UK retail giant Marks & Spencer was hit by a major ransomware attack in April 2025 by the Scattered Spider gang.
Attackers first compromised M&S's IT helpdesk through social engineering, then encrypted systems and exfiltrated customer data including names, birthdates, addresses, and purchase histories.
M&S was forced to halt online orders for 46 days, with Deutsche Bank estimating an immediate 30 million pound profit loss. The attack wiped roughly 750 million pounds off M&S's market value.