01Summary
On April 25, 2025, Scattered Spider compromised M&S systems through social engineering. The attackers deployed ransomware, exfiltrated customer and payment-related data, and caused significant disruption to online ordering and store systems. The group threatened to leak stolen customer data unless a ransom was paid.
02Background
Marks & Spencer is one of the UK's most iconic retailers. Like many large retailers, it became a prime target for ransomware groups seeking both financial gain and media attention.
03Key revelations
- 01Continued success of Scattered Spider-style social engineering attacks against large retailers.
- 02High business impact of ransomware on physical + online retail operations.
04Technical analysis
Initial access via vishing targeting helpdesk or IT staff, followed by privilege escalation and ransomware deployment. The attack also involved data exfiltration before encryption.
- Attack vector
- Vishing / Social Engineering
- Attack method
- Ransomware deployment + Double Extortion
- Initial access
- Vishing (Voice Phishing)
- Lateral movement
- Privilege Escalation
- Exfiltration
- Bulk data extraction
- Tool / malware
- Custom ransomware variant
- Malware type
- Ransomware
Vulnerabilities exploited
- Human vulnerability to social engineering
05Threat actor
Scattered Spider – highly sophisticated group known for vishing, social engineering, and targeting large consumer-facing organizations.
Aliases
- Scattered LAPSUS$ Hunters
- SH
Attribution sources
- Marks & Spencer statements
- BleepingComputer
- The Telegraph
06Victims and impact
Countries affected
- United Kingdom
07Data exposed
Data types
- Customer PII
- Order History
- Payment Details (partial)
- Contact Information
08Financial damage
Tens of millions in lost revenue, recovery costs, and regulatory fines.
09Timeline
- 2025-04-25Attack begins.
- 2025-04-28M&S publicly acknowledges the incident.
- 2025-05-10Major systems restored.
10Reaction and fallout
Public reaction
Frustration over disrupted shopping and fear of personal data exposure.
Political impact
Increased UK government pressure on critical retail infrastructure security.
11Legal
Ongoing ICO investigation.
Civil lawsuits
- Class-action lawsuits filed by affected customers
12Aftermath
Policy changes
- Stronger emphasis on social engineering defense in retail sector.
Security improvements
- Major overhaul of helpdesk verification processes
- Improved segmentation and backup systems
13Significance and legacy
Significance
One of the most disruptive retail cyberattacks in the UK in 2025.
Legacy
Led to industry-wide improvements in ransomware preparedness for retailers.
14Disclosure and media
- Authentication
- Ransom notes and hacker leak site
Publishing organisations
- BBC
- The Telegraph
- BleepingComputer
15Field notes
- 01The attack significantly impacted M&S's peak spring/summer trading period.
16Resolution
Systems gradually restored; data was eventually leaked by the attackers.
17Sources
Official documents
- M&S Cyber Incident Update
References
- [1]Marks & Spencer official statements
- [2]BBC News coverage
- [3]The Telegraph









