Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
voice-social-engineeringoperational-disruptionthird-party-vendor-breachidentity-impersonation-fraud

Marks & Spencer Cyberattack and IT Helpdesk Contract Termination

Updated 3mo agoFirst seen Oct 28, 20253 sources

Marks & Spencer suffered a major cyberattack in April 2025, reportedly linked to the Scattered Spider group, which used advanced social engineering tactics to impersonate senior executives and trick IT helpdesk staff into resetting critical login credentials. The attack led to the suspension of the retailer’s online shopping platform, failures in contactless payments, and significant supply chain disruptions, resulting in an estimated £300 million loss in operating profits. The incident drew public and parliamentary scrutiny, particularly regarding the role of Tata Consultancy Services (TCS), whose staff managed key support lines and password resets targeted by the attackers. Four individuals were arrested by the National Crime Agency in connection with the attack on M&S and other British retailers.

In the aftermath, Marks & Spencer replaced TCS as its IT service desk provider, a decision both companies stated was the result of a procurement process that began before the cyber incident and not a direct response to the breach. TCS continues to provide other IT services for M&S, including data center management, while cybersecurity services are handled by other vendors. The breach and its fallout have prompted M&S to reassess its digital operations, cybersecurity posture, and vendor management strategies, with full restoration of some services, such as Click & Collect, only achieved months after the attack.

Share:
Marks & Spencer Cyberattack and IT Helpdesk Contract Termination
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Oct 28, 20258mo ago

UK authorities arrest four over attacks on British retailers

The UK National Crime Agency arrested four people in connection with cyberattacks targeting M&S and other British retailers. The arrests marked a law-enforcement escalation in the investigation of the retail attack spree.

M&S warns cyberattack will cut profits by about £300 million

M&S CEO Stuart Machin said the cyber incident was expected to reduce profits by roughly £300 million in the 2025/26 financial year. The estimate underscored the scale and duration of the business impact from the attack.

Oct 27, 20258mo ago

M&S replaces TCS as IT service desk provider

In late October 2025, M&S ended or replaced Tata Consultancy Services in the IT service desk role while retaining TCS in other strategic technology work. Both companies said the change followed the procurement process launched in January, though it came amid fallout from the April cyberattack.

TCS says its review found no compromise of its own systems

Tata Consultancy Services said its internal investigation found no compromise of TCS networks or systems and that the relevant weaknesses were in the client environment. TCS also emphasized it did not provide cybersecurity services to M&S.

Apr 1, 20251y ago

Attack attributed to Scattered Spider social engineering

Reporting later attributed the M&S intrusion to Scattered Spider, which allegedly impersonated senior M&S executives to convince helpdesk staff to reset critical credentials. The social-engineering access path became a key technical detail in understanding the breach.

Cyberattack disrupts Marks & Spencer operations

In April 2025, Marks & Spencer disclosed a major cyberattack that caused significant operational disruption. Reported impacts included outages affecting online shopping, Click & Collect, contactless payments, and parts of the supply chain.

Jan 1, 20251y ago

M&S launches competitive procurement for IT service desk

Marks & Spencer began a competitive procurement process for its IT service desk contract in January 2025. Later statements from M&S and Tata Consultancy Services said the eventual contract change stemmed from this process rather than a direct finding of fault from the cyber incident.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Organizations
8 linked
Tata Consultancy ServicesMarks & SpencerFujitsuWalmartnca_ukScattered SpiderGoogleSapient
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.