Skip to content
NetarxImpact Database
Help Desk ImpersonationNo AI reportedConfirmed

Marks & Spencer attack tied to social engineering of outsourced service desk

Marks & Spencer Group plc · Retail · United Kingdom · April 22, 2025

What happened

Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.

How the deception worked

Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.

Sources (6)

  1. M&S hackers gained access through third-party Tata Consulting Services, sources say
    Cybernews·cybernews.comOpen ↗
  2. M&S confirms month-long breach result of third-party vendor phishing attack
    Cybernews·cybernews.comOpen ↗
  3. Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages
    The Hacker News·thehackernews.comOpen ↗
  4. Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre
    BBC News·feeds.bbci.co.ukOpen ↗
  5. Marks and Spencer confirms data breach after April cyber attack
    Security Affairs·securityaffairs.comOpen ↗
  6. Marks & Spencer breach linked to Scattered Spider ransomware attack
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.