To avoid critical Access Management (AM) failures, UK organisations must move beyond simple password protection. The most common pitfalls include relying on static MFA, neglecting third-party service desk security, and failing to de-provision "Ghost Accounts". These oversights can lead to catastrophic breaches, as seen in recent UK high-street incidents where social engineering against third-party suppliers bypassed internal security. In 2026, the solution lies in centralised Single Sign-On (SSO), Risk-Based Authentication, and Automated Cloud Identity Management (ACIM) to ensure every access point is audited, verified, and revoked the moment it is no longer required.
The High Price of "Small" Oversights
In the 2026 landscape, the margin for error in digital identity is non-existent. Cyber criminals no longer "break in" by brute-forcing firewalls; they "log in" using legitimate credentials obtained through the exploitation of common management pitfalls. For UK businesses, these errors do not just result in data theft; they lead to total operational paralysis and severe regulatory penalties under the Cyber Essentials v3.3 (Danzell) framework.
Pitfall 1: The "Ghost Account" Graveyard
One of the most persistent vulnerabilities in UK organisations is the failure to de-provision accounts when a user departs. These "Ghost Accounts" remain active in the background, often retaining high-level permissions. If a former employee’s credentials are compromised, an attacker can use this stale account to move laterally through your network without triggering standard "new user" alerts.
Pitfall 2: Over-Privileged Users
For the sake of convenience, many IT departments grant "Administrator" or "Super User" status to more staff members than necessary. This creates a massive attack surface. If a single over-privileged account is compromised, the attacker immediately possesses the "keys to the kingdom," allowing them to disable security logs, encrypt databases, and halt production lines.
Pitfall 3: Inconsistent MFA Application
As the April 2026 Danzell mandate approaches, any cloud service that supports Multi-Factor Authentication (MFA) must have it enabled for all users. Many organisations still treat MFA as an "optional" feature for non-sensitive roles. In 2026, this inconsistency is an automatic failure for Cyber Essentials certification and a primary entry point for ransomware.
Case Studies: When Access Management Fails (2025-2026)
To understand the stakes of 2026, one must examine the catastrophic failures of 2025. These incidents prove that even the most iconic UK brands are vulnerable if their access management is siloed or outdated.

Marks & Spencer (April 2025): The Third-Party Compromise
In April 2025, Marks & Spencer learned a brutal lesson in modern business: your security is only as strong as your weakest partner. While M&S had spent millions securing its own perimeter, a group of cybercriminals found a "side door" by targeting a third-party IT contractor that managed the retailer’s helpdesk. Instead of using complex coding to break in, the hackers used simple social engineering—essentially fast-talking helpdesk staff over the phone—to trick them into resetting administrative passwords. Once they had these credentials, they bypassed multi-factor authentication and gained total "God-mode" access to the core M&S network.
The timing was calculated for maximum pain, hitting right as the Easter bank holiday weekend began. The hackers deployed ransomware that effectively paralyzed the company’s digital nervous system. To prevent the infection from spreading, M&S had to pull the plug on its entire online operation. For months, the website and app were essentially digital ghost towns, unable to process orders. In physical stores, the chaos was just as real; automated inventory systems failed, forcing staff to manage stock and track fresh food deliveries using manual logs and clipboards, just like they did decades ago.
By the time the dust settled in the summer of 2025, the financial wreckage was staggering. The attack cost M&S an estimated £300 million in lost profits—a massive hit driven by months of dead online sales and the gargantuan cost of rebuilding their IT infrastructure from scratch. Beyond the money, the personal data of millions of customers was compromised, leading to a long-term crisis of trust. The incident serves as a stark warning to the corporate world: in a connected economy, a single lapse at a remote helpdesk can bring a multi-billion pound empire to its knees.
Did the criminals get caught?
Yes, a significant number of them were. On July 10, 2025, the UK’s National Crime Agency (NCA) arrested four individuals in the West Midlands and London. The group was surprisingly young—including a 17-year-old and two 19-year-olds—and were linked to the Scattered Spider hacking collective.
