Back to the archive

The encyclopedia · Engineering & Operations · Technical decision · 2025

M&S let a contractor's help desk reset any password by phone — hackers just asked

Scattered Spider impersonated an M&S employee to a Tata help desk, got a password reset, and the ransomware that followed cost M&S roughly £300 million.

Marks & Spencer · Tata Consultancy Services · 2025-04

What happened

Around Easter weekend 2025, the hacking group Scattered Spider breached Marks & Spencer not through a technical exploit but by calling the IT help desk M&S had outsourced to Tata Consultancy Services and impersonating an M&S employee. The help desk carried out a password reset for the caller. Reuters later reported that logins belonging to at least two TCS employees were used in the intrusion. M&S chairman Archie Norman described it to UK lawmakers as a 'sophisticated impersonation' operation 'involving a third party' — naming the method without naming the weak point.

Once inside, the attackers deployed DragonForce ransomware. M&S switched off its automated stock and inventory systems rather than risk them spreading the attack further, so staff fell back to manual, pen-and-paper processes to move fresh food, drinks and clothing through stores and warehouses. Online clothing and home ordering was suspended for weeks; food and beauty online sales were disrupted longer. A month after the attack, M&S's online clothing service was still offline.

M&S put the cost at roughly £300 million (about $400 million) in lost operating profit across 2025 and 2026, which it hoped to roughly halve through insurance and cost management. The Cyber Monitoring Centre later assessed the combined damage from the M&S attack and a related one at the Co-op — same threat actor, similar timeline, similar techniques — at £270–440 million across the two retailers. M&S's market value fell by more than £1 billion.

Six months after the attack, M&S ended its help-desk services contract with TCS. Both companies stated the decision predated the breach and was not a response to it, but the timing left the outsourced help desk — the actual entry point — as the visible casualty of a breach whose root cause was a process, not a system.

Why it happened

  • The help desk M&S outsourced to Tata Consultancy Services could reset an employee's credentials on the strength of a phone call, with no verification step that impersonation couldn't defeat.
  • At least two genuine TCS employee logins were used in the intrusion — attackers reached systems through credentials the help desk itself controlled, not a technical vulnerability.
  • M&S had automated its stock and inventory systems tightly enough that shutting them down to contain the ransomware also meant it had no manual process ready to run the business without them.
  • Outsourcing the help desk moved a high-privilege function — the ability to reset any employee's access — outside M&S's direct security culture and oversight.
What it cost£300M (~$400M) lost profit, £1B+ market value dropcostly

The lesson

A help desk that can reset anyone's password on a phone call is a single point of failure no firewall protects — this attack started with a conversation, not a technical exploit.

Aftermath

M&S restored online clothing and home ordering over following weeks and food/beauty operations progressively through mid-2025, with disruption's tail into July 2025. It ended its help-desk contract with TCS about six months later. The Cyber Monitoring Centre classified the M&S and Co-op incidents as a single 'Category 2 systemic event' given the shared attacker, timing and methods, and the help-desk social-engineering approach was flagged as a template used against other large organizations, including in US insurance.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →