Marks & Spencer Cyber Attack Details: Timeline, Root Causes, and Business Impact

Marks & Spencer Cyber Attack Details: Timeline, Root Causes, and Business Impact

Palak Agrawal

Case Studies

Published on June 17, 2026

12 min read

Share on:

It started with a phone call.  

Not a zero-day exploit. Not a sophisticated piece of malware. Just a call to an IT helpdesk, a convincing impersonation, and a contractor who had no way to verify who was on the other end of the line.  

That call, made in February 2025, gave a group of mostly twenty-something cybercriminals access to one of Britain's most recognisable retailers. What followed was eight weeks of undetected access. Attackers moved through the network quietly, mapped servers, stole credentials, and positioned ransomware at the heart of Marks & Spencer's UK infrastructure. On Easter weekend, they deployed ransomware across Marks and Spencer's UK systems.  

Payments failed across every store. Online orders stopped. Warehouse systems went offline. The Marks and Spencer cyber attack in 2025 cost the company £300 million in lost operating profit and kept its online store shut for 46 days.  

This case study covers how it happened, why the damage ran so deep, and what the Marks & Spencer attack details reveal about the security gaps that made it possible.  

Marks & Spencer and the Attack Overview  

Marks & Spencer is an FTSE 100 company with annual revenues exceeding £13 billion. Its online business, which was the primary target of the disruption, accounts for approximately one-third of total clothing and home sales. The company generates roughly £3.8 million per day from online orders alone.  

In April 2025, M&S became the victim of the most operationally destructive cyberattack in UK retail history. The attackers encrypted the company's virtualisation infrastructure over Easter weekend, taking down systems that controlled online ordering, payment processing, warehouse automation, and stock management.  

Category
Details
Company
Marks & Spencer Group plc
Attack Type
Ransomware with data exfiltration (double extortion)
Threat Actor
Scattered Spider, also known as UNC3944, Octo Tempest, Muddled Libra, and Scatter Swine
Ransomware Used
DragonForce
Initial Access
Social engineering of a third-party IT helpdesk (February 2025)
Ransomware Deployed
24 April 2025, Easter weekend
Systems Affected
VMware ESXi hypervisors, online ordering, payments, stock management, warehouse automation

The UK Cyber Monitoring Centre classified the combined attacks on Marks and Spencers UK and Co-op as a single Category 2 systemic cyber event, the first time UK retail had been placed at that classification level. The total financial impact across both companies is estimated at between £270 million and £440 million.  

Who Is Scattered Spider?  

Before we go into the Marks and Spencer attack details, let's first understand Scattered Spider.

Scattered Spider is known by several names across the cybersecurity industry, including UNC3944 (Mandiant), Octo Tempest (Microsoft), Muddled Libra (Palo Alto Networks), Scatter Swine (Okta), and Storm-0875 (Microsoft). Unlike many high-profile threat actors, Scattered Spider is not a nation-state operation. Instead, it is a financially motivated and loosely organised criminal collective.

Being native English speakers gives them a significant advantage when targeting Western organisations. They know how corporate helpdesks operate, what internal IT language sounds like, and how to construct a convincing impersonation on a phone call. That is what makes them dangerous in a way that many technically sophisticated groups are not.  

CISA first formally documented the group's tactics in a November 2023 advisory. The advisory was updated in July 2025 to reflect new techniques the group had added after that initial publication.  

How Scattered Spider Works?

The Marks and Spencer attack details of how Scattered Spider operates follow a consistent pattern. They do not break in through software vulnerabilities. They find a person who can be talked into opening the door.  

Their main techniques include calling IT helpdesks while impersonating employees, SIM-swapping to take over a target's phone number, MFA fatigue attacks that spam a user with authentication approval requests until one is accepted by mistake, and building phishing pages that closely replicate corporate login portals.  

After the ALPHV/BlackCat ransomware group disbanded in early 2024, Scattered Spider shifted through RansomHub and Qilin before settling on DragonForce as their ransomware platform of choice. DragonForce launched in late 2023 and offers affiliates 80% of any ransom paid, along with automated tooling for managing attacks. The M&S attack was the first major DragonForce deployment against an FTSE 100 company.  

