Strip away the specific technology and the Arup deepfake fraud and the M&S ransomware breach are the same attack, executed at different points in an organisation's process. Both succeeded through the same three-stage anatomy, and understanding that shared structure is more useful for defence than treating each incident as a unique technical curiosity.
Stage one is reconnaissance, and it is almost always public. Arup's attackers built their deepfakes from webinar recordings, press interviews, and conference footage — material the company itself had published. Scattered Spider's approach to M&S required knowing enough about internal structure and personnel to convincingly impersonate an employee to a help desk operator, information that is often available through LinkedIn, company org charts, and prior data leaks circulating in criminal forums. In both cases, the attackers did not need to breach anything to gather what they needed. They needed to pay attention to what the organisation had already made available.
Stage two is the trust exploit — the moment where a human being, not a piece of software, makes the decision that matters. The M&S help desk operator decided a caller's story was credible enough to reset a privileged account. The Arup employee decided a video call with familiar faces was credible enough to override his initial suspicion of the phishing email. Neither decision was unreasonable given what each person could perceive in the moment; both decisions were engineered, well in advance, to feel reasonable. This is the stage that all the technical controls in the world — firewalls, endpoint detection, email filtering — cannot fully close, because it does not route through the technology stack at all.
Stage three is exfiltration or extraction, and this is where the two cases diverge in mechanism but converge in speed. Once M&S's attackers had a working credential, they moved to exfiltrate the NTDS.dit file and deploy ransomware within a compressed timeframe. Once Arup's employee was convinced, fifteen wire transfers went out before anyone paused to double-check. In both cases, the gap between the trust exploit succeeding and the damage becoming irreversible was measured in hours, not days — which is the strongest argument for building deliberate friction into exactly this stage: mandatory delays, secondary approvals, and out-of-band verification specifically for the moment right after trust has been extended, when an attacker is moving fastest and a defender's attention is often lowest.