David Read, Founder and Chairman of Prestige Purchasing argues that new AI-powered cybercrime redefines risk, response needs, and resilience especially for SMEs in the sector
One Saturday morning a few weeks ago I went to my local Co-op supermarket to buy some groceries. To my surprise the store was almost devoid of shoppers, save a few drifting around the isolated shelves that had a few items of stock on them. Notes explaining the empty shelves had been hastily scribbled by staff and sellotaped up to apologise for the almost total lack of stock. Grumpily, I climbed back into my car and drove the 30-minutes to my next nearest supermarket (M&S), but it too was depleted of many areas of stock and customers were queuing for the cash machine as payment systems were down. While M&S has resumed online orders, the in-store disruption is expected to last well into July as they ramp operations back up to fully stocked levels. The company has stated that the breach exposed the personal data of 9.4 million customers and estimates a reduction in profits of around £300 million, which is more than analysts had initially expected and represents a significant hit to the company’s overall profitability.
In M&S the attackers exploited a third-party IT system, a chilling reminder of supply chain vulnerability. At the Co-op hackers exploited social engineering tactics to infiltrate and reset employee passwords. Harrods, another iconic name, reportedly faced coordinated phishing and data exfiltration attempts from the same or a similar hacking group, prompting system shutdowns and emergency reviews.
The fact that these most recent events were restricted to large food retailers does not mean that a series of similar events within hospitality are any less likely. The advent of AI-driven cyber-attack capability has significantly increased an already present risk, and hospitality businesses both large and small, are squarely in the crosshairs. The lessons from the recent high-profile attacks are immediate, and the implications stretch from head office to every site, every shift, and every service.
According to the UK Government’s Cyber Security Breaches Survey 2024, 32% of small businesses and 53% of medium-sized businesses experienced cybersecurity breaches or attacks in the past year. These incidents are not mere nuisances. They often involve ransomware, data theft, or significant service disruption, with many resulting in financial and reputational harm. Alarmingly, while the frequency remains high, the report found that only 30% of small businesses had undertaken any form of cybersecurity risk assessment, exposing a major preparedness gap. Hospitality SMEs are especially vulnerable, with many businesses operating distributed networks (multiple locations and/or franchise structures), relying on third-party systems (POS vendors, suppliers), and often lacking in-house IT security teams. Cyber attackers know this and seek to exploit it.
Cyberattacks often begin with human error. A single click on a phishing email or the use of a weak password can allow attackers access to internal systems. From there, ransomware can be deployed encrypting critical files until a ransom is paid or sensitive customer and financial data can be stolen and sold on the dark web. Supply chains are a growing target. Attackers may infiltrate a trusted vendor, such as a software provider or payment processor, and use that access to breach multiple downstream businesses. Cybercriminals are increasingly using artificial intelligence (AI) to supercharge their attacks. AI can generate highly convincing phishing emails, create deepfakes to impersonate staff, or even identify weak points in a company’s digital infrastructure with shocking speed. Phishing attacks alone have surged since generative AI tools like ChatGPT became publicly available. In the past, a hacker might need hours to craft a convincing email. Now, they can launch thousands in seconds. The attackers are faster, smarter, and more scalable. This changes everything.
As a part of my research for this article I asked John Creaton, Co-Founder of Cyberrock to bring to life what the arrival of AI in the world of cyber-attacks will mean for hospitality:
“I see a sector that urgently needs to shift its mindset: from reactive to proactive, from IT-centric to board-level priority. Hospitality SMEs have spent much of the past decade investing in their tech-stack but often underestimate the scale and complexity of their resulting digital footprint, and that’s where the danger lies. Attacks don’t discriminate by size – they aim to exploit gaps. As we’ve seen with M&S and Co-op, even global brands with sophisticated systems are being breached. What chance do under-resourced SMEs have unless they act? Those who move quickly to strengthen their cyber resilience won’t just survive, they will win trust, reduce insurance costs, and become preferred partners in their supply chains. There’s also a strategic opportunity here. Businesses that visibly strengthen their cyber posture can win trust from corporate partners, suppliers, and insurers. Resilience becomes a differentiator.”
To stay ahead of this new environment operators need to focus on regular training of all staff to spot phishing and social engineering tactics, as well as using new AI-powered defence tools that can detect anomalies before they become threats. Also critical is auditing suppliers and partners to ensure they follow strong cybersecurity practices and having an incident response plan so you’re not scrambling in a crisis.
New tools are now emerging (of which one example is Cyberrock) that are specifically designed for both SMEs and larger businesses with distributed sites. These tools are a kind of AI-powered cybersecurity companion that acts like a virtual CIO continuously monitoring networks for vulnerabilities, offering clear alerts, and supporting remedial action. Many work alongside existing cybersecurity tools recommending additional tools where they find gaps. They can train staff via in-app nudges to avoid the types of errors that led to recent high profile breaches in the UK and support rapid escalation to IT teams for serious issues.
The hospitality sector is a prime target. Ransomware can halt service and cost tens of thousands in payments or downtime. Data breaches can trigger GDPR fines and damage customer trust. System outages can leave you unable to take bookings, accept payments, or even open your doors. For larger hospitality groups, the threat is amplified by complexity. Distributed sites mean more points of vulnerability. A breach at a single location can compromise the brand.
And all the time AI is changing the rules of engagement. Operators must act quickly to adapt.




