Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 004
Incident Reports

Inside the M&S Ransomware Attack: How One Phone Call Cost £300 Million

The breach that shut down Marks & Spencer's online ordering for 46 days did not start with a software vulnerability. It started with someone calling a help desk and asking nicely.

In April 2025, Marks & Spencer — a company with over 1,400 stores and 64,000 employees — was reduced to tracking fresh food and clothing stock with pen and paper. The retailer's chairman later confirmed the entry point in testimony to the UK Parliament: attackers impersonated an M&S employee in a phone call to the company's IT help desk, run by a third-party contractor, and talked the operator into resetting a privileged account's multi-factor authentication.

That single social-engineering call was the entire technical breakthrough the attackers needed. With the reset credential, they gained access to Active Directory and exfiltrated the NTDS.dit file — the database that stores password hashes for every domain user in the organisation. Cracked offline, those hashes handed the attackers a working set of credentials across the M&S network. From there they deployed DragonForce ransomware, encrypting the virtualisation infrastructure that controlled online ordering, warehouse automation, and stock management.

The entire technical breakthrough the attackers needed was one phone call and an operator willing to be helpful under pressure.

The financial toll was severe by any measure: a 46-day suspension of online ordering, roughly £300 million wiped from annual profit, and over £500 million lost from the company's market capitalisation in the days after the attack became public. The UK's Cyber Monitoring Centre classified the incident, alongside a closely related attack on the Co-op, as a Category 2 systemic cyber event — the first time UK retail had been placed at that classification level.

The attribution that emerged — a decentralised group tracked as Scattered Spider, working with the DragonForce ransomware platform — points to a specific and increasingly common failure mode. This was not a sophisticated exploit against a firewall or an unpatched server. It was a fluent, confident phone call exploiting a help desk process designed to be helpful. Four people were later arrested in connection with the M&S, Co-op, and Harrods attacks, but the technical lesson for every organisation with an IT help desk is more durable than any single arrest: identity verification procedures are only as strong as the operator's willingness to follow them under social pressure, and that is a training and process problem, not a technology purchase.

← OlderThe Co-op and Harrods Attacks: Why Regulators Called This 'One Combined Cyber Event'