What happened
Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.
How the deception worked
Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.
Sources (6)
- M&S hackers gained access through third-party Tata Consulting Services, sources sayCybernews·cybernews.comOpen ↗
- M&S confirms month-long breach result of third-party vendor phishing attackCybernews·cybernews.comOpen ↗
- Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in DamagesThe Hacker News·thehackernews.comOpen ↗
- Beware phony IT calls after Co-op and M&S hacks, says UK cyber centreBBC News·feeds.bbci.co.ukOpen ↗
- Marks and Spencer confirms data breach after April cyber attackSecurity Affairs·securityaffairs.comOpen ↗
- Marks & Spencer breach linked to Scattered Spider ransomware attackBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.