In April 2025, Marks & Spencer — a company with over 1,400 stores and 64,000 employees — was reduced to tracking fresh food and clothing stock with pen and paper. The retailer's chairman later confirmed the entry point in testimony to the UK Parliament: attackers impersonated an M&S employee in a phone call to the company's IT help desk, run by a third-party contractor, and talked the operator into resetting a privileged account's multi-factor authentication.
That single social-engineering call was the entire technical breakthrough the attackers needed. With the reset credential, they gained access to Active Directory and exfiltrated the NTDS.dit file — the database that stores password hashes for every domain user in the organisation. Cracked offline, those hashes handed the attackers a working set of credentials across the M&S network. From there they deployed DragonForce ransomware, encrypting the virtualisation infrastructure that controlled online ordering, warehouse automation, and stock management.
The financial toll was severe by any measure: a 46-day suspension of online ordering, roughly £300 million wiped from annual profit, and over £500 million lost from the company's market capitalisation in the days after the attack became public. The UK's Cyber Monitoring Centre classified the incident, alongside a closely related attack on the Co-op, as a Category 2 systemic cyber event — the first time UK retail had been placed at that classification level.
The attribution that emerged — a decentralised group tracked as Scattered Spider, working with the DragonForce ransomware platform — points to a specific and increasingly common failure mode. This was not a sophisticated exploit against a firewall or an unpatched server. It was a fluent, confident phone call exploiting a help desk process designed to be helpful. Four people were later arrested in connection with the M&S, Co-op, and Harrods attacks, but the technical lesson for every organisation with an IT help desk is more durable than any single arrest: identity verification procedures are only as strong as the operator's willingness to follow them under social pressure, and that is a training and process problem, not a technology purchase.