These "digital pirates" were caught because their aggressive tactics, like making voice-phishing calls to helpdesks, left behind "vocal fingerprints" that investigators were able to track. While the larger "DragonForce" group they worked with is a global network that is harder to dismantle, these specific arrests were a major blow to the gang that targeted M&S.
What happened to M&S?
- The Rebound: It took nearly 46 days for M&S to even begin taking online orders again, and services didn't fully return to normal until July 2025.
- The Cost: The final "bill" for the attack was roughly £300 million in lost profit.
- The Security Fix: M&S was forced to completely rebuild its IT systems. They moved to a "Zero Trust" model, which basically means the computer system now assumes everyone is a stranger until they prove their identity multiple times—even if they claim to be calling from the helpdesk.
The Co-operative Group (May 2025): The Persistence of Ghost Accounts
In May 2025, the Co-operative Group—one of the UK’s most trusted community retailers—discovered that a massive digital disaster can happen even when you think you’ve caught the "bad guys." The trouble began when a group of cybercriminals managed to break into the Co-op’s main computer network. At first, it looked like a success story: the Co-op’s security teams spotted the intruders almost immediately and kicked them out. However, the hackers had a secret weapon that the company’s tech team had overlooked: "Ghost Accounts."
These ghosts were the digital profiles of former employees and retired staff members that had never been properly deleted. Because these accounts were still active but no longer monitored, the hackers were able to sneak back in and hide inside them. It was like a burglar being kicked out of the front door, only to realize they still had a key to the basement that the homeowner had forgotten existed. Because the Co-op’s "identity directory" was cluttered with these old, unmanaged accounts, the hackers were able to stay inside the system for weeks, quietly stealing the personal data of roughly 8 million members, including names, addresses, and shopping habits.
The impact on the real world was immediate and messy. As the company scrambled to truly lock the hackers out, they had to shut down the systems that tell delivery trucks which food to take to which stores. For the average shopper, this meant walking into their local Co-op only to find empty shelves where the bread, milk, and fresh vegetables should be. The "Persistence of Ghost Accounts" didn't just cause a data leak; it broke the supply chain.
In the end, the Co-op "Ghost Account" breach became one of the most high-profile cases of 2025, not because of how the hackers got in, but because of how long they were able to stay. Here is what happened to the criminals and where the company stands now.
Did the criminals get caught?
Yes, but they were not the "masterminds" you might expect. On July 10, 2025, the National Crime Agency (NCA) arrested four people—a 20-year-old woman and three teenagers (aged 17 and 19). They were detained in London and the West Midlands.
While these individuals were the ones "pulling the trigger" on the Co-op, M&S, and Harrods attacks, they were part of the Scattered Spider collective. This group is famous for recruiting young, tech-savvy people who are experts at "social engineering"—the art of tricking people over the phone to get passwords. While these four were caught and their devices seized, the larger international network they worked with still exists, which is why the police investigation is still ongoing.
What happens now?
- The Final Bill: The Co-op revealed that the attack cost them £206 million in lost revenue. Because they had to shut down their ordering systems to find the "ghosts," they couldn't get food to stores, which led to a £32 million operating loss for that half of the year.
- Turning "Black Hats" into "White Hats": In a unique move, the Co-op’s CEO, Shirine Khoury-Haq, announced a partnership with a group called The Hacking Games. Instead of just building higher walls, the Co-op is now helping to fund programs in schools to find kids who are good at hacking and teach them how to use those skills for good (as "White Hat" hackers) instead of becoming criminals.
- Cleaning the House: The Co-op has since moved to a "Zero Trust" security system. They have deleted millions of old, stale accounts so there are no more "ghosts" left for hackers to hide in.
