Marks & Spencer security incident

DragonForce ransomware / Scattered Spider social engineering; initial access reportedly via a third-party contractor (TCS). Online ordering halted approximately 7 weeks; contactless payment and click-and-collect disrupted; first-ever profit warning tied to cyber.

Last modified

Summary

  • Environment: Retail
  • Operational impact: Online ordering halted approximately 7 weeks; contactless payment and click-and-collect disrupted; first-ever profit warning tied to cyber
  • Financial impact: Est. £300-400M
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In 2025, Marks & Spencer experienced an incident in its retail environment. The retained source describes the attack path as follows: DragonForce ransomware / Scattered Spider social engineering; initial access reportedly via a third-party contractor (TCS). [1]

The documented consequence was: Online ordering halted approximately 7 weeks; contactless payment and click-and-collect disrupted; first-ever profit warning tied to cyber. [1]

Impact

  • Documented impact: Online ordering halted approximately 7 weeks; contactless payment and click-and-collect disrupted; first-ever profit warning tied to cyber. [1]
  • Documented financial consequence: Est. £300-400M. [1]

Threat Group & Attack Vector

The retained source describes the attack path as follows: DragonForce ransomware / Scattered Spider social engineering; initial access reportedly via a third-party contractor (TCS). The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • Scattered Spider — identified in the supported attack description. [1]

TTPs

Response

The retained source describes a forensic or specialist investigation of the incident. [1]

This account is bounded to Full Year Results for 52 Weeks Ended 29 March 2025. Details absent from that evidence are left unresolved rather than inferred. [1]