logo
M&S cyber-attack linked to hacking group Scattered Spider

M&S cyber-attack linked to hacking group Scattered Spider

The Guardian29-04-2025

A major cyber-attack on Marks & Spencer has been linked to a hacking collective known as Scattered Spider, which is previously thought to have hit MGM Resorts and the US casino operator Caesars.
The group, which has previously been found to include people in their 20s from the UK and the US – some of whom faced charges over attempts to steal cryptocurrency via phishing attacks in the US – are reported to have encrypted key M&S systems using ransomware, according to the technology specialist site BleepingComputer.
The reports emerged as online sales at M&S – which account for an average £3.8m a day – were suspended for a fifth day.
The disruption caused by the hack – and uncertainty over when it will end – has wiped more than £500m off the stock market value of M&S in the past week as experts said it had clearly suffered a cyber-attack on a huge scale.
Industry insiders said it was rumoured that the attack had originated at one of M&S's service suppliers and it was not clear if the company had been directly targeted.
M&S said: 'As you would expect, we cannot share the details of this cyber incident.'
BleepingComputer reported the hackers had stolen M&S data as early as February that could have helped them gain access to key systems. It said the hackers had then encrypted access to a server using software from the ransomware operator DragonForce last week.
Tim Mitchell, a senior threat researcher at SecureWorks, said that while it was impossible for outsiders to confirm who the hackers were, the extent of the disruption caused to M&S indicated it had been subject to a ransomware attack. These attacks encrypt access to important systems and demand a ransom in return for a key to unlock them.
He said Scattered Spider, also known as Octo Tempest, appeared to be 'quite unusual' as a hacking group in that they were largely English-speaking – unlike the majority of such groups, which are based in places such as Russia, where there is a more 'permissive environment' where they have more freedom to operate.
He added: 'Their motivation appears to be as much about bragging rights on those channels [where they communicate] as about money.'
Sign up to Business Today
Get set for the working day – we'll point you to all the business news and analysis you need every morning
after newsletter promotion
He said the hackers could have used phishing emails, gained control of a company phone number or rung up help services pretending to be M&S employees to gain access to systems.
Julius Černiauskas, the chief executive of the web intelligence experts Oxylabs, added: 'Following the M&S cyber-attack and the potential involvement of hacking group, Scattered Spider, all major UK retailers will be seriously worried if they'll be tangled in the web next. The impact on the M&S share price shows the damage these attacks can do and will have many corporate retailers working day and night to ensure they do not suffer a similar fate.
'Ransomware gangs typically target companies like M&S with the aim of causing maximum disruption to force a quick payout. Their goal is simple: the greater the disruption, the greater the pressure on the company to pay the ransom.'
Shoppers are still able to browse online and shop in M&S's physical stores using cash or cards, but some difficulties continue in stores, with gift cards not currently being accepted. Returning goods is only possible at tills in clothing and homeware stores or via post. Food stores are not currently able to accept returns.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

UK's 2nd longest pier to finally reopen in £600bn cash injection boosting Victorian seaside town's economy
UK's 2nd longest pier to finally reopen in £600bn cash injection boosting Victorian seaside town's economy

Scottish Sun

time8 hours ago

  • Scottish Sun

UK's 2nd longest pier to finally reopen in £600bn cash injection boosting Victorian seaside town's economy

