GoFirm
Back to Blog
Case Studies·3 min read

The Marks & Spencer Attack and the Help Desk That Opened the Door

By GoFirm

In February 2025, attackers quietly entered Marks & Spencer's network. Nobody noticed for two months.

The initial access came through social engineering. Scattered Spider - the same group responsible for the MGM Resorts attack in 2023 - contacted the M&S service desk, which was operated by a third-party provider, impersonated an employee, and had credentials reset on their behalf. With those credentials, the attackers obtained the NTDS.dit file - the Windows Active Directory database containing password hashes for every user on the corporate network. They cracked those hashes offline, giving them valid credentials for a wide range of accounts. They then spent weeks moving through M&S's infrastructure undetected.

On 24 April 2025, they deployed DragonForce ransomware across M&S's VMware ESXi hosts. Virtual machines running inventory, point-of-sale, supply chain and ordering systems were encrypted simultaneously. Online orders were suspended. Contactless payments failed across over 1,000 stores. Warehouse operations halted, with around 200 staff furloughed. The online store remained down for 46 days.

M&S quantified the damage at roughly £300 million in lost profit, with £3.8 million lost every day the online store was offline. The company's market value dropped by over £500 million in the immediate aftermath.

The Cyber Monitoring Centre assessed the combined M&S and Co-op attacks - which used the same tactics and were attributed to the same threat actor - as a single Category 2 systemic event with a total financial impact of between £270 million and £440 million.

This is the same attack as MGM. Same group. Same method. Same result. The only things that changed were the location, the sector, and the scale of the disruption to daily life. In both cases, the attack began with a social engineering call to an outsourced help desk, and in both cases that call produced a credential reset that no confirmed human authority had sanctioned.

GoFirm addresses this at two points. The credential reset itself - an administrative action on a privileged account - is a configurable gate. Before a help desk operative resets credentials for a high-privilege account, the named authority receives a confirmation request on their registered device. They confirm or the reset does not proceed. And at the infrastructure layer, GoFirm Deep Guard gates the privilege escalation that follows - the access to Active Directory, the NTDS.dit exfiltration, the ESXi host access. Each of those actions requires confirmed human authority before execution.

A social engineering call to an outsourced help desk, however convincing, cannot produce that confirmation. The two months of undetected access that preceded the ransomware deployment would have been stopped at the first privileged action.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. Specops Software, M&S Ransomware Attack: Service Desk and Active Directory Security Lessons, 2025

2. BlackFog, Marks & Spencer Breach: How a Ransomware Attack Crippled a UK Retail Giant, October 2025

3. BlackFog, ibid.

4. The Hacker News, Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages, June 2025

Share this article