Entra ID & IdentityIncident TeardownsRetrospectives

Marks & Spencer Ransomware (Apr 2025): Scattered Spider Returns to the Help Desk

By OnCloudSec Research Team · Published Oct 6, 2026 · 5 min read

Facts in this article were checked against the sources listed below as of Oct 5, 2026.

Retrospective: this article looks back at events from April 2025, written in 2026 with the benefit of hindsight.

Over the Easter weekend in April 2025, UK retailer Marks & Spencer began experiencing problems with contactless payments and Click & Collect. Within days, it paused online clothing and home orders — a channel worth more than £3 million in sales a day. Store shelves developed gaps as systems were taken offline. Customer personal data, which could include names, email addresses, postal addresses and dates of birth, was taken.

How it unfolded
  1. Third-party footholdAttackers gain entry through "human error" at a third party, according to M&S.
  2. Identity abuseReporting links the attack to Scattered Spider, known for social engineering service desks and abusing identity systems.
  3. Disruption beginsAround April 21, 2025: problems with contactless payments and Click & Collect appear over the Easter period.
  4. Online orders pausedM&S pauses online clothing and home orders for weeks; customer personal data is taken.
  5. Financial impactM&S says the attack will hit operating profit by about £300 million, with disruption into July.

M&S later said the attack would hit operating profit by about £300 million, with disruption expected to last into July. The company said attackers had entered through "human error" at a third party. The attack was widely attributed to Scattered Spider, the group linked to the 2023 attacks on MGM Resorts and Caesars. Other UK retailers, including Co-op, reported attacks around the same time.

The pattern

Scattered Spider's playbook is well documented: research employees, impersonate them to a service desk, persuade staff to reset passwords or MFA, then use control of identity systems to spread and deploy ransomware. In the MGM case, reporting described a short phone call to the IT help desk. At M&S, the company pointed to a third party.

Many large organizations outsource service desk and IT support. That means the people who reset passwords and MFA may work for another company — under different training, different pressures and sometimes different procedures.

Why it mattered

The same technique worked again. Two years after MGM, a major retailer suffered a similar outcome through a similar entry point.

Retail has little tolerance for downtime. E-commerce, warehouses, stores and suppliers are tightly connected. When systems go offline, sales stop immediately.

Outsourcing moves the risk, not the responsibility. Customers and regulators held M&S accountable regardless of where the error occurred.

What to do now

  1. Strengthen self-service password reset. In Entra ID, require two methods to reset, remove weak methods such as security questions and, where possible, SMS, and notify users and administrators when passwords change.
  2. Protect MFA registration with Conditional Access. Create a policy for the user action Register security information that requires a compliant device, a trusted location or a Temporary Access Pass. Then an attacker with only a password can't register their own MFA method from anywhere.
  3. Use Temporary Access Pass for recovery. Help desk staff should issue a time-limited pass after strong verification rather than deleting all of a user's MFA methods.
  4. Restrict who can reset whom. Help desk roles shouldn't be able to reset administrators or executives; use restricted management administrative units, and require security approval for privileged resets.
  5. Strengthen verification. Replace personal-detail questions with callbacks to numbers on file, video verification, manager confirmation or Microsoft Entra Verified ID with face check.
  6. Hold third parties to your standard. Put verification procedures in contracts, audit them and test outsourced service desks with simulated social engineering.
  7. Protect Active Directory and virtualization management. Treat domain controllers, identity sync servers and hypervisor management as Tier 0 assets with separate administration.
  8. Plan continuity for revenue systems. Decide in advance how stores, fulfillment and customer service will operate if core systems are offline for weeks.

How to detect the pattern

  • MFA registration from unusual places. "User registered security info" from an IP address, country or device not associated with the user, especially soon after a reset.
  • Reset followed by risky sign-in. A password or MFA reset followed within hours by a sign-in rated medium or high risk, or from a new location.
  • Privilege use after reset. Role activations, Conditional Access changes or access to identity infrastructure by recently reset accounts.
  • Resets of privileged accounts by help desk staff, which should be rare and should alert immediately.
  • Reset activity without matching tickets in your service management system.

Common mistakes

  • Assuming the outsourced provider follows your rules without checking.
  • Allowing MFA registration from any device and location.
  • Letting the help desk reset administrators with the same process as regular users.
  • No business continuity plan for e-commerce and logistics.

Questions to ask your outsourced service desk

If a third party resets passwords or MFA for your organization, ask:

  • What exact verification steps do agents follow before resetting a password or MFA method?
  • Are those steps different — and stronger — for administrators and executives?
  • Can agents reset accounts with privileged roles at all? If so, who approves it?
  • How do you train agents to resist pressure, urgency and impersonation?
  • Do you record calls, and can we review them after an incident?
  • How quickly will you notify us of a suspicious request or a confirmed mistake?
  • When did you last run a social engineering test, and what did it find?

Write the answers into your contract and schedule regular tests.

The cost of downtime

M&S's own figures show why prevention and recovery planning are business decisions. Online clothing and home orders account for more than £3 million in sales a day, and the company expected disruption to last into July. Against numbers like that, investment in help desk verification, identity protection and continuity planning is small.

Questions for leadership

  • How does every help desk we use — internal and outsourced — verify a caller before resetting access?
  • Could an attacker with one employee's password register their own MFA device?
  • How long could we keep selling if core systems were offline for a month?

Key takeaways

  • M&S expected about £300 million in lost operating profit after an attack that began with human error at a third party.
  • The pattern matches earlier Scattered Spider attacks: social engineering, identity takeover, ransomware.
  • Protect MFA registration, use Temporary Access Pass and restrict privileged resets.
  • Require outsourced providers to meet — and prove — your verification standards.

Sources

  1. The Record: M&S says cyberattack will hit profits by £300 million, disruption to last until July
  2. SupplyChainBrain: Marks & Spencer expects cyberattack to cost £300 million
marks and spencer cyber attackM&S / Scattered Spider2025

More on this story