Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Morrisons suffers from insider breach current page
Link copied

Morrisons suffers from insider breach

Apr 23, 2014
Author:
Kevin Franks
Marketing Communications Manager
Blog banner default
Morrisons suffers from insider breach
Kevin Franks
Marketing Communications Manager

On 13 March, Supermarket retailer Morrisons confirmed that it had suffered a large security breach, with personal details of around 100,000 staff stolen from its payroll system, according to reports.

With Morrisons ruling out external cyber attack, the likely cause is an insider theft, with the company stating it had been victim of an "illegal theft of data" which was removed from the website it was uploaded to within hours. The stolen data was reportedly sent to a local Bradford newspaper containing employee salary and bank details affecting nearly all of the supermarket chain's staff.

Morrisons is working with West Yorkshire Police and cyber crime authorities to determine the source, as well as Experian and the major banks to provide support to employees. Customer data is unaffected.

Paul Kenyon, co-founder and EVP of global sales at Avecto commented: "It appears Morrisons has been the subject of an insider attack. Organizations can invest a huge amount protecting their networks and data from outside attacks, but those defences mean little against a rogue employee with an agenda, or even an unintentional error.

"We should give Morrisons credit as it has done all the right things in the aftermath. It reported the theft to the authorities, urgently reviewed its internal security measures and ensured its response is being led right from the top of the company.

"It's difficult to defend against the insider threat but there are steps that can be taken. Limiting the number of administrative accounts and controlling access efficiently can go a long way to minimising the risk."

Latest Posts
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
Related
  • Here's a Little Cybersecurity Trick I Learned to Keep Your Identity Secure
    Apr 10, 2018 Here's a Little Cybersecurity Trick I Learned to Keep Your Identity Secure
    Blog
    1m
  • Desktop Misadventures
    Oct 20, 2017 Desktop Misadventures
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.