London Mail
  • Home
  • World
  • News
  • Opinion
  • Business
  • Tech
  • Science
  • Sports
  • Lifestyle
  • Health
  • Motering/Cars
  • More
    • Entertainment
    • Travel
    • Crypto
    • Food
    • Home Improvment
      • Real Estate
    • Press Release
No Result
View All Result
  • Home
  • World
  • News
  • Opinion
  • Business
  • Tech
  • Science
  • Sports
  • Lifestyle
  • Health
  • Motering/Cars
  • More
    • Entertainment
    • Travel
    • Crypto
    • Food
    • Home Improvment
      • Real Estate
    • Press Release
No Result
View All Result
London Mail
No Result
View All Result
Home Business

Everything we know about the M&S cyber attack that halted online orders

by London Mail
May 13, 2025
in Business
Reading Time: 7 mins read
0
SHARES
Share on FacebookShare on Twitter

Marks & Spencer bosses have confirmed that some customer’s personal data had been accessed in the recent attack on the company.

However the company said this did not include “useable payment or card details” or passwords.

But M&S said that for “extra peace of mind” customers will be prompted to change their passwords next time they log in to their online accounts.

The company, which employs about 64,000 people and operates more than 1,400 stores globally, is continuing to investigate the breach.

Here’s what we know so far about the M&S cyber attack.

What happened in the M&S cyber attack?

Marks & Spencer first revealed the cyber attack on Monday, April 21, after customers reported payment issues and delays receiving online orders.

In an email to shoppers, M&S chief executive Stuart Machin wrote: “Over the last few days, M&S has been managing a cyber incident. To protect you and the business, it was necessary to temporarily make some small changes to our store operations, and I am sincerely sorry if you experienced any inconvenience.

“Importantly, our stores remain open, and our website and app are operating as normal. There is no need for you to take any action at this time, and if the situation changes, we will let you know.”

M&S employs about 64,000 people and operates more than 1,400 stores globally

PA Wire

“This is a pretty bad episode of ransomware,” he said.

“It is a highly disruptive event and a very difficult one for them to deal with.”

“I would suggest there is a high level of confidence this is a ransomware-style event,” Dan Card, cyber expert at BCS, the chartered institute for IT, told the BBC.

“I describe these as like a digital bomb has gone off. So recovering from them is often both technically and logistically challenging… the victim organisation is likely going to be working around the clock to respond and recover.”

Ransomware is a type of malicious software that locks or encrypts a victim’s data and demands payment, usually in cryptocurrency, to restore access.

Who was behind the M&S cyber attack?

It said the group was suspected of breaching M&S systems as early as February 2025, allegedly stealing the Windows domain’s NTDS.dit file—a sensitive database containing user credentials. They are also believed to have used ransomware to encrypt parts of M&S’s infrastructure.

Also called UNC3944, Octo Tempest or Muddled Libra, Scattered Spider is reportedly known for employing advanced social engineering tactics, including phishing and multi-factor authentication (MFA) fatigue attacks, to infiltrate large organisations.

Phishing tricks users into revealing sensitive information, while MFA fatigue involves bombarding users with repeated login requests in hopes they’ll approve one out of frustration or confusion.

Hackers from the renowned Scattered Spider group were reportedly behind the M&S cyber attack

Alamy/PA

“Scattered Spider is one of the most dangerous and active hacking groups we are monitoring,” Graeme Stewart, the head of public sector at security company Check Point, told Sky News.

“Since they first appeared in 2022, they have been linked to more than 100 targeted attacks across industries such as telecoms, finance, retail and gaming.”

BleepingComputer reported that DragonForce ransomware was deployed to VMware ESXi hosts on April 24 to encrypt virtual machines. The group reportedly gained access to M&S systems and remained undetected for weeks.

Scattered Spider reportedly comprises young hackers, some as young as 16, who frequent hacker forums, Telegram channels, and Discord servers. Some members are also believed to be linked to the “Com”, a loosely affiliated community known for cyber and real-world criminal activity that has drawn media attention.

Following the breach, M&S enlisted CrowdStrike, Microsoft, and Fenix24 cybersecurity experts to help investigate and contain the incident. The company declined to provide BleepingComputer with additional details about the attack.