Prior Attacks  

The Marks & Spencer UK breach did not come out of nowhere. Scattered Spider had already demonstrated their capability across a series of high-profile targets before they turned their attention to UK retail.  

Year
Target
Method
Outcome
2022
Multiple BPOs
SIM swapping, phishing
Credential compromise and initial access operations associated with Scattered Spider’s early activity
Jan 2023
Riot Games
Social engineering
Source code for League of Legends and other systems was stolen; Riot reported a ransom demand
Sep 2023
Caesars Entertainment
Social engineering / account compromise
Caesars disclosed a cyber incident and reporting widely described a ransom payment of about $15M after a larger demand.
Sep 2023
MGM Resorts International
IT helpdesk social engineering + ALPHV ransomware
Major operational disruption across resorts; public reporting and MGM disclosures place losses around $100M

Marks & Spencer Attack Timeline: February to June 2025  

One of the most significant aspects of this breach is the gap between initial compromise and visible impact. The Marks and Spencer attack timeline below shows that Scattered Spider had full domain access for approximately eight weeks before M&S staff or customers noticed anything wrong. Each Marks and Spencer cyber attack update in this sequence reveals how far the attackers had progressed before detection.  

February 2025  

The Marks and Spencer attack timeline begins here. Attackers called the IT service desk operated by a third-party contractor. They impersonated an M&S employee and asked for a credential reset with MFA disabled. The contractor had no process to verify the caller's identity before carrying out the request.  

February 2025 

With a valid domain account, the attackers reached the Windows domain controller and copied the NTDS.dit file. This is Active Directory's master database. It stores password hashes for every user on the M&S Windows domain, including administrators. The hashes were cracked offline. The attackers now had plaintext passwords for a broad set of accounts without needing to touch M&S's systems again.  

February to April 2025 

For weeks, the attackers moved through the M&S network using cracked credentials and the same remote administration tools that M&S's own IT staff used. They mapped the server estate, escalated to the domain administrator level, located the VMware ESXi hosts running M&S's critical systems, exfiltrated customer data, and placed DragonForce ransomware payloads ready for detonation.  

21–22 April 2025

During the Easter weekend, DragonForce ransomware was deployed across key systems, encrypting servers and disrupting operations. M&S launched its incident response process and publicly disclosed the cyber incident on 22 April.

23–25 April 2025

To contain the attack, M&S took several systems offline and suspended online orders. Contactless payments, Click & Collect, and other customer services were affected. External cybersecurity experts were brought in to support recovery efforts.

29 April 2025  

Investigators linked the attack to social engineering tactics targeting help desk processes. The incident prompted wider industry warnings about strengthening identity verification and support desk security procedures.

13 May 2025  

This Marks and Spencer cyber attack update confirmed that customer personal data had been stolen, including names, email addresses, postal addresses, dates of birth, and purchase histories. M&S stated that payment card data and passwords were not among the stolen files.  

M&S revealed that the attack had caused significant financial losses and that full-service restoration would take several weeks. As recovery progressed, the company worked with regulators and law enforcement while strengthening its cybersecurity controls.  

The incident also prompted retailers across the UK to review their defenses against third-party and social engineering risks.

What are the Root Causes behind the Marks and Spencer Website Attack?  

The Marks and Spencer cyber attack 2025 was not caused by one failure. Several separate weaknesses compounded each other. Each one on its own might have been manageable. Together, they created a straight line from a single phone call to full infrastructure compromise.  

1. Social Engineering via Third-Party Help Desk  

Attackers impersonated M&S employees in sophisticated vishing calls to a third-party IT service desk. They convinced staff to reset passwords for legitimate accounts. M&S Chairman Archie Norman described it as a “sophisticated impersonation” involving internal knowledge. This bypassed technical perimeter controls entirely.  

2. Weak Active Directory Controls and Credential Exposure  

Once inside (or as part of early access), attackers extracted the NTDS.dit file from the domain controllers as early as February 2025. They cracked password hashes offline to obtain plaintext credentials, enabling privilege escalation and lateral movement. Insufficient network segmentation allowed broad domain access using legitimate tools.  

3. MFA and Identity Verification Gaps  

The group is known for MFA fatigue attacks and helpdesk manipulation to reset or bypass MFA. In this case, the password reset process itself appears to have granted effective access, highlighting weak verification protocols for high-privilege actions and third-party access.  

