
Palak Agrawal
Published on June 17, 2026
12 min read
Share on:
It started with a phone call.
Not a zero-day exploit. Not a sophisticated piece of malware. Just a call to an IT helpdesk, a convincing impersonation, and a contractor who had no way to verify who was on the other end of the line.
That call, made in February 2025, gave a group of mostly twenty-something cybercriminals access to one of Britain's most recognisable retailers. What followed was eight weeks of undetected access. Attackers moved through the network quietly, mapped servers, stole credentials, and positioned ransomware at the heart of Marks & Spencer's UK infrastructure. On Easter weekend, they deployed ransomware across Marks and Spencer's UK systems.
Payments failed across every store. Online orders stopped. Warehouse systems went offline. The Marks and Spencer cyber attack in 2025 cost the company £300 million in lost operating profit and kept its online store shut for 46 days.
This case study covers how it happened, why the damage ran so deep, and what the Marks & Spencer attack details reveal about the security gaps that made it possible.
Marks & Spencer is an FTSE 100 company with annual revenues exceeding £13 billion. Its online business, which was the primary target of the disruption, accounts for approximately one-third of total clothing and home sales. The company generates roughly £3.8 million per day from online orders alone.
In April 2025, M&S became the victim of the most operationally destructive cyberattack in UK retail history. The attackers encrypted the company's virtualisation infrastructure over Easter weekend, taking down systems that controlled online ordering, payment processing, warehouse automation, and stock management.
Category | Details |
Company | Marks & Spencer Group plc |
Attack Type | Ransomware with data exfiltration (double extortion) |
Threat Actor | Scattered Spider, also known as UNC3944, Octo Tempest, Muddled Libra, and Scatter Swine |
Ransomware Used | DragonForce |
Initial Access | Social engineering of a third-party IT helpdesk (February 2025) |
Ransomware Deployed | 24 April 2025, Easter weekend |
Systems Affected | VMware ESXi hypervisors, online ordering, payments, stock management, warehouse automation |
The UK Cyber Monitoring Centre classified the combined attacks on Marks and Spencers UK and Co-op as a single Category 2 systemic cyber event, the first time UK retail had been placed at that classification level. The total financial impact across both companies is estimated at between £270 million and £440 million.
Before we go into the Marks and Spencer attack details, let's first understand Scattered Spider.
Scattered Spider is known by several names across the cybersecurity industry, including UNC3944 (Mandiant), Octo Tempest (Microsoft), Muddled Libra (Palo Alto Networks), Scatter Swine (Okta), and Storm-0875 (Microsoft). Unlike many high-profile threat actors, Scattered Spider is not a nation-state operation. Instead, it is a financially motivated and loosely organised criminal collective.
Being native English speakers gives them a significant advantage when targeting Western organisations. They know how corporate helpdesks operate, what internal IT language sounds like, and how to construct a convincing impersonation on a phone call. That is what makes them dangerous in a way that many technically sophisticated groups are not.
CISA first formally documented the group's tactics in a November 2023 advisory. The advisory was updated in July 2025 to reflect new techniques the group had added after that initial publication.
The Marks and Spencer attack details of how Scattered Spider operates follow a consistent pattern. They do not break in through software vulnerabilities. They find a person who can be talked into opening the door.
Their main techniques include calling IT helpdesks while impersonating employees, SIM-swapping to take over a target's phone number, MFA fatigue attacks that spam a user with authentication approval requests until one is accepted by mistake, and building phishing pages that closely replicate corporate login portals.
After the ALPHV/BlackCat ransomware group disbanded in early 2024, Scattered Spider shifted through RansomHub and Qilin before settling on DragonForce as their ransomware platform of choice. DragonForce launched in late 2023 and offers affiliates 80% of any ransom paid, along with automated tooling for managing attacks. The M&S attack was the first major DragonForce deployment against an FTSE 100 company.
The Marks & Spencer UK breach did not come out of nowhere. Scattered Spider had already demonstrated their capability across a series of high-profile targets before they turned their attention to UK retail.
Year | Target | Method | Outcome |
2022 | Multiple BPOs | SIM swapping, phishing | Credential compromise and initial access operations associated with Scattered Spider’s early activity |
Jan 2023 | Riot Games | Social engineering | Source code for League of Legends and other systems was stolen; Riot reported a ransom demand |
Sep 2023 | Caesars Entertainment | Social engineering / account compromise | Caesars disclosed a cyber incident and reporting widely described a ransom payment of about $15M after a larger demand. |
Sep 2023 | MGM Resorts International | IT helpdesk social engineering + ALPHV ransomware | Major operational disruption across resorts; public reporting and MGM disclosures place losses around $100M |
One of the most significant aspects of this breach is the gap between initial compromise and visible impact. The Marks and Spencer attack timeline below shows that Scattered Spider had full domain access for approximately eight weeks before M&S staff or customers noticed anything wrong. Each Marks and Spencer cyber attack update in this sequence reveals how far the attackers had progressed before detection.

The Marks and Spencer attack timeline begins here. Attackers called the IT service desk operated by a third-party contractor. They impersonated an M&S employee and asked for a credential reset with MFA disabled. The contractor had no process to verify the caller's identity before carrying out the request.
With a valid domain account, the attackers reached the Windows domain controller and copied the NTDS.dit file. This is Active Directory's master database. It stores password hashes for every user on the M&S Windows domain, including administrators. The hashes were cracked offline. The attackers now had plaintext passwords for a broad set of accounts without needing to touch M&S's systems again.
