Fingers are pointing to the prolific Scattered Spider hacking group as the culprits of the recent Marks and Spencer cyber-attack, which has already cost the British retailer millions in lost sales as well as sending its value crashing by almost £700 million.
Reports have emerged that the ongoing chaos at M&S, which has seen warehouse staff told not to go to work and thousands of customers left in limbo, stems from a ransomware attack that encrypted the company’s servers.
As first reported by Bleeping Computer, the hackers are thought to have broken into M&S’s systems as far back as February. During the initial breach, they supposedly stole the firm’s NTDS.dit file from the main Windows server, using this to access passwords for the company’s Windows accounts.
According to industry rumours reported by the Guardian, it is unclear at the moment if M&S was directly targeted, as the attack may have originated with the company’s service suppliers.Â
Regardless, using the lifted credentials, once threat actors got inside Marks and Spencer’s network, they spread through the system while looting it for valuable data to encrypt using software allegedly obtained from the DragonForce ransomware operator.
The fallout from Scattered Spiders’ ransomware attack took out the retailer’s contactless payments, effectively halted online orders, and has even reportedly left some stores short of food items, although cybersecurity experts heaped praise on M&S’s initial handling of the cyber-attack.
According to Bleeping Computer, M&S has so far gone to the likes of Microsoft and Crowdstrike to help with the attacks’ aftermath and investigation, while the Met Police also confirmed that detectives from the force’s Cyber-Crime Unit were investigating the cyber-attack, although so far there has not been much in the way of details.
Recommended reading
- 60% of Businesses Anticipating a Cyber-breach in 2025
- VPN Security Fears Pushing Firms To ‘Zero Trust Everywhere’
- Growing Adoption of Zero-trust and Multi-cloud Environments
Scattered Spider, otherwise known as Octo Tempest by Microsoft threat researchers, has a notorious reputation, having been linked to the hack of casino operators MGM Resorts International and Caesars Entertainment in 2023, eventually walking away with an alleged $15 million ransom payout.
Described by an earlier Microsoft report as ‘one of the most dangerous financial criminal groups’ in operation, Scattered Spider have adopted an increasingly aggressive approach since first coming to attention in 2022, targeting firms across diverse industries, including gaming, retail, law, financial services, and manufacturing.
Last year, American law enforcement charged five men as allegedly being part of the ransomware gang, including a British national arrested by UK police in the West Midlands, and accused them of stealing $11 million in cryptocurrency from at least twenty-nine victims as well as taking part in corporate raiding.





