Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Marks and Spencer Cyberattack 2025: How Impersonating a…
Breach analysis Incident: 17 Apr 2025

Marks and Spencer Cyberattack 2025: How Impersonating a Third-Party User Cost £300 Million

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 8 min read
On this page

Over the Easter weekend of April 2025, Marks and Spencer (M&S) was hit by a ransomware attack that stopped online orders for weeks and, by the company's estimate, cut £300 million from its profit before recoveries. M&S chairman Archie Norman told MPs the attackers got in through "sophisticated impersonation" of one of the retailer's third-party users: they got into an account that belonged to a contractor, not an employee. The attack has been widely linked to the Scattered Spider collective and DragonForce ransomware, and in July 2025 the UK's National Crime Agency arrested four people. M&S is a human identity breach, but it shows how identity verification at the help desk and third-party access have become the front line.

Key takeaways

  • Attackers entered M&S systems on 17 April 2025 and were detected on 19 April. M&S disclosed the incident on 22 April and paused online and app orders on 25 April.
  • M&S described the entry as "sophisticated social engineering/impersonation of an individual combined with a third party vector". Norman told MPs it was impersonation of a third-party user.
  • Customer personal data was stolen, including names, dates of birth, contact details, household information and order histories. M&S said it did not include usable card details or account passwords.
  • M&S estimated a £300 million reduction in profit before recoveries, with online disruption costing about £10 million a week.
  • The fix is identity verification: strong checks before any password or MFA reset, especially for third-party and privileged users.

At a glance

OrganisationMarks and Spencer Group
WhenAccess on 17 April 2025; detected 19 April; disclosed 22 April 2025
AttackerWidely attributed to Scattered Spider using DragonForce ransomware; four people arrested by the NCA in July 2025
Entry pointSocial engineering and impersonation of a third-party user
Identities abusedA third-party (contractor) user account and the processes used to reset or grant its access
ImpactOnline orders paused from 25 April into June; customer personal data stolen; about £300 million profit impact before recoveries
CategoryHuman identity (not listed as an NHI or AI agent breach)

What happened

Customers first noticed problems with contactless payments and click and collect over the Easter weekend. M&S disclosed a cyber incident to the London Stock Exchange on 22 April 2025 and, on 25 April, paused online and app orders. In its evidence to the House of Commons Business and Trade Committee in July 2025, M&S said the attackers entered on 17 April and were detected on 19 April, when it convened a crisis team.

M&S described the attack as "highly sophisticated and targeted", involving "sophisticated social engineering/impersonation of an individual combined with a third party vector". Chairman Archie Norman told MPs the attackers used "sophisticated impersonation" of one of M&S's third-party users. Reporting has linked the third party to the contractor managing M&S's IT help desk; M&S's evidence refers to an email "apparently connected to a Tata Consultancy Services employee account".

On 13 May M&S confirmed that customer personal data had been taken, including names, dates of birth, contact details, household information and order histories. It said the data did not include usable payment or card details or account passwords. M&S declined to say whether it paid a ransom, citing law enforcement considerations. Online ordering restarted in June, with disruption continuing into July as systems were restored.

The attack came in the same wave as incidents at Co-op and Harrods. On 10 July 2025 the National Crime Agency arrested four people, aged 17 to 20, on suspicion of Computer Misuse Act offences, blackmail, money laundering and participating in the activities of an organised crime group.

Timeline

Date (2025)Event
17 AprilAttackers enter M&S systems (M&S evidence to Parliament).
19 AprilAttack detected; crisis team convened.
Easter weekendContactless payment and click and collect problems appear.
22 AprilM&S discloses the incident to the London Stock Exchange.
25 AprilOnline and app orders paused.
13 MayM&S confirms customer personal data was stolen.
MayM&S estimates a £300 million profit impact.
JuneOnline ordering restarts.
8 JulyArchie Norman gives evidence to the Business and Trade Committee.
10 JulyNCA arrests four people over the M&S, Co-op and Harrods attacks.

How it happened: the identity attack path

  1. Research the target. The attackers identified a third-party user with access to M&S systems and gathered enough information to impersonate them.
  2. Impersonate, not hack. Using social engineering, they obtained access to that user's account. Reporting links this to the outsourced help desk, the pattern known as help desk social engineering.
  3. Use legitimate access. Signed in as a trusted third-party user, the attackers operated with valid credentials rather than malware at first.
  4. Escalate and spread. From that foothold they moved through the environment far enough to steal customer data and deploy ransomware.
  5. Disrupt operations. The ransomware and the containment response forced M&S to stop online trading and fall back on manual workarounds in stores.

Impact

  • Trading: online and app orders paused from 25 April until June, with wider disruption into July.
  • Financial: about £300 million reduction in profit before recoveries, roughly £10 million a week while online sales were down.
  • Customers: personal data stolen, excluding usable card details and passwords according to M&S.
  • Law enforcement: four arrests by the NCA in July 2025.

What this means for identity security

M&S is on our list because it shows where identity attacks now land: at the people and processes that grant access, rather than at the technology that checks it. MFA and strong passwords did not stop the attackers, because they persuaded someone to hand over or reset access. Archie Norman's summary, "the perimeter is permeable", reflects that shift.

The third-party angle matters too. Outsourced help desks and contractors hold access and reset rights on behalf of many organisations, and their verification processes become part of the customer's attack surface. The same is true of machine access: integrations and service accounts run by suppliers extend trust in ways that are easy to lose track of, as the Salesloft Drift OAuth token breach showed. And once inside with valid credentials, attackers look for secrets and service accounts to go further, which is why credential hygiene inside the network still matters.

The same group of attackers is linked to earlier incidents on our timeline, including the Co-op DragonForce breach, the MGM Resorts breach and the Caesars Entertainment breach. Social engineering of support staff features in several of these incidents.

Recommendations

  • Verify identity before any reset. Require strong verification, such as a call-back to a known number, manager approval or in-person or video checks, before resetting passwords or MFA, especially for privileged and third-party users. See our Workforce Identity Security Guide.
  • Hold suppliers to the same standard. Contract for, and test, the identity verification processes of outsourced help desks.
  • Use phishing-resistant MFA so that a reset alone does not hand over a working session.
  • Limit third-party access. Give contractors time-bound, least-privilege access and review it regularly, as described in our Privileged Access Management Guide.
  • Alert on risky resets. A reset followed quickly by new-device sign-in and privileged activity should trigger an immediate check.
  • Remove secrets attackers can reuse inside. Plaintext credentials and over-privileged service accounts help attackers move from one account to the whole estate. Our guide to the secret sprawl challenge covers this.

Frequently asked questions

How did hackers get into Marks and Spencer?

According to M&S, through sophisticated social engineering and impersonation of a third-party user, which gave the attackers access to an account belonging to a contractor rather than an employee.

How much did the M&S cyberattack cost?

M&S estimated a £300 million reduction in profit before recoveries, including about £10 million a week of lost profit while online orders were paused.

Is the M&S cyberattack a non-human identity breach?

No. The entry point was a human third-party user account obtained through social engineering. We include it because it shows how access processes and third-party trust have become the main identity battleground.

Co-op DragonForce breach · MGM Resorts breach 2023 · Human vs Non-Human Identity · IAM and IGA Basics

How NHI Mgmt Group can help

Attackers target whichever identity is easiest to take over, human or machine. Our NHI Foundation Level Training Course helps teams extend identity controls to service accounts, API keys, tokens and AI agents, so that one compromised account cannot unlock the rest.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org