top of page

-- INSIGHTS
The Human Side of Cybersecurity
Cybersecurity incidents are rarely just technical. They are shaped by employee decisions, security culture, phishing and social engineering, AI use, and the way organizations respond to risk.
HumanSecIQ Insights examines those factors through practical guidance, analysis, and real-world cybersecurity incidents.
LATEST
Latest Insights
Insights, guidance, and practical perspectives on human risk, security culture, and AI governance.


Co-op Cyber Incident 2025: Third-Party Access and the Decision to Disconnect
The third UK retailer hit in a two-week wave detected its intruders in hours, cut its own network before the ransomware could fire, and never paid a penny. It still lost the data of all 6.5 million members and £206 million in sales. This is what the good outcome costs. Case type: Social engineering / attempted ransomware / data theft Identified: Apr 22, 2025 Disclosed: Apr 30, 2025 Attribution: Scattered Spider affiliates / DragonForce RaaS Every breach in this serie


Marks & Spencer Cyber Incident 2025: Help Desk Social Engineering and Identity Risk
The first and hardest-hit target of the UK retail wave. A few minutes of impersonation at an outsourced service desk, weeks of quiet access, every domain password reportedly harvested, and then the encryptor. M&S never said whether it paid. Its accounts said statutory profit fell from $509 million to $4.4 million. Case type: Social engineering / ransomware Identified: Apr 19–21, 2025 Disclosed: Apr 22, 2025 Attribution: Scattered Spider (reported) / DragonForce ransomware


Harrods Cyber Incident 2025: When Identity Defenses Actually Work
The third target of the UK retail wave cut its own internet access, kept trading, and said almost nothing. The wave broke against it. Months later, 430,000 customer records left anyway, through a supplier Harrods has never named. Both halves are the story Case type: Attempted intrusion / third-party data breach Identified: Late Apr 2025; Sept 2025 Disclosed: May 1, 2025; Sept 26, 2025 Attribution: Wave linked to Scattered Spider / DragonForce; Sept actor unnamed By the
HUMAN RISK
SECURITY CULTURE
AI GOVERNANCE



Co-op Cyber Incident 2025: Third-Party Access and the Decision to Disconnect
The third UK retailer hit in a two-week wave detected its intruders in hours, cut its own network before the ransomware could fire, and never paid a penny. It still lost the data of all 6.5 million members and £206 million in sales. This is what the good outcome costs. Case type: Social engineering / attempted ransomware / data theft Identified: Apr 22, 2025 Disclosed: Apr 30, 2025 Attribution: Scattered Spider affiliates / DragonForce RaaS Every breach in this serie

Rebecca Guy
Jul 29, 20255 min read


Marks & Spencer Cyber Incident 2025: Help Desk Social Engineering and Identity Risk
The first and hardest-hit target of the UK retail wave. A few minutes of impersonation at an outsourced service desk, weeks of quiet access, every domain password reportedly harvested, and then the encryptor. M&S never said whether it paid. Its accounts said statutory profit fell from $509 million to $4.4 million. Case type: Social engineering / ransomware Identified: Apr 19–21, 2025 Disclosed: Apr 22, 2025 Attribution: Scattered Spider (reported) / DragonForce ransomware

Rebecca Guy
Jun 17, 20255 min read


MGM Resorts Breach 2023: Help Desk Social Engineering and Operational Risk
A social engineering attack against MGM Resorts turned an identity-verification failure into widespread operational disruption. The incident shows how help desk processes, trusted identities, and human decisions can become part of the security boundary.

Rebecca Guy
Oct 10, 20234 min read


Caesars Entertainment Breach 2023: Social Engineering, Vendor Risk, and Extortion
Three weeks before MGM went dark, the same attackers called a help desk that worked for Caesars, and walked away with the loyalty database. No outage, no headlines at first, a negotiated ransom, and zero guarantees the data was ever deleted. Case type: Social engineering / vendor compromise / extortion Identified: Sept 7, 2023 Disclosed: Sept 14, 2023 Attribution: Scattered Spider (UNC3944) On August 18, 2023, attackers associated with Scattered Spider targeted the help desk

Rebecca Guy
Sep 23, 20234 min read


Uber Breach 2022: MFA Fatigue and the Human Cost of One Approved Request
A contractor's stolen credentials, repeated MFA prompts, and one approved request gave an attacker access to Uber's internal systems. This breach shows how identity controls can fail when attackers exploit both technology and predictable human behavior.

Rebecca Guy
Nov 7, 20224 min read


Cisco Breach 2022: MFA Fatigue and the Limits of a Trusted Login
Stolen credentials, repeated MFA prompts, and voice phishing gave an attacker access to Cisco's corporate VPN. The incident shows how trusted identities can become attack paths when authentication depends on both technical controls and human decisions.

Rebecca Guy
Sep 1, 20224 min read


Twilio Breach 2022: SMS Phishing and the Limits of MFA
SMS messages impersonating Twilio's IT team directed employees to fraudulent login pages, allowing attackers to capture credentials and access internal systems. The breach shows how phishing-resistant authentication and identity controls matter when attackers target the login process itself.

Rebecca Guy
Aug 15, 20224 min read

Next Steps
Turn What You've Learned Into Visibility.
The Free Human Risk Check provides a five-minute snapshot of potential human-driven cybersecurity risk across your organization.
bottom of page