Skip to main content
Back to overview
Medium

Marks & Spencer hit by ransomware via IT partner, data likely exposed

For the latest discoveries in cyber research for the week of 5th May, please download our Threat Intelligence Bulletin .

Key points

  • "Scattered Spider" group used social engineering on a helpdesk vendor.
  • Ransomware deployed across M&S systems, disrupting operations.
  • Likely customer data exposure.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
May 6, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

MarksandspencerData DisclosureMarksSpencerFor theThreat Intelligence BulletinThreeCo-opHarrods and MarksM&S

Quick context

Questions about this signal

What happened in this signal?

For the latest discoveries in cyber research for the week of 5th May, please download our Threat Intelligence Bulletin . Three major UK retailers – Co-op , Harrods and Marks & Spencer (M&S) – were hit by cyberattacks that disrupted operations and compromised sensitive data. The attacks are believed linked to the Scattered Spider gang, while DragonForce ransomware gang claimed responsibility for the attacks. The American non-profit healthcare system, Ascension, experienced a data breach following a third-party hacking incident in December 2024. The attack led to the theft of patients’ personal and health information, including names, addresses, Social Security numbers, and inpatient records. Although no threat actor has claimed responsibility, the timeline suggests a possible link to a series of Cl0p ransomware attacks that exploited a zero-day vulnerability in the Cleo secure file transfer software. Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.Win.Clop; Ransomware.Wins.Clop; Ransomware.Wins.Clop.ta.*) Hitachi Vantara, a subsidiary of Japanese Hitachi, has suffered a cyberattack that disrupted parts of its systems. The attack was claimed by Akira ransomware gang which allegedly stole files from the company’s network and left ransom notes on compromised machines. Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.Wins.Akira.ta.*; Ransomware.Wins.Akira; Ransomware.Win.Akira; Trojan.Win.Akira) Media firm Urban One was hit by a cyberattack that occurred in February, resulting in data leakage of 2.5TB of employees’ personal data such as names, addresses, Social Security numbers, direct deposit information and W-2 information. The attack was claimed by Cactus ransomware gang. Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.Win.Cactus; Ransomware.Wins.Cactus.ta.*) Several public and private organizations in the Netherlands have confirmed a series of DDoS attacks linked to the pro-Russian hacktivist group NoName057(16). These attacks caused access issues and service disruptions across key entities. While no data breaches or system compromises have been reported, the group appears to be responding to the Netherlands’ military support for Ukraine. Texas-based employee benefits administration company, VeriSource Services, has been a victim of a data breach that occurred in February 2024, impacting over four million people. The breach exposed sensitive data, including full names, addresses, dates of birth, gender, and Social Security numbers. Nova Scotia Power, along with its parent company Emera, suffered a cyberattack affecting their Canadian network and business servers. The incident disrupted customer service and online access for over 500,000 clients. Operations remained unaffected, however delays have increased. SonicWall reported active exploitation of two older vulnerabilities (CVE-2023-44221 and CVE-2024-38475) affecting its Secure Mobile Access (SMA) appliances. CVE-2023-44221 is a high-severity command injection flaw in the SMA100 SSL-VPN interface exploitable by admins, while CVE-2024-38475 affects Apache HTTP Server and allows unauthenticated remote code execution. Check Point IPS provides protection against this threat (SonicWall SMA Command Injection (CVE-2023-44221), Apache HTTP Server Remote Code Execution) Google’s 2024 0-days report highlighted 75 zero-day vulnerabilities exploited in the wild, with 33 targeting enterprise technologies. Enterprise-focused products – especially security and networking software – accounted for 44% of the total. Many of the exploits involved platforms such as WebKit, Firefox, revealing attackers’ focus on both widely used and specialized technologies. A set of 17 vulnerabilities, dubbed “Airborne”, was discovered in Apple’s AirPlay protocol and SDK. Two flaws (CVE-2025-24252 and CVE-2025-24132) enable wormable zero-click RCE attacks, allowing local network compromise of Apple and third-party devices. Apple issued patches for affected products, including iPhones, iPads, Macs, and Apple Vision Pro. Two misconfiguration-related vulnerabilities, CVE-2025-23242 and CVE-2025-23243, have been disclosed in NVIDIA Riva deployments. These flaws could allow unauthorized access and potential abuse of AI services like speech recognition and text-to-speech. Check Point Research released 2025 AI Security Report with an analysis detailing main AI-driven threats, including LLM poisoning, retrieval manipulation, and AI-powered malware. The report highlights AI powered social engineering and the complete loss of digital identities in the age of AI. It also covers Dark LLMs like WormGPT and how AI is used by cybercriminals to process stolen data. Researchers have uncovered Outlaw, a Perl-based cryptomining botnet targeting Linux systems by exploiting weak or default SSH credentials. The attackers deploy custom XMRig miners, terminate competing miners to conserve resources, and use an IRC-based client for DDoS attacks, file uploads, and backdoor access. The botnet primarily targets devices in the United States. Researchers have discovered a coordinated supply chain attack involving 21 backdoored Magento extensions from vendors Tigren, Meetanshi, and MGS, affecting 500–1,000 e-commerce stores. The PHP backdoor, injected as early as six years ago and activated on April 20, allows remote code execution leading to data theft, skimmer injection, and admin account creation. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign StealthLoader Malware Leveraging Log4Shell BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies. CloudWize Acquired By DoiT International

When was this signal reported?

Shadow Tier lists May 6, 2025 as the signal date.

Which organization is connected to this signal?

Marksandspencer is the organization connected to this public signal.

Explore Marksandspencer
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence