Retail chain Marks & Spencer (M&S) has publicly confirmed that it was the victim of a complex cyberattack, which began with phishing/social engineering and culminated in a widespread ransomware attack, allegedly carried out by the DragonForce group.

The revelation was made by M&S chairman Archie Norman during his testimony to the British Parliament's (as part of hearings on the growing cyber threats to the retail sector).
The principle of the attack: Social engineering via a third party
According to Norman, the attackers breached the network on April 17 through “social engineering.” The method involved stealing the identity of one of the company’s 50,000 associates, with the aim of tricking a third party — likely provider technical support — into resetting an employee’s credentials.
See also: BERT Ransomware disables ESXi virtual machines
"And it was a sophisticated impersonation. They didn't just come in and say, 'Will you change my password?' They were impersonating someone with their credentials. And part of the entry point also involved a third party," the president said.
Tata Consultancy Services (TCS), which provides IT helpdesk services to M&S, is believed to have been the key player in the breach, having been duped into inadvertently allowing hackers to gain access to the company's internal network. However, the investigation is still ongoing.
DragonForce and ransomware with double extortion
M&S has officially named DragonForce as the perpetrator behind the cyberattack for the first time, noting that it is a ransomware organization likely based in Asia. However, the identification of the group has caused confusion, as the name “DragonForce” is also used by a hacktivist group , reportedly based in Malaysia — but with no connection to the ransomware variant.
See also: SafePay ransomware behind Ingram Micro outage
According to information from BleepingComputer , the threat actors are linked to the well-known Scattered Spider group , which used the DragonForce ransomware as the final payload for the attack.
M&S was forced to immediately shut down its systems, but the move came too late: many VMware ESXi servers had already been encrypted, and it is rumored that up to 150GBof data.
DragonForce is reportedly following a “double extortion”: encrypting files and stealing data, with threats of making them public if a ransom is not paid.
Pay or not? M&S keeps its papers closed
Although it is believed that data was stolen, no listings for M&S have so far appeared on leak sites ransomware, which may indicate that:
- either a ransom was paid to prevent the leak,
- either the perpetrators remain in negotiations with the company.
Archie Norman said the company decided not to negotiate directly with the perpetrators, but to leave the handling to specialist ransomware negotiators, who have access to expertise and resources for secure payments, e.g. in cryptocurrencies.

When asked directly whether a ransom was paid, he said he would not comment publicly on the matter, but stressed that M&S was fully cooperating with the National Crime Agency (NCA) and the authorities.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Automation and vulnerability exploitation are boosting ransomware
Another “bell” for the retail sector
The attack on M&S once again highlights the vulnerability of retail to cyberthreats that exploit third-party providers, human error and internal security procedures.
As ransomware attacks become increasingly sophisticated, businesses are being urged to strengthen:
- Staff training on phishing/social engineering issues
- The identification and confirmation of requests policies
- Third-party provider control
- The security of virtualization, such as VMware ESXi servers, remains a key objective.
The M&S case serves as a typical case study of how a simple impersonation can lead to a financial, operational and communication crisis for an entire organization.
Source: www.bleepingcomputer.com
