June 2, 2025
🕷️ Inside the Marks & Spencer Cyberattack: How Scattered Spider Crippled a British Retail Icon
In April 2025, Marks & Spencer (M&S), one of the UK’s most iconic retailers, became the latest high-profile victim of a sophisticated…

By Ankit Sharma
2 min read
In April 2025, Marks & Spencer (M&S), one of the UK's most iconic retailers, became the latest high-profile victim of a sophisticated cyberattack orchestrated by the notorious hacker group Scattered Spider. This breach not only disrupted M&S's operations but also highlighted the evolving tactics of modern cybercriminals and the vulnerabilities present in even the most established organizations.
🛒 Overview of the Incident and Its Impact
On April 24, 2025, M&S experienced a significant cyberattack that forced the company to suspend online orders, disable contactless payments, and shut down Click & Collect services. The breach led to a projected £300 million ($403 million) loss in operating profit and wiped approximately £650 million off the company's market value. The disruption is expected to continue until at least July 2025.
Despite the challenges, M&S's food division showed resilience, with sales increasing by 10.8% year-on-year in the 12 weeks leading up to May 17, 2025.
🧠 How the Cyberattack Happened
The attackers employed advanced social engineering techniques to infiltrate M&S's systems. By impersonating employees and exploiting help desk vulnerabilities, they tricked IT staff into resetting passwords and authentication processes. This allowed them to gain unauthorized access to the company's network.
The breach is believed to have originated through a third-party supplier, Tata Consultancy Services (TCS), which has been a long-term IT partner of M&S. Investigations are ongoing to determine the extent of TCS's involvement or vulnerabilities.
🎭 Who Was Involved: Hackers and Victims
Hacker Group: Scattered Spider, a cybercriminal group known for its elaborate attacks, is believed to be behind the M&S breach. The group is comprised mainly of English-speaking members who use advanced social engineering tactics to gain access to corporate systems.
Victims: The primary victim was M&S, but the attack also affected customers, with personal data such as names, email addresses, postal addresses, and dates of birth being compromised. However, no payment details or account passwords were accessed.
🕷️ About Scattered Spider
Scattered Spider, also known by aliases such as Octo Tempest and UNC3944, is a hacking group primarily composed of young, English-speaking individuals based in the UK and the US. The group is known for its focus on social engineering. It has targeted companies like Tinder, Louis Vuitton, and News Corp. Their strategy often involves impersonating employees to exploit help desk vulnerabilities. Despite arrests made in Spain, the UK, and the US, the group remains resilient and continues to pose a significant threat. Sky News The Express Tribune
📅 Timeline of the Attack
- February 2025: Attackers gain initial access to M&S's network, exfiltrating the Active Directory database.
- April 24, 2025: DragonForce ransomware is deployed, encrypting critical systems and disrupting operations.
- May 13, 2025: M&S confirms that personal customer information was breached in the attack.
- May 21, 2025: M&S announces that the cyberattack will cost the company £300 million and that disruptions are expected to last until July. Specops Software
🔐 Recommendations for Cybersecurity Teams
- Enhance Employee Training: Regularly educate staff about social engineering tactics and phishing scams to reduce the risk of human error.
- Implement Multi-Factor Authentication (MFA): Strengthen access controls by requiring multiple forms of verification.
- Conduct Regular Security Audits: Assess and update security protocols to identify and address vulnerabilities.
- Monitor Third-Party Vendors: Ensure that suppliers and partners adhere to strict cybersecurity standards.
- Develop an Incident Response Plan: Prepare for potential breaches with a clear, actionable plan to mitigate damage and recover operations swiftly.
Sources
The M&S cyberattack underscores the importance of robust cybersecurity measures and the need for constant vigilance against evolving threats. Organizations must prioritize cybersecurity to protect their operations and customer data in an increasingly digital world.