4. Prolonged Dwell Time and Detection Failures  

Attackers maintained undetected access for approximately two months (February to April 24, 2025). The absence of effective monitoring for anomalous AD activity, file access (e.g., NTDS.dit), or lateral movement allowed quiet data exfiltration and preparation before ransomware deployment.  

5. Third-Party and Supply Chain Risk  

Reliance on an external IT service provider for sensitive operations (password resets) without robust oversight, callback verification, or least-privilege controls created the initial entry vector. This reflects broader vendor risk management shortcomings.  

Business Impact After Marks and Spencer Breach  

The financial damage from the M&S breach is unusually well documented. M&S disclosed the figures in its own financial statements and investor communications, so these are not estimates from outside analysts. They are numbers the company itself put on the record.  

1. Financial Losses  

Category
Verified Figure
Lost operating profit
Approximately £300 million for FY 2025/26. Confirmed in M&S Annual Financial Statements, May 2025.
Market capitalisation loss
Over £1 billion wiped from M&S's market value. Share price fell more than 11% in the immediate aftermath of the attack becoming public.
Daily revenue lost from online
Approximately £3.8 million per day during the 46-day online store suspension.
Combined M&S and Co-op impact
£270 million to £440 million. Classified by the UK Cyber Monitoring Centre as a Category 2 systemic event.
Customer recommendation rate
Fell from approximately 87% before the breach to approximately 73% after it.

2. Operational Disruption  

The M&S cyber attack's impact on sales went well beyond lost online revenue. These are the specific systems and services that went down:  

  • Online clothing and homeware orders suspended from 25 April to 10 June 2025, a total of 46 days.
  • Click-and-collect services unavailable until August 2025, four months after the ransomware detonated.
  • Automated stock ordering and management systems were taken offline; staff tracked fresh food and clothing inventory on paper.  
  • Warehouse automation disrupted, leaving some shelves bare.  
  • 65,000 employees affected across the business  

The recovery took longer than most ransomware incidents because the damage sat at the virtualisation layer. Rebuilding encrypted hypervisor infrastructure takes time, and the forensic investigation required before any restored system could be trusted added further delay.  

3. Regulatory Exposure  

The confirmed theft of customer personal data triggered mandatory notification to the UK Information Commissioner's Office and put M&S in scope for potential fines under UK GDPR. The involvement of payment systems raised PCI DSS compliance questions, though M&S stated that payment card data was not among the stolen files.  

What DrupalFit's Security Audits Look For  

The Marks & Spencer breach began with a social engineering attack. No vulnerability scanner would have detected the phone call that gave the attackers their initial foothold.  

What scanners can uncover are the technical weaknesses that often allow attackers to move further into an environment. Exposed services, outdated software, weak encryption, misconfigured network access, and vulnerable web applications are all common findings in post-breach investigations.  

DrupalFit helps organisations identify those risks before they become a problem.  

The platform runs six security audits across your Drupal application, network infrastructure, and encryption configuration:  

Security Scan
What It Checks
OWASP ZAP Passive Scan
Insecure cookies, missing security headers, vulnerable JavaScript libraries, and configuration weaknesses.
OWASP ZAP Active Scan
SQL injection, cross-site scripting (XSS), remote code execution, and other exploitable vulnerabilities.
Nmap TCP Port Scan
Open ports and publicly accessible services that increase attack surface.
Nmap UDP Port Scan
Exposed UDP services such as DNS, SNMP, and NetBIOS.
OpenVAS Vulnerability Scan
Unpatched software, outdated components, and known CVEs.
SSLyze TLS/SSL Scan
Weak cipher suites, certificate issues, and protocol vulnerabilities.

Every finding is categorised by severity and includes technical details along with remediation guidance, making it easier for teams to prioritise and fix security issues.  

Many of the vulnerabilities uncovered during security audits are neither complex nor sophisticated. They are often misconfigurations, outdated software, or exposed services that have simply gone unnoticed.  

The challenge is that most organisations do not know these risks exist until an audit is performed or an incident occurs.  

See what risks exist in your Drupal environment. Create a free DrupalFit account and run your first security audit in minutes.

Run a Security Audit Now!

Related Articles

Tool and strategies modern teams need to help their companies grow

Read more