Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

British Retail Giant Marks & Spencer (M&S) and the Iconic Knightsbridge Department Store, Harrods, have become the latest to be hit by cyberattacks in the UK.
Online orders at M&S, one of the United Kingdom’s most prominent high-street stores, remain pause and the attack has already cost the company millions of pounds in Lost Revenues.
Here is what we know about the incident, its effect and where things stand.
M & S’s Online Services have not fully resumed. Customers can browse online but they cannot complete purchases. Some difficulties also Continue in Stores, with Gift Cards not currently being accepted.
The company has not provided a timeline for recovery.
Although m & s has not confirmed the type of cyberattack it suffered, experts say the company’s shutdown of Systems points to a likely ransomware incident.
Ransomware is a type of malicious software which blocks access to files or systems until a ransom has been paid – usually in cryptocurrency. This sort of software can shut down operations and hold critical data hostage.
Harrods has not shared details about its cyberattack, but experts believe the incidents may be connected.
Both the Metropolitan Police and the National Cyber Security Center (NCSC) are investigating the cyber attacks. The NCSC has urged all retailers to tights their cybersecurity and advised consumers to check bank activity and update passwords.

The attack on M&S has been linked by cybersecurity observers to a group called scattered spider, which is also known as Octo Tempest.
This is a loose network of mostly Young, English-speaking hackers who use tricks like phishing (messages through which criminals trick recipients into handing over sensitive information such as login details), Sim SWArel (Taking Control of Someone’s Phone Number) and Multi-Factor Authentication Fatigue (Mission Repeated Login Requests Until someone accidentally approves one) to break into company Systems.
Scattered Spider is believed to have accessed M&S Systems using Ransomware called Dragonforce.
One of the most common ways ransomware infiltrates a system is through phishing emails, according to cybersecurity firm akamai. Common to all the methods is “The Aim of Exploiting Either a Human Error or A Technical Vulnerability”, its website Explains.
Once inside, the malware spreads and encrypts important files, locking them so the company can not access or use them. The hackers then demand a ransom in exchange for a key to unlock the data.
Tim Mitchell, A Senior Security Researcher at SecureWorks, Told the UK’s Guardian Newspaper that scattered spider is an unusual hacking group because most cybercriminal networks tends to operate out of countries like russia, where loser enforcement provides a more “permissive Environment ”for Cybercrime.
The world cybercrime index ranks russia as the country position the highest cybercrime threat, followed by Ukraine, China, the United States, Nigeria and Romania.
Since the attack, more than 700 Million Pounds ($ 930m) has been wiped off Marks & Spencer’s Market Value, with its share price falling 6.5 percent – including a 2.2 percent drop on the first day of disruptions alone.
Online shopping, which makes up about one-Third of M & S’s Clothing and Home Sales, Generates Roughly 3.8 Million Pounds ($ 5.05m) in Daily Revenue-A Stream Now Halted Due to the Ongoing Shutdown.
The company has also paused recruitment, removing nearly 200 job listings from its website.
Harrods, Meanwhile, has not disclosed any financial losses. As a private hero company, it does not have a stock price and typically does not make its financial information public.
M&S initially responded promptly to the cyberattack, Informing Customers of the Breach and Pausing Affected Services Early on. However, communication has since stalled, with only two official statements released – the last on April 25.
The retailer confirmed it took systems offline “as a precaution”, affecting both in-store stock and logistics.
Harrods, Meanwhile, has not disclosed any financial losses. A Spokesperson Said Harrods is “working closely with leading cybersecurity experts and law enforcement to investigate the incident and enzure the integrity of our systems”.
Yes. M&S and Harrods are the latest in the uk to be affected by cyberattacks.
Co-operative group (co-on), a British consumer Cooperative that operates food stores, Funeral Services and other businesses, also faced an attempted breach the same week. It Shut Down Parts of Its It System, Affecting Back-Office and Call Center Functions. Stores remained open.
Synnovis, a partner of the UK’s National Health Service, was hit by a ransomware attack in June 2024, delaying more than 11,000 medical appointments while patient data it relied on was locked. The Russian-Linked Cybercriminal Group, Qilin, demanded $ 50m to restore access, but synnovis refused to pay, adhering to the uk government’s policy against paying cybercriminals. In response, the group posted the stolen data online including names, dates of birth, NHS numbers and details of blood test results.
According to the UK Government’s Cyber Security Breaches Survey, 74 percent of large businesses were targeted in cyberattacks in 2024. The Information Commissioner’s office also recorded a 40 percent rise in data breaches in the retail sector in 2023 Alone.