- Hackers behind MGM and Caesars breaches hit Marks & Spencer.
- Google warns US retailers may be next in line for ransomware attacks.
A cyberattack that hit UK retailer Marks & Spencer is raising alarms in the US, with Google warning that hackers behind the disruption may soon turn their attention to American retailers.
“The actors are aggressive, creative, and particularly effective at circumventing mature security programs,” said John Hultquist, a threat analyst at Google’s cybersecurity division.
According to The Guardian, the group believed to be responsible is linked to “Scattered Spider,” a loose collection of hackers based in the US and UK. Some members have been tied to previous high-profile breaches, including attacks on MGM Resorts and Caesars Entertainment.
The M&S breach, which took place in late April, has shut down the retailer’s online operations. By the fifth day of downtime, M&S had lost more than £500 million in market value. Shoppers can still buy in-store, but issues remain: Gift cards don’t work, returns are limited, some products are unavailable, and online orders are still frozen.
According to cybersecurity site BleepingComputer, attackers gained access to M&S systems as early as February. They reportedly stole internal data and later encrypted core systems using ransomware associated with a group called DragonForce.
Some sources suggest the attack began with a third-party supplier, although M&S hasn’t confirmed this. The company said it couldn’t share details, but acknowledged customer data was accessed. Names, addresses, and order histories were among the information taken. No payment details or passwords were exposed, the company says.
“Due to the sophisticated nature of the incident, some of their personal customer data has been taken,” M&S told customers in a message. “Importantly, the data does not include usable payment or card details, which we do not hold on our systems, and it does not include any account passwords.”
M&S said affected users would be asked to reset their passwords, but didn’t say how many customers were involved.
While the retailer says there’s no evidence the stolen data has been shared, experts are advising caution. Many M&S customers have already received phishing messages, including a scam offering a free tea hamper. With more information now in the wild, attackers could increase those efforts.
Stuart Machin, M&S’s CEO, said the company is “working around the clock” to fix the damage and restore services.
Security researchers believe the attack fits the profile of a ransomware breach, in which systems are encrypted and attackers demand payment for a decryption key.
Tim Mitchell from Secureworks noted that Scattered Spider, also known as Octo Tempest, stands out as most hacker groups communicate in Russian and operate from countries where law enforcement takes a hands-off approach. This group, in contrast, communicates in English and often includes younger members. “Their motivation appears to be as much about bragging rights on those channels as about money,” Mitchell said.
He added that hackers may have gained access through phishing emails or by impersonating staff on internal help lines.
Retailers are now on high alert. Julius ÄŒerniauskas, CEO of web intelligence firm Oxylabs, said the M&S breach has likely triggered urgent reviews in the UK retail sector. “The impact on the M&S share price shows the damage these attacks can do,” he said.
Ransomware gangs often aim for large companies that depend heavily on digital operations. The more disruption they cause, the more pressure there is to pay.
Analysts expect M&S could face steep fines. Legal fallout, combined with lost sales, has wiped over £1.2 billion from its market value since the breach was first confirmed.
“The data breach means M&S has a big mountain to climb to win back shoppers’ trust,” said Russ Mould, investment director at AJ Bell. “So many people worry about the safety of their information that they might vote with their feet and go elsewhere if there are lingering concerns about the robustness of M&S’s systems.”
Scattered Spider is known for targeting companies one industry at a time. Retail appears to be their current focus, and Google’s security team says US firms should prepare.
The attack on M&S isn’t an isolated case, with other UK retailers having also been hit in recent weeks. The Co-op Group said hackers accessed names and contact details of many of its customers, although no financial information was exposed. Some stores have struggled with restocking as IT systems were shut down. Harrods, the department store, was also affected by a separate cyberattack and had to shut down parts of its systems.
The UK’s Information Commissioner’s Office (ICO) confirmed it had received reports from both M&S and the Co-op. The ICO is now working with the National Cyber Security Centre and law enforcement. The Metropolitan Police and National Crime Agency are investigating the M&S breach.
Scattered Spider’s reach isn’t limited to the UK. In the US, the group made headlines in 2023 after attacks on MGM and Caesars. Both companies were forced to shut down parts of their operations, with Caesars reportedly payingmillions to restore access.
Despite the attention, authorities have struggled to crack down on the group. The hackers operate as a loosely tied network, often recruiting through online forums. Some members have been charged in the US for phishing and cryptocurrency theft, but many remain unidentified.
The group’s structure and the age of its members make enforcement difficult. Companies hit by ransomware often choose not to report full details to avoid reputational damage, adding to the challenge.
While M&S continues working to restore its systems, the broader message is clear. Cyberattacks are no longer just an IT issue. They hit revenue, trust, and reputation – fast.
Author
View all postsAs a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.