Cyber Security News

Marks & Spencer Confirmed Customer Data Theft in Recent Cyber Attack

British retail giant Marks & Spencer has confirmed that customer personal information was compromised in the recent cyber attack that has crippled its digital operations for over three weeks. 

The incident, which began during Easter weekend, has resulted in continued disruption, including suspended online services and product availability issues in stores.

M&S revealed that threat actors exfiltrated various types of customer information during the attack. The stolen data may include customers’ names, home and email addresses, phone numbers, dates of birth, and online order history. 

CEO Stuart Machin emphasized that “there is no evidence that the information has been shared,” though security experts warn this could change as the situation develops.

Importantly, M&S has clarified that the breach did not compromise usable payment card details or account passwords. 

The company stores limited payment information, making any stolen financial data essentially unusable. Nevertheless, as a precautionary measure, all online customers will be prompted to reset their passwords the next time they attempt to access their accounts.

DragonForce Ransomware Behind M&S Cyberattack

BBC reports that the attack is attributed to the DragonForce ransomware group, which has been linked to similar recent incidents targeting other UK retailers, including Co-op and Harrods. 

DragonForce operates as a Ransomware-as-a-Service (RaaS) provider, employing a double extortion technique that combines traditional file encryption with data theft.

Analysis from security researchers indicates that initial access may have been gained through social engineering attacks on IT helpdesk workers, potentially involving password reset manipulations. 

Reports also suggest the involvement of Scattered Spider (also known as UNC3944), a hacking collective composed primarily of teenagers and young adults operating from the US and UK.

The attackers may have extracted the NTDS.dit file – a critical Active Directory database containing user credentials and password hashes – allowing them comprehensive access throughout M&S’s network infrastructure. 

This technique is consistent with DragonForce’s documented tactics, which include exploiting valid accounts and manipulating registry keys to maintain persistence.

The cyber attack has had severe financial consequences, with M&S’s share price dropping approximately 11% and wiping more than £1 billion from its market value. 

Online ordering remains suspended after nearly three weeks, with no announced timeline for restoration. Some physical stores continue experiencing product availability issues as systems were taken offline as a protective measure.

M&S has notified all 9.4 million active online customers about the breach. The company is working with the National Crime Agency, National Cyber Security Centre, and Metropolitan Police to investigate the incident.

While M&S states that customers don’t need to take immediate action, security experts recommend vigilance regarding potential phishing attempts using the stolen information. 

Customers should be particularly cautious about communications claiming to be from M&S and should avoid clicking links in suspicious emails or messages.

The attack highlights the growing sophistication of ransomware operations and the critical importance of robust cybersecurity measures, particularly for organizations handling large volumes of customer data.

Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago