EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2025-marks-and-spencer-breach
064/430

File EL-0367HighResolvedData Breach / Ransomware / Business Disruption

Marks & Spencer Cyber Attack

Also filed as M&S Ransomware Attack · Marks & Spencer Sainsbury's Supply Chain Incident

Sophisticated ransomware and data extortion attack on British retail giant Marks & Spencer that caused major operational disruption and exposed customer data.

  • #retail
  • #ransomware
  • #supply-chain
  • #uk
  • #business-disruption
Notoriety8/10
Event
25 Apr 2025
Disclosed
28 Apr 2025
Target
Marks & Spencer
Actor
Scattered Spider
Scale
2.5M people
Status
Resolved

01Summary

On April 25, 2025, Scattered Spider compromised M&S systems through social engineering. The attackers deployed ransomware, exfiltrated customer and payment-related data, and caused significant disruption to online ordering and store systems. The group threatened to leak stolen customer data unless a ransom was paid.

02Background

Marks & Spencer is one of the UK's most iconic retailers. Like many large retailers, it became a prime target for ransomware groups seeking both financial gain and media attention.

03Key revelations

  1. 01Continued success of Scattered Spider-style social engineering attacks against large retailers.
  2. 02High business impact of ransomware on physical + online retail operations.

04Technical analysis

Initial access via vishing targeting helpdesk or IT staff, followed by privilege escalation and ransomware deployment. The attack also involved data exfiltration before encryption.

Attack vector
Vishing / Social Engineering
Attack method
Ransomware deployment + Double Extortion
Initial access
Vishing (Voice Phishing)
Lateral movement
Privilege Escalation
Exfiltration
Bulk data extraction
Tool / malware
Custom ransomware variant
Malware type
Ransomware

Vulnerabilities exploited

  • Human vulnerability to social engineering

05Threat actor

Scattered Spider – highly sophisticated group known for vishing, social engineering, and targeting large consumer-facing organizations.

Aliases

  • Scattered LAPSUS$ Hunters
  • SH

Attribution sources

  • Marks & Spencer statements
  • BleepingComputer
  • The Telegraph

06Victims and impact

Countries affected

  • United Kingdom

07Data exposed

Data types

  • Customer PII
  • Order History
  • Payment Details (partial)
  • Contact Information

08Financial damage

Tens of millions in lost revenue, recovery costs, and regulatory fines.

09Timeline

  1. 2025-04-25Attack begins.
  2. 2025-04-28M&S publicly acknowledges the incident.
  3. 2025-05-10Major systems restored.

10Reaction and fallout

Public reaction

Frustration over disrupted shopping and fear of personal data exposure.

Political impact

Increased UK government pressure on critical retail infrastructure security.

11Legal

Ongoing ICO investigation.

Civil lawsuits

  • Class-action lawsuits filed by affected customers

12Aftermath

Policy changes

  • Stronger emphasis on social engineering defense in retail sector.

Security improvements

  • Major overhaul of helpdesk verification processes
  • Improved segmentation and backup systems

13Significance and legacy

Significance

One of the most disruptive retail cyberattacks in the UK in 2025.

Legacy

Led to industry-wide improvements in ransomware preparedness for retailers.

14Disclosure and media

Authentication
Ransom notes and hacker leak site

Publishing organisations

  • BBC
  • The Telegraph
  • BleepingComputer

15Field notes

  1. 01The attack significantly impacted M&S's peak spring/summer trading period.

16Resolution

Systems gradually restored; data was eventually leaked by the attackers.

17Sources

Official documents

  • M&S Cyber Incident Update

References

  1. [1]Marks & Spencer official statements
  2. [2]BBC News coverage
  3. [3]The Telegraph
Fact sheetEL-0367

Dates

Event
25 Apr 2025
Started
25 Apr 2025
Ended
10 May 2025
Duration
16 days
Discovered
25 Apr 2025
Disclosed
28 Apr 2025
Ongoing
No

Target

Organisation
Marks and Spencer Group plc
Type
Retail Company
Sector
Retail
Country
United Kingdom

Actor

Name
Scattered Spider
Type
Criminal Gang
Motivation
Financial gain through ransomware extortion and data theft.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
2,500,000
Records
2,500,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.