Marks & Spencer Ransomware (Apr 2025): Scattered Spider Returns to the Help Desk
Facts in this article were checked against the sources listed below as of Oct 5, 2026.
Retrospective: this article looks back at events from April 2025, written in 2026 with the benefit of hindsight.
Over the Easter weekend in April 2025, UK retailer Marks & Spencer began experiencing problems with contactless payments and Click & Collect. Within days, it paused online clothing and home orders — a channel worth more than £3 million in sales a day. Store shelves developed gaps as systems were taken offline. Customer personal data, which could include names, email addresses, postal addresses and dates of birth, was taken.
- Third-party footholdAttackers gain entry through "human error" at a third party, according to M&S.
- Identity abuseReporting links the attack to Scattered Spider, known for social engineering service desks and abusing identity systems.
- Disruption beginsAround April 21, 2025: problems with contactless payments and Click & Collect appear over the Easter period.
- Online orders pausedM&S pauses online clothing and home orders for weeks; customer personal data is taken.
- Financial impactM&S says the attack will hit operating profit by about £300 million, with disruption into July.
M&S later said the attack would hit operating profit by about £300 million, with disruption expected to last into July. The company said attackers had entered through "human error" at a third party. The attack was widely attributed to Scattered Spider, the group linked to the 2023 attacks on MGM Resorts and Caesars. Other UK retailers, including Co-op, reported attacks around the same time.
The pattern
Scattered Spider's playbook is well documented: research employees, impersonate them to a service desk, persuade staff to reset passwords or MFA, then use control of identity systems to spread and deploy ransomware. In the MGM case, reporting described a short phone call to the IT help desk. At M&S, the company pointed to a third party.
Many large organizations outsource service desk and IT support. That means the people who reset passwords and MFA may work for another company — under different training, different pressures and sometimes different procedures.
Why it mattered
The same technique worked again. Two years after MGM, a major retailer suffered a similar outcome through a similar entry point.
Retail has little tolerance for downtime. E-commerce, warehouses, stores and suppliers are tightly connected. When systems go offline, sales stop immediately.
Outsourcing moves the risk, not the responsibility. Customers and regulators held M&S accountable regardless of where the error occurred.
What to do now
- Strengthen self-service password reset. In Entra ID, require two methods to reset, remove weak methods such as security questions and, where possible, SMS, and notify users and administrators when passwords change.
- Protect MFA registration with Conditional Access. Create a policy for the user action Register security information that requires a compliant device, a trusted location or a Temporary Access Pass. Then an attacker with only a password can't register their own MFA method from anywhere.
- Use Temporary Access Pass for recovery. Help desk staff should issue a time-limited pass after strong verification rather than deleting all of a user's MFA methods.
- Restrict who can reset whom. Help desk roles shouldn't be able to reset administrators or executives; use restricted management administrative units, and require security approval for privileged resets.
- Strengthen verification. Replace personal-detail questions with callbacks to numbers on file, video verification, manager confirmation or Microsoft Entra Verified ID with face check.
- Hold third parties to your standard. Put verification procedures in contracts, audit them and test outsourced service desks with simulated social engineering.
- Protect Active Directory and virtualization management. Treat domain controllers, identity sync servers and hypervisor management as Tier 0 assets with separate administration.
- Plan continuity for revenue systems. Decide in advance how stores, fulfillment and customer service will operate if core systems are offline for weeks.
How to detect the pattern
- MFA registration from unusual places. "User registered security info" from an IP address, country or device not associated with the user, especially soon after a reset.
- Reset followed by risky sign-in. A password or MFA reset followed within hours by a sign-in rated medium or high risk, or from a new location.
- Privilege use after reset. Role activations, Conditional Access changes or access to identity infrastructure by recently reset accounts.
- Resets of privileged accounts by help desk staff, which should be rare and should alert immediately.
- Reset activity without matching tickets in your service management system.
Common mistakes
- Assuming the outsourced provider follows your rules without checking.
- Allowing MFA registration from any device and location.
- Letting the help desk reset administrators with the same process as regular users.
- No business continuity plan for e-commerce and logistics.
Questions to ask your outsourced service desk
If a third party resets passwords or MFA for your organization, ask:
- What exact verification steps do agents follow before resetting a password or MFA method?
- Are those steps different — and stronger — for administrators and executives?
- Can agents reset accounts with privileged roles at all? If so, who approves it?
- How do you train agents to resist pressure, urgency and impersonation?
- Do you record calls, and can we review them after an incident?
- How quickly will you notify us of a suspicious request or a confirmed mistake?
- When did you last run a social engineering test, and what did it find?
Write the answers into your contract and schedule regular tests.
The cost of downtime
M&S's own figures show why prevention and recovery planning are business decisions. Online clothing and home orders account for more than £3 million in sales a day, and the company expected disruption to last into July. Against numbers like that, investment in help desk verification, identity protection and continuity planning is small.
Questions for leadership
- How does every help desk we use — internal and outsourced — verify a caller before resetting access?
- Could an attacker with one employee's password register their own MFA device?
- How long could we keep selling if core systems were offline for a month?
Key takeaways
- M&S expected about £300 million in lost operating profit after an attack that began with human error at a third party.
- The pattern matches earlier Scattered Spider attacks: social engineering, identity takeover, ransomware.
- Protect MFA registration, use Temporary Access Pass and restrict privileged resets.
- Require outsourced providers to meet — and prove — your verification standards.
Sources
- How to Lock Down Entra ID Password Reset and MFA Re-Registration How-To & Hardening
- Detecting Help Desk MFA Reset Abuse: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Retail Lessons From a £300 Million Cyber Attack CIO Briefings