Breach report
RetailMarks & Spencer
Marks & Spencer confirms customers' personal data was stolen in hack
A ransomware attack over Easter 2025 halted Marks & Spencer's online sales for weeks, emptied store shelves and exposed customer personal data, costing the British retailer an estimated £300 million in lost profit.
Reported by TechCrunch
Records exposed
Undisclosed
Undisclosed (M&S had about 9.4 million online customers)
- When
- 2025
- How they got in
- Social engineering of IT help desk followed by DragonForce ransomware
- Sector
- Retail
Marks & Spencer, one of Britain's best-known retailers, began experiencing disruption to contactless payments and click-and-collect orders over the Easter weekend of April 2025. On April 22 it confirmed a cybersecurity incident, and days later it suspended online and app orders entirely. On May 13 the company confirmed that customer personal data had been stolen, including names, dates of birth, home and email addresses, phone numbers, household information and online order histories. M&S said payment card details and account passwords were not taken, but it required customers to reset their passwords as a precaution.
Investigators and news reports linked the intrusion to Scattered Spider, a loose network of mostly young, English-speaking hackers known for impersonating staff in calls to IT help desks to obtain password resets. The attackers reportedly gained a foothold months earlier and then deployed ransomware from the DragonForce operation against the company's virtual server infrastructure. M&S chairman Archie Norman later told British lawmakers that the attackers had used sophisticated impersonation involving a third party, and declined to say whether the company had engaged with or paid the hackers.
The operational damage was extensive. Online orders in the U.K. were halted for roughly seven weeks, some food shelves went bare as automated stock systems faltered, and staff reverted to manual processes. M&S estimated that the attack would reduce its operating profit by about £300 million, partly offset by insurance, and its share price fell sharply in the weeks after the incident. The same campaign also struck the Co-op and attempted to breach Harrods.
In July 2025, the U.K.'s National Crime Agency arrested four people, aged between 17 and 20, on suspicion of offenses including computer misuse, blackmail and money laundering in connection with the attacks on M&S, Co-op and Harrods. The incidents prompted the government to discuss new measures on ransomware payments and pushed the country's cyber agency to issue guidance urging retailers to tighten help desk identity checks.
The M&S attack demonstrated that a well-executed social engineering call can do as much damage as an advanced technical exploit, and that ransomware's real cost often lies in lost trading rather than stolen data. It showed how dependent modern retailers are on interconnected supply chain and ordering systems. For businesses, the key takeaways were to verify identities rigorously before resetting credentials and to rehearse offline operations; for customers, it was a warning to be wary of messages exploiting the breach.