We began this investigation with a simple question: How did a complete stranger convince someone inside Marks & Spencer to hand them the keys to a billion-pound empire?
The answer turned out to be surprisingly simple.
They didn’t.
They didn’t persuade the help desk to trust them. They systematically removed every reason not to.
Each piece of publicly available information became another piece of currency that could be exchanged for one less question, one less hesitation, one less reason to stop the call. By the time the phone rang, the attackers had accumulated enough of it that there was almost nothing left to doubt.
This revelation points toward a broader conclusion. For years, organizations have treated social engineering primarily as a training problem: teach employees to recognize deception, ask better questions, and become more skeptical. Those remain important defenses. But they focus on the moment the attack begins.
The Marks & Spencer breach suggests the attack began much earlier.
It began while attackers were assembling the reconnaissance needed to impersonate an insider using information the organization had already left exposed.

That’s the idea behind Human Attack Surface Management (HASM). Rather than asking only, “How do we help employees recognize increasingly sophisticated social engineering?” HASM asks a different question: “How do we make those attacks dramatically harder to construct in the first place?”
Organizations can’t function without trust. In lieu of eliminating trust, the solution is to reduce the raw material attackers use to manufacture credibility before they ever make contact.
That means reducing the information attackers rely on to execute social engineering attacks: removing exposed personal information from data brokers, limiting unnecessary employee information across public sources, and identifying organizational details that reveal reporting structures, internal systems, and authentication processes.
None of those steps prevent social engineering outright. Nothing can. What they do is change the economics of the attack.
Every employee profile removed, every outdated data broker listing deleted, and every unnecessary piece of organizational metadata taken offline deprives attackers of the intelligence they need to build convincing social engineering pretexts. Instead of handing attackers the ingredients for trust, organizations force them to spend more time, gather more intelligence, accept greater uncertainty, and take greater risks before they ever place the call.
The goal isn’t to eliminate trust.
The goal is to make social engineering attacks significantly harder to execute by denying attackers the information they need to earn that trust.