Data leak β›“ Supply Chain

Marks & Spencer Tata Consultancy Services Breach

πŸ“… 2025-04-22 🏒 Tata Consultancy Services (IT outsourcing vendor) 🦠 DragonForce ransomware
Primary Source β†—

Incident Details

Beginning around April 22, 2025, Scattered Spider (also tracked as UNC3944 and Octo Tempest) attacked Marks & Spencer, the UK’s largest clothing retailer, by socially engineering employees at TCS (Tata Consultancy Services), M&S’s IT outsourcing provider. Attackers obtained credentials and used NTLM hash relay attacks to access M&S’s internal Active Directory. DragonForce ransomware was deployed in late April 2025, causing widespread disruption to M&S’s online ordering, contactless payments, and supply chain systems. Online clothing orders were suspended for over three weeks. The breach affected customer data including names, email addresses, phone numbers, home addresses, and order history β€” though M&S stated payment data was not compromised. The attack caused an estimated Β£300M+ in lost sales and share price decline. Simultaneously part of the broader wave of Scattered Spider attacks on UK retailers in spring 2025.

Technical Details

Initial Attack Vector
Scattered Spider (UNC3944) conducted a social engineering / vishing attack targeting Tata Consultancy Services (TCS) employees who had privileged access to M&S systems, gaining access to M&S Active Directory via NTLM hash relay and deploying DragonForce ransomware
Vendor / Product
Tata Consultancy Services (IT outsourcing vendor)
Malware Family
DragonForce ransomware
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-04-22 Breach occurred
  2. 2025-04-22 Publicly disclosed
  3. 2025-05-13 Customers notified