The ongoing outages at British retail chain Marks & Spencer (M&S) are due to a ransomware, allegedly carried out by hackers known as “Scattered Spider,” according to information collected by BleepingComputer.

Last Tuesday, the company announced that it had suffered a cyberattack that caused serious disruptions, affecting contactless payments and online ordering , among other things . According to various media outlets, the problems persist, with around 200 warehouse workers being told to stay home as Marks & Spencer tries to manage the situation.
See also: Interlock ransomware behind DaVita attack
BleepingComputer has revealed that the cause of the ongoing problems is a ransomware attack that has encrypted the company’s servers. It is believed that hackers “Scattered Spider” have been breaching M&S’s systems since February, stealing the NTDS.dit, which is associated with the company’s Windows domain. NTDS.dit is the core database for Active Directory Services running on a Windows domain controller and contains, among other things, password hashes for Windows accounts. Cybercriminals can extract this data and attempt to recover the actual passwords offline.
By obtaining these credentials, attackers can spread within the company's network, stealing data from servers and other network devices.
According to BleepingComputer's sources, the attackers eventually deployed the DragonForce to VMware ESXi on April 24, locking down virtual machines. Marks & Spencer is said to have enlisted the help of CrowdStrike, Microsoft , and Fenix24 to investigate and address the cyberattack.
The investigation so far indicates that the hackers Scattered Spider are behind the ransomware attack on Marks & Spencer.
Who is the Scattered Spider team?
The Scattered Spider group, also known by the names 0ktapus, Starfraud, UNC3944, Scatter Swine, Octo Tempest, and Muddled Libra, is comprised of experienced cybercriminals who specialize in social engineering attacks, phishing, multi-factor authentication (MFA) bombing, and targeted intrusions into large networks.
See also: Medusa Ransomware demands $4 million ransom from NASCAR
It is mainly made up of young English-speaking individuals, even as young as 16, who possess various skills and are active on hacking forums, Telegram groups and Discord servers. Through these platforms they organize and execute their attacks in real time.
There is also an assessment that some of its members belong to the so-called “Comm”, an informal online community associated with violent actions and cybercriminal activities, which has attracted media interest.
Although the media and researchers often describe Scattered Spider as a single criminal organization, it is actually a network of individuals, with different threat actors participating in each attack. This flexible structure makes it difficult to track and analyze.
The group began with activities involving financial fraud and attacks on social media accounts, but then evolved into highly sophisticated social engineering, aimed at stealing cryptocurrencies or breaching corporate networks for extortion purposes.
Their campaign escalated in September 2023, when they managed to breach MGM Resorts, posing as an employee who contacted the company's technical support department. In this attack, the hackers used the ransomware BlackCat to encrypt over 100 VMware ESXi hypervisors.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This incident is considered a turning point in the ransomware space, as it was the first indication of cooperation between English-speaking and Russian-speaking criminal groups in cyberspace.
See also: Arcus Media ransomware: Did it target the National Audit Office of Kiribati?
Since then, Scattered Spider has reportedly acted as a collaborator for various ransomware operations, including RansomHub, Qilin , and, most recently, DragonForce.
Scattered Spider hackers attacked Marks & Spencer: Ransomware protection:
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to the network
- Encryption of sensitive data
- Updating devices and systems with the latest security patches
- Conducting regular security audits and penetration testing
- Using strong, unique passwords
- Limiting user access to only necessary systems and information
- Use solutions email security for additional protection against phishing attacks
- Recovery plan for rapid restoration of systems in the event of an attack
- Regular data backups
Source: www.bleepingcomputer.com