The project could boost the town's tourism industry with new jobs and business opportunties PIER IN UK's 2nd longest pier to finally reopen in £600bn cash injection boosting Victorian seaside town's economy Click to share on X/Twitter (Opens in new window) Click to share on Facebook (Opens in new window) AN HISTORIC pier at a popular seaside town is set to reopen following a £600 billion cash injection. After closing in 2022, Southport Pier could be revived after the government promised to prioritise local developments projects in its Spending Review. Sign up for Scottish Sun newsletter Sign up 4 Southport Pier is set to reopen following a recent government announcement Credit: Getty 4 4 The pier has been closed since 2022 after adverse weather caused damage Credit: Getty 4 It's part of a £600 billion country-wide development project Credit: Getty Chancellor Rachel Reeves announced the review on June 11, which included a £600 billion cash injection to support the country's infrastructure. This cash injection aims to expedite a range of locally-significant development projects, including Southport Pier. It clarifies how day-to-day expenditure will be used in the country, as well as capital spending on transport, schools, community assets and hospitals. In a speech at the Houses of Parliament, Chancellor Reeves said: "I know the pride that people feel in their communities. I see it everywhere I go, but I also know that for too many people, there is a sense that something has been lost." She cited the death of the high street as one of the problems facing British towns, alongside a decline in community spaces, jobs and opportunities. The Spending Review aims to solve some of these problems as Reeves added: "Job creation and community assets are vital to our growth mission, but too often, regeneration projects are held back, gathering dust in bureaucratic limbo. We are changing that." During the speech, she named Southport Pier as just one of the projects that could benefit. The government hopes that reopening the pier, which has been shut since 2022, could create jobs and new business opportunities in the local area. Sefton Council closed the historic pier - which is the second longest in the country - after a period of extreme weather that left structural engineers concerned. Trendy English seaside town has rooftop bar that 'feels like the Med' Southport locals were excited at the prospect of a revival of such a culturally significant site for the town. Local MP Patrick Hurley said: "We've got a commitment from the Chancellor at the dispatch box to support the project. What that support means, in concrete and practical terms, is that there's going to be funding made available to make sure that the pier can be reopened." Hurley announced that by the end of summer they would have a better understanding of the exact funding, as well as the concrete proposals and timescales that would enable the pier to reopen. Mayor of Liverpool City Region, Steve Rotheram, expressed his support for the project. During a meeting at Lancaster House, Mr Rotheram said that Prime Minister Keir Starmer had given his word that Southport would be included in the development plans. Mayor Rotheram said: "This hasn't happened by chance. It's the result of tireless work by people who've never stopped fighting for the town's future." He credited Councillor Marion Atkinson and MP Hurley as being integral to the project's success, as well as the enthusiasm of Southport locals. In addition to being Britain's second longest pier, Southport Pier also has an important history. First opened in 1860, it has hosted famous performers like Charlie Chaplin. A restoration project between 2000 and 2002 helped to revive the pier and boost the local tourism industry before it closed in 2022.

M&S reveals new summer cafe menu including Matilda cake dupe and Eton mess milkshake
M&S reveals new summer cafe menu including Matilda cake dupe and Eton mess milkshake

Scottish Sun

time10 hours ago

  • Scottish Sun

M&S reveals new summer cafe menu including Matilda cake dupe and Eton mess milkshake

M&S has taken a classic favourite to a whole new level – scroll down! Click to share on X/Twitter (Opens in new window) Click to share on Facebook (Opens in new window) MARKS & Spencer has unveiled a brand-new summer menu at its cafés across the UK, featuring more than 30 exciting new dishes, cakes, and drinks. Designed to reflect the sunny season, the new offerings are sure to attract customers looking for something fresh and indulgent. Sign up for Scottish Sun newsletter Sign up 4 A customer is seen at the British multinational retailer Marks & Spencer Credit: Getty 4 A general view of a Marks and Spencer M&S Foodhall supermarket Credit: Getty 4 M&S in London, England Credit: Getty Available in M&S cafés nationwide, the new menu includes a variety of breakfast, lunch, and dessert options. For those who like to start their day with something substantial, the Pesto Eggs, Halloumi & Asparagus (£9.95) is a hearty choice. If you're stopping by for lunch, the Hot & Crunchy Sandwiches (£7.50) offer a more casual but equally delicious option. The sandwiches, available in two flavours – Pesto Chicken and Spicy Tuna – are lightly toasted, crispy, and served with smashed avocado and rocket. For dessert, M&S has added some exciting new sweet treats to their café menu. Among the standouts is the Mini Bite Showstopper Cake (£5.50), which features layers of rich chocolate sponge and buttercream, topped with crunchy cornflakes and double chocolate mini bites. This cake is certainly one of the standout new offerings. But for those who remember the famous Matilda cake from the beloved movie, M&S has crafted a similar version that captures all the delicious indulgence of the iconic treat. Fans of classic treats will enjoy the Ultimate Cookie Sandwich (£2.50), where two soft butter cookies are filled with creamy Belgian chocolate ganache. In addition to the cakes, the café's drink menu has also received a summer makeover. The previously popular Iced Matcha has been replaced with the Iced Wild Strawberry Matcha, which combines the smoothness of matcha with the fruity taste of wild strawberries. This new drink promises to be a refreshing choice for the warmer months. For those with a serious sweet tooth, the Eton Mess Milkshake (£4.25) is a must-try. A twist on the classic British dessert, the milkshake is made with strawberry and raspberry flavours, topped with whipped cream, freeze-dried raspberries, and mini meringues. The full summer menu is available at M&S cafés across the UK, offering plenty of choice for every taste.

