Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptionbreach-disclosure-notificationthird-party-vendor-breachransomware-group-operation

Marks & Spencer Hack Exposed Customer Data and Drove Major Retail Disruption

Updated 27d agoFirst seen May 25, 20269 sources

Marks & Spencer said a cyberattack exposed customer personal data and caused prolonged disruption across its retail operations, including suspended online orders, store outages, delivery problems, and empty grocery shelves. The company said stolen information included names, dates of birth, home and email addresses, phone numbers, household details, and online order histories, prompting password resets for online accounts. UK authorities, including the National Cyber Security Centre, worked with affected retailers and law enforcement as the fallout spread beyond M&S.

The attack has been linked in reporting to Scattered Spider and the DragonForce ransomware and extortion operation, with Co-op and Harrods also reported as targets around the same period. M&S later said the intrusion began through a contractor compromised via sophisticated social engineering rather than exploitation of a flaw in its own systems, and warned the impact would continue for months. The retailer estimated the incident would cut profits by about £300 million, with some losses expected to be offset through insurance and other recovery measures.

Share:
Marks & Spencer Hack Exposed Customer Data and Drove Major Retail Disruption
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Nov 5, 20258mo ago

M&S reports profits almost wiped out after cyberattack

Later financial reporting said the cyberattack had almost wiped out M&S profits, underscoring the long-term business impact of the incident beyond the initial operational disruption.

May 21, 20251y ago

M&S says disruption may last into July and profit hit could reach £300m

M&S disclosed that the cyberattack was expected to disrupt its online business into July and reduce annual profits by about £300 million, with the impact partly offset by insurance and other measures.

May 13, 20251y ago

Co-op confirms customer data theft; NCSC engages with victims

Co-op later confirmed that customer data was also stolen in the related retail attacks, while the U.K. National Cyber Security Centre said it was working with affected organizations and law enforcement to understand the incidents.

M&S confirms customer personal data was stolen

M&S said attackers stole customer data including names, dates of birth, contact details, household information, and online order histories. The company said payment card details and account passwords were not exposed and began resetting online account passwords.

May 6, 20251y ago

Reporting links M&S attack to Scattered Spider and DragonForce

Media reports and industry coverage linked the M&S intrusion to Scattered Spider, with DragonForce ransomware/extortion infrastructure also cited in connection with the attack.

Apr 30, 20251y ago

Attacks on Co-op and Harrods linked to same wave emerge

Shortly after the M&S incident, similar cyberattacks were reported against other U.K. retailers including Co-op and Harrods, indicating a broader campaign affecting the sector.

Apr 20, 20251y ago

M&S shuts down online orders and suffers store disruption

Following the intrusion, M&S suspended website orders and experienced operational disruption affecting stores, partner deliveries, and grocery availability, with reports of empty shelves and outages.

M&S detects cyber intrusion over Easter weekend

Marks & Spencer detected a cyber intrusion over the Easter weekend after threat actors reportedly gained access through a contractor using sophisticated social engineering rather than exploiting an M&S system vulnerability.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.