What impact has the cyber attack had on M&S?

Nayna McIntosh, a former M&S executive and founder of Hope Fashion, said the decision to halt online orders was comparable to “cutting off a limb.”

Susannah Streeter, head of money and markets at Hargreaves Lansdown, said the pause on online orders will be “hugely damaging for sales”.

“Fashion sales are likely to take a big hit particularly as the attack has come during the spell of warm weather when summer ranges would ordinarily be piling up in virtual baskets,” she added. “While other retailers have not been immune to IT breaches, the depth of Marks and Spencer’s problems in resolving the issue are worrying, and it may take some time to win back some warier shoppers.”

Shares fell 2.2 per cent to 377.3p on Monday morning, with more than £700 million wiped from the company’s market value since the cyber attack.

The shop was left with “pockets of limited availability” across some of its stores for the past week following a cyber attack that temporarily disrupted parts of its IT systems.

The British retailer has been grappling with the fallout from the cyber incident for over a week, which wiped millions off its market value.

It has also been reported that certain stores, such as Liverpool, are being forced to reduce food items on mass, amid fears the stores are not as busy as usual.

Source link

Related Posts

Bank of England will monitor cash acceptance on ongoing basis
Business

Bank of England will monitor cash acceptance on ongoing basis

July 12, 2025
Boost for first-time buyers as ‘mortgage lending reins loosened’
Business

Boost for first-time buyers as ‘mortgage lending reins loosened’

July 9, 2025
The Rachel papers: Chancellor Reeves’ first year is no cause for celebration
Business

The Rachel papers: Chancellor Reeves’ first year is no cause for celebration

July 3, 2025
Next Post
Three superfoods you WON’T have heard of – but only for the brave

Three superfoods you WON'T have heard of - but only for the brave

Warning over ‘dangerous’ egg storage mistake that could make you ill

Warning over 'dangerous' egg storage mistake that could make you ill

The gorgeous city that’s one of the cheapest places to fly this summer – and beers are only £2.50

The gorgeous city that's one of the cheapest places to fly this summer - and beers are only £2.50

Recommended

The public wants firm action on union chaos

The public wants firm action on union chaos

2 years ago
China property crisis deepens as Moody’s withdraws credit ratings

China property crisis deepens as Moody’s withdraws credit ratings

1 year ago
Disposable vapes ban to come into force in bid to improve health and cut litter

Disposable vapes ban to come into force in bid to improve health and cut litter

1 month ago
Inside the ‘UFO cult’ led by a ‘sex maniac’: Netflix’s new documentary reveals how journalist who claimed he was an ‘alien prophet’ used his power to ‘bed thousands of women’

Inside the ‘UFO cult’ led by a ‘sex maniac’: Netflix’s new documentary reveals how journalist who claimed he was an ‘alien prophet’ used his power to ‘bed thousands of women’

1 year ago

Categories

  • Business
  • Crypto
  • Entertainment
  • Food
  • Health
  • Home Improvment
  • Lifestyle
  • Motering/Cars
  • News
  • Opinion
  • Press Release
  • Real Estate
  • Science
  • Sports
  • Tech
  • Travel
  • World
No Result
View All Result

Highlights

Bank of England will monitor cash acceptance on ongoing basis

Amanda Anisimova vs Iga Swiatek – Wimbledon women’s final LIVE: A break of serve in the first set as both aim for maiden SW19 title

Simple ingredient will stop iced coffee tasting watery and bland during heatwave

Ominous ‘Doomsday cloud’ shrouds Maryland in darkness amid storm warnings

How to buy Obama tickets now for UK visit | Theatre | Entertainment

The new ‘It’ girl and supermodel who look YEARS older… as experts issue stark warning about beauty treatment used by millions

London Mail

London Mail | Stay Informed, Stay Inspired ©2025, All rights Reserved

Navigate Site

  • Home
  • About
  • Advertise
  • Contact

Follow Us

No Result
View All Result
  • Home
  • Tech
  • News
  • Business
  • Science
  • Health
  • Sports
  • Lifestyle
  • Travel
  • Opinion

London Mail | Stay Informed, Stay Inspired ©2025, All rights Reserved