In the wake of the recent cyberattacks on M&S and Co-op, it is becoming increasingly clear that these types of attacks are unlikely to stop any time soon. Cyberattacks are defined by the National Cyber Security Centre as an “attempt to damage, disrupt or gain unauthorised access to computer systems, networks, or devices”, and they are not limited to activity over the internet. One of the most overlooked threats arises from human factors, which are attacks that exploit the weakest link in the security chain: humans.
Social engineering is one of the most common threats of this kind. Criminals play on human emotions—such as fear, curiosity, greed, and the instinct to help others—to extract sensitive information out of them. They may pose as authority figures, genuine businesses, or family members to create a sense of authenticity.
Other common human vulnerabilities are weak passwords and inadequate security training within the workforce. Weak passwords can be easily cracked within minutes—or even seconds—using tools that are free and widely available on the internet. Additionally, when passwords are leaked in data breaches, they are often added to large wordlists available publicly on the internet, making it even more important to use secure passwords, as weak ones may have already been leaked.
A lack of security training poses a risk, as poor understanding can result in risky behaviours, including clicking on insecure links within e-mails, sharing passwords, or downloading questionable software off the internet. Technical factors are also a major contributor to cyberattacks. Often, software running on machines can be left outdated for years, leaving them exposed to known vulnerabilities that have been patched in later updates.
A recent example was the June 2024 attack on Synnovis, a pathology laboratory responsible for processing blood tests for several NHS organisations. Hackers were able to gain access to the computer system, leaking over 400GB of sensitive patient data, causing long-term, or even permanent, harm to multiple patients’ health. Doctors who spoke to investigators reported using computers that were over ten years old, running the Windows 7 operating system, which has not been updated since January 2020.
So, what is the point of these cyberattacks? A lot of the time, it is monetary gain. Criminals can hold sensitive information for ransom, demanding money in return for the data.
Alternatively, data can be sold on the black market for significant amounts of money. Another big motive is cyberwarfare, which is the use of cyberattacks against a state. These types of attacks are carried out to disrupt critical government and civilian infrastructure, often for espionage or political gain.
As much as artificial intelligence (AI) is helpful in our day-to-day lives, I believe it may have a profoundly negative impact on the future of cybersecurity, with increases in the frequency and severity of new cyberattacks. The introduction of AI-powered coding assistants has led to junior developers becoming complacent, often relying heavily on generated code without fully grasping the underlying logic, colloquially known online as “vibe coding”. As AI has the tendency to fabricate incorrect information—known as hallucinations— these tools can inadvertently introduce subtle security flaws that go unnoticed.
As the attacks on M&S and Co-op remind us, cyber threats are no longer distant possibilities—they are current realities, and addressing both human and technical vulberabilities is the only way to stay one step ahead.

