Marks & Spencer said a cyberattack exposed customer personal data and caused prolonged disruption across its retail operations, including suspended online orders, store outages, delivery problems, and empty grocery shelves. The company said stolen information included names, dates of birth, home and email addresses, phone numbers, household details, and online order histories, prompting password resets for online accounts. UK authorities, including the National Cyber Security Centre, worked with affected retailers and law enforcement as the fallout spread beyond M&S.
The attack has been linked in reporting to Scattered Spider and the DragonForce ransomware and extortion operation, with Co-op and Harrods also reported as targets around the same period. M&S later said the intrusion began through a contractor compromised via sophisticated social engineering rather than exploitation of a flaw in its own systems, and warned the impact would continue for months. The retailer estimated the incident would cut profits by about £300 million, with some losses expected to be offset through insurance and other recovery measures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Later financial reporting said the cyberattack had almost wiped out M&S profits, underscoring the long-term business impact of the incident beyond the initial operational disruption.
M&S disclosed that the cyberattack was expected to disrupt its online business into July and reduce annual profits by about £300 million, with the impact partly offset by insurance and other measures.
Co-op later confirmed that customer data was also stolen in the related retail attacks, while the U.K. National Cyber Security Centre said it was working with affected organizations and law enforcement to understand the incidents.
M&S said attackers stole customer data including names, dates of birth, contact details, household information, and online order histories. The company said payment card details and account passwords were not exposed and began resetting online account passwords.
Media reports and industry coverage linked the M&S intrusion to Scattered Spider, with DragonForce ransomware/extortion infrastructure also cited in connection with the attack.
Shortly after the M&S incident, similar cyberattacks were reported against other U.K. retailers including Co-op and Harrods, indicating a broader campaign affecting the sector.
Following the intrusion, M&S suspended website orders and experienced operational disruption affecting stores, partner deliveries, and grocery availability, with reports of empty shelves and outages.
Marks & Spencer detected a cyber intrusion over the Easter weekend after threat actors reportedly gained access through a contractor using sophisticated social engineering rather than exploiting an M&S system vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcetheguardian.com
Open sourcetheguardian.com
Open sourcecomputerweekly.com
Open sourcebbc.co.uk
Open sourcetechcrunch.com
Open sourcetheregister.com
Open sourcetheweek.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.