The Vice Society ransomware group claimed responsibility for attacks that disrupted Spar-affiliated stores in the United Kingdom and Isle of Man, affecting card payments and forcing some outlets to close. The gang said it compromised James Hall & Co., the main wholesaler serving more than 600 Spar stores in northern England, as well as Heron and Brearley, owner of Mannin Retail, which operates 19 Spar stores on the Isle of Man. The U.K. National Cyber Security Centre (NCSC) confirmed an incident affecting Spar stores supplied by James Hall & Co. and said impacted locations were being restored.
Vice Society also allegedly published more than 93,000 stolen files on its leak site, suggesting the victims likely did not pay a ransom. The incident highlights the operational impact ransomware can have on retail supply chains, while NCSC guidance continues to urge organizations to harden defenses against malware and ransomware through preventive security controls, resilience planning, and recovery measures.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The U.K. National Cyber Security Centre confirmed that James Hall & Co. had been attacked and said it was aware of an incident affecting some Spar stores serviced by the wholesaler in northern England. The NCSC also said James Hall & Co. had confirmed it was bringing affected stores back online.
Spar reported that an online attack on its IT systems was affecting some U.K. operations. The incident disrupted card payment processing and led to temporary store closures.
Vice Society posted more than 93,000 files on its leak site that were allegedly stolen in the attacks. The publication of the data suggested the victims likely did not pay a ransom.
Vice Society claimed responsibility for attacks affecting James Hall & Co. and Heron and Brearley, whose Mannin Retail operates Spar stores on the Isle of Man. Kela reported that leaked files appeared related to Spar operations and both named companies.
Vice Society launched its data leak site, which it later used to name victims and publish stolen data. The article cites this as part of the group's broader ransomware activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.