Oil prices jump after Israel's attack on Iran and it could lead to higher gas costs
Oil prices jump after Israel's attack on Iran and it could lead to higher gas costs

The Independent

time11 hours ago

  • The Independent

Oil prices jump after Israel's attack on Iran and it could lead to higher gas costs

Oil prices have jumped following Israel's attack on Iran as experts warn the conflict could lead to higher gas costs. The price of a barrel of benchmark U.S. crude jumped 6.8 percent to $72.65 Friday. Brent crude, the international standard, rose 7.1 percent to $74.30 a barrel. '#GasPrices will likely start to rise across much of the country later this evening in response to Israel's attacks on Iran, which have caused oil prices to surge. For now, I expect the rise to be noticable, but limited. Approx 10-25c/gal thus far, but this could change,' industry expert Patrick De Haan wrote on X. Iran is one of the world's major producers of oil and if a wider war escalates, it could slow the flow of Iranian oil to U.S. customers and elsewhere. 'Iran knows full well that Trump i s focused on lower energy prices and actions by Iran that impact Middle East supply and consequently raise oil prices damage Trump politically,' Andy Lipow, president of Lipow Oil Associates consulting firm, told CNN. Past attacks involving Iran and Israel have seen prices for oil spike initially, only to fall later 'once it became clear that the situation was not escalating and there was no impact on oil supply,' said Richard Joswick, head of near-term oil at S&P Global Commodity Insights. The Secretary of the Organization of the Petroleum Exporting Countries warned industry executives not to 'raise false alarms.' 'There are currently no developments in supply or market dynamics that warrant unnecessary measures,' the organization said on X. Israel said 200 fighter jets took part in strikes on more than 100 targets in Iran overnight in an escalation that threatens to spark a wider conflict in the Middle East. Israel said Iran has launched more than 100 drones towards Israel in response - but Tehran has denied these reports, according to Iranian media. Trump firmly put the U.S. in Israel's corner after the attacks. The president said he'd given Tehran 'chance after chance to make a deal' that would have headed off the strikes by putting restrictions on the country's nuclear weapons program and complained that Iranian negotiators had never been able to come to an agreement. 'I gave Iran chance after chance to make a deal. I told them, in the strongest of words, to 'just do it,' but no matter how hard they tried, no matter how close they got, they just couldn't get it done,' he wrote on Truth Social. Trump also said he'd warned Iran that Israel 'has a lot' of American-made military hardware — 'the best and most lethal' — and is quite proficient in using it. 'Certain Iranian hardliner's spoke bravely, but they didn't know what was about to happen. They are all DEAD now, and it will only get worse!' he added. 'Iran must make a deal, before there is nothing left. No more death, no more destruction, JUST DO IT, BEFORE IT IS TOO LATE,' the president wrote.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store