Back to blog

Blog Post

Scattered Spider Linked to Marks & Spencer Cyberattack

Share on social

May 2, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Scattered Spider Linked to Marks & Spencer Cyberattack

[Marks & Spencer Attack]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

A significant cyberattack on British retailer Marks & Spencer (M&S) has been linked to the hacking group Scattered Spider, who have been previously associated with breaches at MGM Resorts and Caesars Entertainment in the U.S.

The attackers are believed to have deployed ransomware to encrypt key M&S systems, according to BleepingComputer. The same group, which reportedly consists of a group of individuals in their 20s from the U.K. and U.S., has been previously charged in the U.S. for phishing schemes targeting cryptocurrency.

The fallout from the attack has been significant. Online sales, typically worth £3.8 million per day, have now been suspended for five consecutive days. While customers can still browse M&S’s website and shop in physical stores, technical issues still persist. Gift cards are currently not being accepted, and returns are restricted to tills in clothing and homeware stores or by post. Food stores are unable to process returns entirely.

The disruption and uncertainty around a resolution have concerned investors, wiping £500 million from M&S’s stock market value over the past week. It is suggested the attack may have originated via one of the retailer’s third-party service providers, raising concerns about the wider M&S supply chain.

In a brief statement, M&S said: “As you would expect, we cannot share the details of this cyber incident.”

The breach is still unfolding, as investigators work to determine how the attackers infiltrated M&S’s systems and when normal operations can resume.

Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient