Data leak
β Supply Chain
Marks & Spencer Tata Consultancy Services Breach
Primary Source βIncident Details
Beginning around April 22, 2025, Scattered Spider (also tracked as UNC3944 and Octo Tempest) attacked Marks & Spencer, the UK’s largest clothing retailer, by socially engineering employees at TCS (Tata Consultancy Services), M&S’s IT outsourcing provider. Attackers obtained credentials and used NTLM hash relay attacks to access M&S’s internal Active Directory. DragonForce ransomware was deployed in late April 2025, causing widespread disruption to M&S’s online ordering, contactless payments, and supply chain systems. Online clothing orders were suspended for over three weeks. The breach affected customer data including names, email addresses, phone numbers, home addresses, and order history β though M&S stated payment data was not compromised. The attack caused an estimated Β£300M+ in lost sales and share price decline. Simultaneously part of the broader wave of Scattered Spider attacks on UK retailers in spring 2025.
Technical Details
- Initial Attack Vector
- Scattered Spider (UNC3944) conducted a social engineering / vishing attack targeting Tata Consultancy Services (TCS) employees who had privileged access to M&S systems, gaining access to M&S Active Directory via NTLM hash relay and deploying DragonForce ransomware
- Vendor / Product
- Tata Consultancy Services (IT outsourcing vendor)
- Malware Family
- DragonForce ransomware
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-04-22 Breach occurred
- 2025-04-22 Publicly disclosed
- 2025-05-13 Customers notified