Jaguar Land Rover (August 2025): The Production Paralysis
In August 2025, Jaguar Land Rover (JLR) fell victim to what many experts call the "perfect storm" of cyberattacks, proving that even the most advanced machinery is useless if the digital brains behind it are compromised. The crisis didn't start with a high-tech movie hack; it began with a series of deceptive phone calls. A group of hackers, later identified as a hybrid gang known as the Scattered Lapsus$ Hunters, used social engineering to trick employees into handing over their login details. By posing as friendly IT support staff, they walked right through the front door of JLR's network. Once inside, they exploited a specific weakness in the company’s network drivers to gain "God-mode" control over the entire system.
The timing could not have been worse. The attack struck on September 1st, known in the UK as "New Plate Day," the busiest day of the year for car sales. JLR operates on a "Just-in-Time" model, a high-speed logistics system where every part—from a leather seat to a tiny engine bolt—arrives at the factory exactly when the robots are ready to install it. This system relies on a constant, flawless stream of digital data. To stop the hackers from gaining control of the actual assembly-line robots or stealing sensitive designs, JLR leadership made the agonizing decision to "pull the plug" on their entire global IT network. In an instant, the massive factories in Solihull and Halewood went silent.
The result was a total production paralysis that lasted for weeks. With the computers down, the factories couldn't tell which parts were coming in or which cars were being built, forcing thousands of workers to down tools. This shutdown didn't just affect JLR; it sent a shockwave through the entire British economy. Over 5,000 smaller companies that supply parts to JLR were suddenly left with no one to sell to, leading to a massive financial crisis across the supply chain. By the time the systems were safely rebooted in October, the company had lost roughly £50 million every single week.
In the aftermath, the story became a landmark case for international police. The National Crime Agency and the FBI teamed up, using the recorded voices from those initial trick phone calls to track down several members of the hacking group in the UK and abroad. While JLR eventually got its robots moving again thanks to a massive government-backed loan, the event changed the industry forever. It served as a loud wake-up call that in the modern world, a car company is actually a software company that happens to make vehicles—and a single hijacked password can stall an entire empire.
In the end, the Jaguar Land Rover (JLR) crisis was a massive wake-up call for the global automotive industry. Because the company’s "Just-in-Time" system was so tightly connected, the shutdown wasn't just a quiet glitch—it was a multi-billion pound emergency that required the UK government to step in.
Did the criminals get caught?
The answer is a mix of "yes" and "partially." Because the hackers—operating under the name Scattered Lapsus$ Hunters—were so loud and boastful on Telegram, they left a trail for international police.
In late 2025, the National Crime Agency (NCA), working with the FBI, arrested several key members of the group in the UK and the United States. Many of those arrested were surprisingly young, linked to the same "Scattered Spider" group that hit Marks & Spencer earlier that year. Police used the recordings of their "vishing" (voice phishing) phone calls to match their voices and locations. However, because these groups are often loose "alliances" of hackers spread across the globe, some of the masterminds hiding in countries without extradition laws remain at large.
What happens now?
- The Massive Bill: The final cost of the "Production Paralysis" was estimated at £1.9 billion. To prevent the entire car-part supply chain in the UK from collapsing, the British government had to provide a £1.5 billion loan guarantee to stabilize the industry.
- The "Zero Trust" Era: JLR had to spend the end of 2025 completely rebuilding its digital architecture. They moved to a Zero Trust model, which assumes the network is always under threat. Now, no one—not even a senior manager—can access critical factory robots without multiple layers of identity verification.
- Economic Impact: The Bank of England noted that this single hack was so large it actually slowed down the UK's overall economic growth (GDP) for the second half of 2025.
Expanding the List: Further Access Management Pitfalls
Pitfall 1: The Service Desk Weak Link
In 2026, cyber criminals frequently bypass technical firewalls by targeting the human element. Attackers utilise AI-generated voice cloning to impersonate senior executives during calls to the IT service desk, claiming they have lost access to their accounts while travelling. Without a verified, automated process for identity confirmation, service desk staff often reset passwords manually, inadvertently handing control of a privileged account to an intruder.
