\"@id\":\"https:\/\/www.drapersonline.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp\",\"datePublished\":\"2026-04-17T15:37:00+00:00\",\"dateModified\":\"2026-04-20T13:32:28+00:00\",\"author\":{\"@id\":\"https:\/\/www.drapersonline.com\/#\/schema\/person\/5b1aa19432ac14a74880f38584a12593\"},\"description\":\"Last year\u2019s cyber-attacks on some of the industry\u2019s biggest names\u00a0have forced fashion retail to take security seriously \u2013\u00a0but\u00a0despite greater investment, there remains a lack of confidence in their defences.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage\",\"url\":\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp\",\"contentUrl\":\"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp\",\"width\":2100,\"height\":1400,\"caption\":\"Robot peeping from computer monitor. Surveillance, artifical intelligence anxiety, internet spying concept. Vector illustration.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.drapersonline.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber-attacks one year on: is fashion retail more secure?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.drapersonline.com\/#website\",\"url\":\"https:\/\/www.drapersonline.com\/\",\"name\":\"Drapers\",\"description\":\"Fashion retail industry news, trends and analysis\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.drapersonline.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.drapersonline.com\/#\/schema\/person\/5b1aa19432ac14a74880f38584a12593\",\"name\":\"Sabina Weston\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.drapersonline.com\/#\/schema\/person\/image\/1143e08624b4dfcba69d1e1b72216912\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a8e7b75e640cf0670d96f4826b2bacc8f1ab58d1d14013963557257a7d238d3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a8e7b75e640cf0670d96f4826b2bacc8f1ab58d1d14013963557257a7d238d3e?s=96&d=mm&r=g\",\"caption\":\"Sabina Weston\"},\"description\":\"Sabina Weston joined Drapers in May 2022, driving fashion retail exclusives, reporting from fashion weeks and trade shows as well as profiling industry executives from businesses including Marks &amp; Spencer, New Look, John Lewis and Urban Outfitters for Drapers\u2019 My Fashion Life and How I Got Here interviews. A graduate of City, University of London\u2019s MA magazine journalism course, Sabina started her reporting career as a writer for online technology news publication IT Pro. For news tips or interview pitches, email Sabina at sabina.weston@emap.com.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/sabina-weston-903039153\/\"],\"url\":\"https:\/\/www.drapersonline.com\/author\/sabina-weston-2\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Cyber-attacks one year on: is fashion retail more secure?","description":"Last year\u2019s cyber-attacks on some of the industry\u2019s biggest names\u00a0have forced fashion retail to take security seriously \u2013\u00a0but\u00a0despite greater investment, there remains a lack of confidence in their defences.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks","og_locale":"en_US","og_type":"article","og_title":"Cyber-attacks one year on: is fashion retail more secure?","og_description":"Last year\u2019s cyber-attacks on some of the industry\u2019s biggest names\u00a0have forced fashion retail to take security seriously \u2013\u00a0but\u00a0despite greater investment, there remains a lack of confidence in their defences.","og_url":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks","og_site_name":"Drapers","article_published_time":"2026-04-17T15:37:00+00:00","article_modified_time":"2026-04-20T13:32:28+00:00","og_image":[{"width":560,"height":315,"url":"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1-560x315.jpg","type":"image\/jpeg"}],"author":"Sabina Weston","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sabina Weston","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#article","isPartOf":{"@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks"},"author":{"name":"Sabina Weston","@id":"https:\/\/www.drapersonline.com\/#\/schema\/person\/5b1aa19432ac14a74880f38584a12593"},"headline":"Cyber-attacks one year on: is fashion retail more secure?","datePublished":"2026-04-17T15:37:00+00:00","dateModified":"2026-04-20T13:32:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks"},"wordCount":2536,"commentCount":0,"image":{"@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage"},"thumbnailUrl":"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp","articleSection":["Digital + tech","Digital and Tech","Subscriber-only content"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks","url":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks","name":"Cyber-attacks one year on: is fashion retail more secure?","isPartOf":{"@id":"https:\/\/www.drapersonline.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage"},"image":{"@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage"},"thumbnailUrl":"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp","datePublished":"2026-04-17T15:37:00+00:00","dateModified":"2026-04-20T13:32:28+00:00","author":{"@id":"https:\/\/www.drapersonline.com\/#\/schema\/person\/5b1aa19432ac14a74880f38584a12593"},"description":"Last year\u2019s cyber-attacks on some of the industry\u2019s biggest names\u00a0have forced fashion retail to take security seriously \u2013\u00a0but\u00a0despite greater investment, there remains a lack of confidence in their defences.","breadcrumb":{"@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#primaryimage","url":"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp","contentUrl":"https:\/\/cdn.rt.emap.com\/wp-content\/uploads\/sites\/2\/2026\/05\/17153204\/CYBER-ATTACK-SINGLE-USE-MAY-2026-DRAPERS-GettyImages-1746666469-Converted-copy-1.webp","width":2100,"height":1400,"caption":"Robot peeping from computer monitor. Surveillance, artifical intelligence anxiety, internet spying concept. Vector illustration."},{"@type":"BreadcrumbList","@id":"https:\/\/www.drapersonline.com\/topics\/digital-and-tech-topics\/how-is-fashion-retail-recovering-from-cyber-attacks#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.drapersonline.com\/"},{"@type":"ListItem","position":2,"name":"Cyber-attacks one year on: is fashion retail more secure?"}]},{"@type":"WebSite","@id":"https:\/\/www.drapersonline.com\/#website","url":"https:\/\/www.drapersonline.com\/","name":"Drapers","description":"Fashion retail industry news, trends and analysis","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.drapersonline.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.drapersonline.com\/#\/schema\/person\/5b1aa19432ac14a74880f38584a12593","name":"Sabina Weston","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.drapersonline.com\/#\/schema\/person\/image\/1143e08624b4dfcba69d1e1b72216912","url":"https:\/\/secure.gravatar.com\/avatar\/a8e7b75e640cf0670d96f4826b2bacc8f1ab58d1d14013963557257a7d238d3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a8e7b75e640cf0670d96f4826b2bacc8f1ab58d1d14013963557257a7d238d3e?s=96&d=mm&r=g","caption":"Sabina Weston"},"description":"Sabina Weston joined Drapers in May 2022, driving fashion retail exclusives, reporting from fashion weeks and trade shows as well as profiling industry executives from businesses including Marks &amp; Spencer, New Look, John Lewis and Urban Outfitters for Drapers\u2019 My Fashion Life and How I Got Here interviews. A graduate of City, University of London\u2019s MA magazine journalism course, Sabina started her reporting career as a writer for online technology news publication IT Pro. For news tips or interview pitches, email Sabina at sabina.weston@emap.com.","sameAs":["https:\/\/www.linkedin.com\/in\/sabina-weston-903039153\/"],"url":"https:\/\/www.drapersonline.com\/author\/sabina-weston-2"}]}},"_links":{"self":[{"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/posts\/459893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/users\/100686"}],"replies":[{"embeddable":true,"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/comments?post=459893"}],"version-history":[{"count":18,"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/posts\/459893\/revisions"}],"predecessor-version":[{"id":461627,"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/posts\/459893\/revisions\/461627"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/media\/461603"}],"wp:attachment":[{"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/media?parent=459893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/categories?post=459893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.drapersonline.com\/wp-json\/wp\/v2\/tags?post=459893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}