Marks and Spencer halted online orders after DragonForce ransomware attack

Organization
Marks & Spencer
Exploit
Ransomware
Industry
Retail

Marks and Spencer confirmed on 22 April 2025 that it had been managing a cyber incident for several days, following complaints from customers on social media about disrupted services. On 25 April the retailer suspended all orders placed through its website and apps, leaving customers able to browse products but not buy them.

Reporting identified the incident as a ransomware attack. Both the DragonForce ransomware operation and the Scattered Spider cybercrime collective were linked to it by security researchers, and Google's threat intelligence unit warned in May that the actors behind the UK retail attacks had begun targeting US retailers. M&S did not name an attacker at the time.

Stores stayed open, but food availability suffered and the company incurred extra waste and logistics costs as staff fell back on manual processes. M&S shares fell close to 5 percent on the day online sales were paused. In May the retailer told investors the incident would cut annual operating profit by roughly 300 million pounds before insurance and mitigation, and that online disruption would run through June and into July.

M&S later confirmed that customer personal data had been taken, including contact details, dates of birth and online order histories. It said payment card data was masked and unusable and that passwords were not exposed, but required customers to reset their passwords. Online ordering restarted in a limited form on 10 June 2025, about six weeks after it was suspended.

Sources