Pitfall 2: Siloed Identity Management
Managing access separately for every application—such as your VLE, HR system, and finance portal—is a recipe for disaster. This fragmentation makes it impossible to gain a unified view of who has access to what. It also ensures that when a staff member leaves, they are inevitably missed in at least one system, leaving a "back door" wide open.
Pitfall 3: Neglecting the "Mover" Lifecycle
Most organisations focus on "joiners" and "leavers" but forget the "movers." When an employee changes departments, they often retain their old permissions while gaining new ones. This "access creep" results in long-term staff possessing an dangerous level of broad access that they no longer require for their current role.
Pitfall 4: Ignoring Device Health as a Factor
In the modern UK workspace, access should not be granted based on credentials alone. If a user provides a correct password and MFA token but is using an unmanaged, infected personal device, the risk is too high. Failing to check for device "compliance" before granting access is a primary cause of data leakage.
Pitfall 5: Relying on Manual Audit Logs
If your organisation only reviews access logs during an annual audit, you are essentially driving a car by looking in the rear-view mirror. In 2026, security must be proactive. Manual logs are often incomplete and too slow to help you stop an active breach like the one that impacted The Co-operative Group.
Pitfall 6: Lack of "Impossible Travel" Detection
With the rise of remote and international research collaboration in UK Higher Education, detecting anomalous logins is vital. If a user logs in from London and then attempts to access a sensitive database from an overseas IP address ten minutes later, the system must automatically block the attempt.
Pitfall 7: The "Check-Box" Compliance Trap
Many IT leaders view the Cyber Essentials v3.3 certification as a "one-and-done" task. However, security is a continuous process. Treating compliance as a simple tick-box exercise leads to a "set it and forget it" mentality, which attackers exploit the moment your configurations drift away from the secure baseline.
Information Gain: The "Service Desk Hijack" and the Zero-Trust Fallacy

The 2026 Reality of Social Engineering
A unique insight for UK IT directors is the evolution of the "Service Desk Hijack." Modern attackers are no longer just sending phishing emails; they are using deep-fake technology to manipulate the very people hired to help. To combat this, organisations must implement "Out-of-Band" verification. This means that even if a "Director" calls the service desk, the technician must send a verification push to a registered device or use a pre-shared "Secret Key" managed within a centralised system like Overt's SAAM Bridge.
Why Zero-Trust Fails Without a Unified Fabric
"Zero-Trust" is a popular buzzword in 2026, but it is often misunderstood. A Zero-Trust strategy will fail if you do not have a unified Identity Fabric. If your VLE follows Zero-Trust principles but your legacy on-premises applications do not, attackers will simply find the weakest link. True security requires a bridge that applies the same high standards of verification across every single application in your estate.
How Overt Software Solutions Eliminates These Pitfalls
Overt Software Solutions provides the tools and expertise required to transition from a vulnerable, manual setup to a resilient, automated infrastructure.
- Managed Single Sign-On (SSO): We eliminate "Siloed Directories" and "Ghost Accounts" by centralising your access control. When you disable a user in your primary directory, their access is revoked everywhere—instantly.
- The SAAM Bridge: Our unique bridge technology allows you to apply modern, Risk-Based Authentication to legacy systems, ensuring that even your oldest applications meet Cyber Essentials 2026 standards.
- Automated Lifecycle Management: By integrating your MIS/SIS directly with your access management, we ensure that "Joiners, Movers, and Leavers" are handled automatically, eliminating human error.
Take Action Before the Next Audit
Do not wait for a breach to discover the pitfalls in your infrastructure. The failures of Marks & Spencer and Jaguar Land Rover were preventable with the right identity governance.
Contact Overt Software Solutions today for a "Pitfall Prevention" Health Check. Our engineers will audit your current access management flows and help you build a secure, compliant, and frictionless environment for your staff and students.
