PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

One Month Later, Marks & Spencer Is Still Reeling from a Cyberattack

By Wesley Grant
May 20, 2025
in Cybersecurity, Fraud & Security, Merchant, News
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
marks & spencer

Abstract blur department store and shopping mall interior for background

For over 140 years, Marks & Spencer (M&S) has been a fixture of Britain’s retail landscape, but the department store has faced sharp losses and operational issues following a devastating cyberattack.

Shortly after the April ransomware incident, M&S halted online and in-app order—services the retailer has yet to restore. According to Reuters, Marks & Spencer hasn’t resumed its online operations out of an abundance of caution.

A group of hackers gained access to the store’s systems and threatened to shut down the company’s network if a ransom wasn’t paid. M&S refused to succumb to the threat actors’ demands and is now working to restore all its systems.

The attack is estimated to have cost Marks & Spencer $80 million, but the impacts could go beyond monetary losses. While M&S said it was surprised by customers’ willingness to shop in-store, store-sourced voices raised concerns that customers could eventually lose patience with the lack of digital options—potentially leading to reputational ramifications if the outage persists.

Aggressive, Creative, and Effective

The M&S attack was the handiwork of a loosely affiliated network of hackers known as Scattered Spider, which has carried out attacks around the globe. A smaller group within the network, called DragonForce, is behind the M&S hack as well as similar efforts against UK retailers Harrods and the Co-op.

Though British merchants have been the initial targets, Google recently warned that Scattered Spider could be just as likely to target their U.S. counterparts.

“US retailers should take note,” John Hultquist, Cybersecurity Analyst at Google, told The Independent. “These actors are aggressive, creative, and particularly effective at circumventing mature security programs.”

The Magnitude of These Attacks

Bad actors targeting large organizations is not a novel phenomenon, but the scale of damage is broadening. For example, crypto exchange Coinbase was recently hacked in an incident that could cost the company up to $400 million, after cybercriminals bribed Coinbase contractors to divulge protected customer data.

Similarly, the M&S breach derived from a contractor relationship. At least two logins used in the hack were linked to Tata Consulting Services, a company that provides IT and help desk services for the retailer.

The magnitude of these attacks will likely prompt many organizations to reevaluate their partnerships and reassess their security measures. However, as criminals become increasingly innovative, businesses will also need to find creative ways to defend themselves.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: CybercriminalsData BreachM&SMarks & SpencerRansomwareScattered Spider

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    fraud as a service

    Keeping Up with the Most Dangerous Fraud Trends of 2026

    December 8, 2025
    open banking

    Open Banking Has Begun to Intrude on Banks’ Customer Relationships

    December 5, 2025
    conversational payments

    Conversational Payments: The Next Big Shift in Financial Services  

    December 4, 2025
    embedded finance

    Inside the Embedded Finance Shift Transforming SMB Software

    December 3, 2025
    metal cards

    Metal Card Magnitude: How a Premium Touch Can Enthrall High-Value Customers

    December 2, 2025
    digital gift cards

    How Nonprofits Can Leverage Digital Gift Cards to Help Those in Need

    December 1, 2025
    stored-value prepaid

    How Stored-Value Accounts Are the Next Iteration of Prepaid Payments

    November 26, 2025
    google crypto wallet, crypto regulation

    Crypto Heads Into 2026 Awaiting Its ‘Rocketship Point’

    November 25, 2025

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result