top of page

-- INSIGHTS
The Human Side of Cybersecurity
Cybersecurity incidents are rarely just technical. They are shaped by employee decisions, security culture, phishing and social engineering, AI use, and the way organizations respond to risk.
HumanSecIQ Insights examines those factors through practical guidance, analysis, and real-world cybersecurity incidents.
LATEST
Latest Insights
Insights, guidance, and practical perspectives on human risk, security culture, and AI governance.


Co-op Cyber Incident 2025: Third-Party Access and the Decision to Disconnect
The third UK retailer hit in a two-week wave detected its intruders in hours, cut its own network before the ransomware could fire, and never paid a penny. It still lost the data of all 6.5 million members and £206 million in sales. This is what the good outcome costs. Case type: Social engineering / attempted ransomware / data theft Identified: Apr 22, 2025 Disclosed: Apr 30, 2025 Attribution: Scattered Spider affiliates / DragonForce RaaS Every breach in this serie


Marks & Spencer Cyber Incident 2025: Help Desk Social Engineering and Identity Risk
The first and hardest-hit target of the UK retail wave. A few minutes of impersonation at an outsourced service desk, weeks of quiet access, every domain password reportedly harvested, and then the encryptor. M&S never said whether it paid. Its accounts said statutory profit fell from $509 million to $4.4 million. Case type: Social engineering / ransomware Identified: Apr 19–21, 2025 Disclosed: Apr 22, 2025 Attribution: Scattered Spider (reported) / DragonForce ransomware


Harrods Cyber Incident 2025: When Identity Defenses Actually Work
The third target of the UK retail wave cut its own internet access, kept trading, and said almost nothing. The wave broke against it. Months later, 430,000 customer records left anyway, through a supplier Harrods has never named. Both halves are the story Case type: Attempted intrusion / third-party data breach Identified: Late Apr 2025; Sept 2025 Disclosed: May 1, 2025; Sept 26, 2025 Attribution: Wave linked to Scattered Spider / DragonForce; Sept actor unnamed By the
HUMAN RISK
SECURITY CULTURE
AI GOVERNANCE



Co-op Cyber Incident 2025: Third-Party Access and the Decision to Disconnect
The third UK retailer hit in a two-week wave detected its intruders in hours, cut its own network before the ransomware could fire, and never paid a penny. It still lost the data of all 6.5 million members and £206 million in sales. This is what the good outcome costs. Case type: Social engineering / attempted ransomware / data theft Identified: Apr 22, 2025 Disclosed: Apr 30, 2025 Attribution: Scattered Spider affiliates / DragonForce RaaS Every breach in this serie

Rebecca Guy
Jul 29, 20255 min read


Harrods Cyber Incident 2025: When Identity Defenses Actually Work
The third target of the UK retail wave cut its own internet access, kept trading, and said almost nothing. The wave broke against it. Months later, 430,000 customer records left anyway, through a supplier Harrods has never named. Both halves are the story Case type: Attempted intrusion / third-party data breach Identified: Late Apr 2025; Sept 2025 Disclosed: May 1, 2025; Sept 26, 2025 Attribution: Wave linked to Scattered Spider / DragonForce; Sept actor unnamed By the

Rebecca Guy
Jun 3, 20255 min read


CDK Global Cyberattack 2024: Vendor Concentration and Industry-Wide Disruption
One software company went down and roughly 15,000 car dealerships went back to pen and paper in the middle of quarter-end. A restoration that got knocked down mid-recovery, a reported $25 million ransom, and over a billion dollars in dealer losses that the ransom did nothing to prevent. Case type: Ransomware / SaaS supply chain outage Identified: Jun 18, 2024 Disclosed: Jun 19, 2024 Attribution: BlackSuit (Royal / Conti lineage) On the morning of June 19, 2024, thousan

Rebecca Guy
Jul 23, 20245 min read


MGM Resorts Breach 2023: Business Continuity and Operational Resilience
Part one told how a ten-minute phone call breached MGM. This is what the next ten days cost: dark slot floors, handwritten check-ins, a refusal to pay, and a $100 million lesson in what operational resilience actually means. Case type: Ransomware / operational disruption Identified: Sept 10, 2023 Disclosed: Sept 11, 2023 Attribution: Scattered Spider / ALPHV Part one of this case examined how a ten-minute phone call gave attackers the keys to MGM Resorts. This companion pi

Rebecca Guy
Oct 17, 20235 min read


Optus Breach 2022: API Exposure and the Cost of Weak Governance
No phishing, no malware, no stolen credentials. A four-year-old coding error, a forgotten domain, and an API that never asked who was calling exposed the records of roughly 9.5 million Australians. Some breaches aren't broken into. They're walked into. Case type: Data exposure / unauthenticated API Identified: Sept 20, 2022 Disclosed: Sept 22, 2022 Attribution: Unidentified actor, handle "optusdata" Cybersecurity breaches are often measured in records exposed, systems compro

Rebecca Guy
Oct 4, 20226 min read

Next Steps
Turn What You've Learned Into Visibility.
The Free Human Risk Check provides a five-minute snapshot of potential human-driven cybersecurity risk across your organization.
bottom of page