The UK National Audit Office issued a report warning that attacks on online systems in the food supply chain by cybercriminals could lead to severe disruptions. Last year, Co-op and Marks & Spencer suffered destructive attacks; Marks & Spencer estimated that the total loss in April was approximately 136 million pounds, while Co-op confirmed that an attack resulted in the theft of data from 6.5 million members. The Audit Office noted that the optimized supply chain structure for efficiency makes it more vulnerable to interference, and companies face risks of increased costs and operational disruptions. It is expected that without government intervention, they will struggle to withstand the increasingly serious threats over the next five to ten years. Although Defra has been conducting specialized drills since 2023, its own digitalization level is low, and some services still rely on paper forms with insufficient application support.
The UK National Audit Office warned that attacks on online systems in the food supply chain by cybercriminals could lead to serious disruptions. The agency noted that the destructive attacks on Co-op and Marks & Spencer last year indicated an increasing risk, and recommended that the Department of Environment, Food and Rural Affairs (Defra) strengthen cooperation with industry to prevent such impacts. The report stated that although the supply chain has shown some resilience, companies face increased costs and disruptions in daily operations due to cyberattacks. Marks & Spencer estimated that the total loss from the attack in April last year was approximately 136 million pounds. Co-op confirmed that a single attack last year resulted in the theft of data from its 6.5 million members. The audit office emphasized that the supply chain structure developed for efficiency made it more vulnerable to interference, and companies are expected to struggle to withstand the growing risks without government intervention over the next five to ten years. Since 2023, Defra has conducted specialized drills for responding to cyber incidents in the food sector, but its own digitalization level is low, with some services still relying on paper forms and insufficient application support.