Cyberattack Cripples M&S Operations in £10m Ransomware Assault

Cybersecurity analysts have warned that this breach could compromise the entire IT environment.

1 min read
File Photo from Marks and Spencer

Marks & Spencer has been hit by a major cyberattack, reportedly carried out by a hacking collective known as Scattered Spider, causing widespread disruption across its UK operations.

According to a report by tech news outlet BleepingComputer, the group—allegedly comprising young hackers based in the UK and the US—launched a ransomware attack on the high street giant’s IT infrastructure in February. Though the attack remained undisclosed for weeks, its effects have now become visible across the retailer’s network of 1,049 stores and online services.

Industry sources estimate that the ransom demand could be as high as £10 million, a figure not uncommon in high-profile corporate ransomware cases. However, M&S has not confirmed whether it has received or paid a ransom.

As a result of the breach, the retailer was forced to pause online orders on Friday, April 25, and advised customers using click-and-collect services to wait for confirmation emails before visiting stores. Approximately 200 agency workers at its Castle Donington distribution centre in the East Midlands have been told to stay home, severely impacting logistics.

Shares in the FTSE 250-listed company have fallen nearly 7% since the cyberattack was disclosed last week, with investors rattled by the potential long-term fallout and interruption to revenue.

According to reports, the attackers managed to extract the NTDS.dit file from the company’s Windows domain in February—a critical component of the Active Directory system that contains sensitive credentials and security data. Cybersecurity analysts have warned that this breach could compromise the entire IT environment.

Sources also allege that the hackers used the “DragonForce” encryptor to lock M&S systems, rendering data and operations inaccessible unless a decryption key is provided. The retailer has enlisted the help of major cybersecurity firms including CrowdStrike, Microsoft, and Fenix24 to investigate and mitigate the damage.

In a statement, M&S confirmed it has no timeline yet for when full services will resume. Remote-working staff have seen their access to internal systems restricted, though some functions remain operational.

The incident has been reported to the UK’s data protection authorities and the National Cyber Security Centre. Experts note that paying a ransom—while potentially expediting recovery—presents a significant ethical and strategic dilemma. Law enforcement typically advises against it, citing the risk of encouraging further attacks and the absence of guarantees that attackers will honor decryption promises.

The attack represents a setback for the retailer, which had recently seen success from a broader turnaround strategy under CEO Stuart Machin. Improved sales and pre-tax profits had signaled renewed momentum for the iconic British brand.

M&S declined to comment further on the incident.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog