案例库 · 工程与运营 · 技术决策 · 2025
这条还没译成中文,下面是英文原文。
M&S let a contractor's help desk reset any password by phone — hackers just asked
Scattered Spider impersonated an M&S employee to a Tata help desk, got a password reset, and the ransomware that followed cost M&S roughly £300 million.
Marks & Spencer · Tata Consultancy Services · 2025-04
怎么回事
Around Easter weekend 2025, the hacking group Scattered Spider breached Marks & Spencer not through a technical exploit but by calling the IT help desk M&S had outsourced to Tata Consultancy Services and impersonating an M&S employee. The help desk carried out a password reset for the caller. Reuters later reported that logins belonging to at least two TCS employees were used in the intrusion. M&S chairman Archie Norman described it to UK lawmakers as a 'sophisticated impersonation' operation 'involving a third party' — naming the method without naming the weak point.
Once inside, the attackers deployed DragonForce ransomware. M&S switched off its automated stock and inventory systems rather than risk them spreading the attack further, so staff fell back to manual, pen-and-paper processes to move fresh food, drinks and clothing through stores and warehouses. Online clothing and home ordering was suspended for weeks; food and beauty online sales were disrupted longer. A month after the attack, M&S's online clothing service was still offline.
M&S put the cost at roughly £300 million (about $400 million) in lost operating profit across 2025 and 2026, which it hoped to roughly halve through insurance and cost management. The Cyber Monitoring Centre later assessed the combined damage from the M&S attack and a related one at the Co-op — same threat actor, similar timeline, similar techniques — at £270–440 million across the two retailers. M&S's market value fell by more than £1 billion.
Six months after the attack, M&S ended its help-desk services contract with TCS. Both companies stated the decision predated the breach and was not a response to it, but the timing left the outsourced help desk — the actual entry point — as the visible casualty of a breach whose root cause was a process, not a system.
为什么会这样
- The help desk M&S outsourced to Tata Consultancy Services could reset an employee's credentials on the strength of a phone call, with no verification step that impersonation couldn't defeat.
- At least two genuine TCS employee logins were used in the intrusion — attackers reached systems through credentials the help desk itself controlled, not a technical vulnerability.
- M&S had automated its stock and inventory systems tightly enough that shutting them down to contain the ransomware also meant it had no manual process ready to run the business without them.
- Outsourcing the help desk moved a high-privilege function — the ability to reset any employee's access — outside M&S's direct security culture and oversight.
教训
A help desk that can reset anyone's password on a phone call is a single point of failure no firewall protects — this attack started with a conversation, not a technical exploit.
后来呢
M&S restored online clothing and home ordering over following weeks and food/beauty operations progressively through mid-2025, with disruption's tail into July 2025. It ended its help-desk contract with TCS about six months later. The Cyber Monitoring Centre classified the M&S and Co-op incidents as a single 'Category 2 systemic event' given the shared attacker, timing and methods, and the help-desk social-engineering approach was flagged as a template used against other large organizations, including in US insurance.
资料来源
- Al Jazeera — UK retailer M&S puts cyberattack cost at $400m as disruptions continue
- The Hacker News — Scattered Spider behind cyberattacks on M&S and Co-op, causing up to $592M in damages
- Yahoo Finance (Reuters) — M&S ousts Indian outsourcer accused of £300m cyberattack failures
发现哪里写错了?告诉我们。
类似的案例
这家公司栽倒的地方,别处有人漂亮地解开过。 第二意见 →

Comments · 0
登录 后就能评论。