For weeks, the attackers moved through the M&S network using cracked credentials and the same remote administration tools that M&S's own IT staff used. They mapped the server estate, escalated to the domain administrator level, located the VMware ESXi hosts running M&S's critical systems, exfiltrated customer data, and placed DragonForce ransomware payloads ready for detonation.
During the Easter weekend, DragonForce ransomware was deployed across key systems, encrypting servers and disrupting operations. M&S launched its incident response process and publicly disclosed the cyber incident on 22 April.
To contain the attack, M&S took several systems offline and suspended online orders. Contactless payments, Click & Collect, and other customer services were affected. External cybersecurity experts were brought in to support recovery efforts.
Investigators linked the attack to social engineering tactics targeting help desk processes. The incident prompted wider industry warnings about strengthening identity verification and support desk security procedures.
This Marks and Spencer cyber attack update confirmed that customer personal data had been stolen, including names, email addresses, postal addresses, dates of birth, and purchase histories. M&S stated that payment card data and passwords were not among the stolen files.
M&S revealed that the attack had caused significant financial losses and that full-service restoration would take several weeks. As recovery progressed, the company worked with regulators and law enforcement while strengthening its cybersecurity controls.
The incident also prompted retailers across the UK to review their defenses against third-party and social engineering risks.
The Marks and Spencer cyber attack 2025 was not caused by one failure. Several separate weaknesses compounded each other. Each one on its own might have been manageable. Together, they created a straight line from a single phone call to full infrastructure compromise.
Attackers impersonated M&S employees in sophisticated vishing calls to a third-party IT service desk. They convinced staff to reset passwords for legitimate accounts. M&S Chairman Archie Norman described it as a “sophisticated impersonation” involving internal knowledge. This bypassed technical perimeter controls entirely.
Once inside (or as part of early access), attackers extracted the NTDS.dit file from the domain controllers as early as February 2025. They cracked password hashes offline to obtain plaintext credentials, enabling privilege escalation and lateral movement. Insufficient network segmentation allowed broad domain access using legitimate tools.
The group is known for MFA fatigue attacks and helpdesk manipulation to reset or bypass MFA. In this case, the password reset process itself appears to have granted effective access, highlighting weak verification protocols for high-privilege actions and third-party access.
Attackers maintained undetected access for approximately two months (February to April 24, 2025). The absence of effective monitoring for anomalous AD activity, file access (e.g., NTDS.dit), or lateral movement allowed quiet data exfiltration and preparation before ransomware deployment.
Reliance on an external IT service provider for sensitive operations (password resets) without robust oversight, callback verification, or least-privilege controls created the initial entry vector. This reflects broader vendor risk management shortcomings.
The financial damage from the M&S breach is unusually well documented. M&S disclosed the figures in its own financial statements and investor communications, so these are not estimates from outside analysts. They are numbers the company itself put on the record.
Category | Verified Figure |
Lost operating profit | Approximately £300 million for FY 2025/26. Confirmed in M&S Annual Financial Statements, May 2025. |
Market capitalisation loss | Over £1 billion wiped from M&S's market value. Share price fell more than 11% in the immediate aftermath of the attack becoming public. |
Daily revenue lost from online | Approximately £3.8 million per day during the 46-day online store suspension. |
Combined M&S and Co-op impact | £270 million to £440 million. Classified by the UK Cyber Monitoring Centre as a Category 2 systemic event. |
Customer recommendation rate | Fell from approximately 87% before the breach to approximately 73% after it. |
The M&S cyber attack's impact on sales went well beyond lost online revenue. These are the specific systems and services that went down:
The recovery took longer than most ransomware incidents because the damage sat at the virtualisation layer. Rebuilding encrypted hypervisor infrastructure takes time, and the forensic investigation required before any restored system could be trusted added further delay.
The confirmed theft of customer personal data triggered mandatory notification to the UK Information Commissioner's Office and put M&S in scope for potential fines under UK GDPR. The involvement of payment systems raised PCI DSS compliance questions, though M&S stated that payment card data was not among the stolen files.
The Marks & Spencer breach began with a social engineering attack. No vulnerability scanner would have detected the phone call that gave the attackers their initial foothold.
What scanners can uncover are the technical weaknesses that often allow attackers to move further into an environment. Exposed services, outdated software, weak encryption, misconfigured network access, and vulnerable web applications are all common findings in post-breach investigations.

DrupalFit helps organisations identify those risks before they become a problem.
The platform runs six security audits across your Drupal application, network infrastructure, and encryption configuration:
Security Scan | What It Checks |
OWASP ZAP Passive Scan | Insecure cookies, missing security headers, vulnerable JavaScript libraries, and configuration weaknesses. |
OWASP ZAP Active Scan | SQL injection, cross-site scripting (XSS), remote code execution, and other exploitable vulnerabilities. |
Nmap TCP Port Scan | Open ports and publicly accessible services that increase attack surface. |
Nmap UDP Port Scan | Exposed UDP services such as DNS, SNMP, and NetBIOS. |
OpenVAS Vulnerability Scan | Unpatched software, outdated components, and known CVEs. |
SSLyze TLS/SSL Scan | Weak cipher suites, certificate issues, and protocol vulnerabilities. |
Every finding is categorised by severity and includes technical details along with remediation guidance, making it easier for teams to prioritise and fix security issues.
Many of the vulnerabilities uncovered during security audits are neither complex nor sophisticated. They are often misconfigurations, outdated software, or exposed services that have simply gone unnoticed.
The challenge is that most organisations do not know these risks exist until an audit is performed or an incident occurs.
See what risks exist in your Drupal environment. Create a free DrupalFit account and run your first security audit in minutes.