Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » How hackers ‘tricked’ IT department of one of the biggest UK retailers to disable its entire online operations, ET CISO

How hackers ‘tricked’ IT department of one of the biggest UK retailers to disable its entire online operations, ET CISO

How hackers ‘tricked’ IT department of one of the biggest UK retailers to disable its entire online operations, ET CISO

Last month, a group of cybercriminals brought the online operations of Marks & Spencer to a halt by reportedly exploiting a basic human vulnerability. Posing as legitimate employees, the hackers called up the IT help desks of one of the UK’s largest retailers and convinced its staff to reset passwords for the accounts they had impersonated, a report claims. With those credentials in hand, they infiltrated the company network and disabled its website and app ordering systems. Two weeks after the incident, customers remain unable to place clothing and home orders online, while M&S claims to be working “day and night” to restore services. However, the retailer has not provided a timeline for resuming online orders, noted that some food products remain unavailable, and has yet to disclose the financial impact of the disruption.

How has this cybercrime affected the retailer’s customers

M&S first encountered disruptions over the Easter weekend, when customers reported issues with Click & Collect and contactless payments. The company confirmed it was dealing with a “cyber incident,” and although these services have since resumed, it paused online orders on its website and apps last week. A week later, there is still no timeline for when online ordering will restart.

In-store, some food items remain unavailable as M&S continues to take systems offline to manage the attack. Signs on empty shelves read: “Please bear with us while we fix some technical issues affecting product availability.” Although the retailer had hoped to restore full food availability by the end of the week, it remains unclear whether that target will be met.

Additionally, M&S has temporarily removed all job adverts from its website. Visitors now see a message stating: “Sorry you can’t search or apply for roles right now, we’re working hard to be back online as soon as possible.”

Cybersecurity experts have warned UK businesses against data breaches

According to a report by BleepingComputer, Britain’s National Cyber Security Centre has also advised all organisations to audit their help-desk procedures to identify and prevent such incidents.

In a joint blog post (seen by Bleeping Computer), Jonathon Ellison and Ollie Whitehouse, national resilience director and chief technology officer at Britain’s cyber security centre, respectively, said: “Criminal activity online – including, but not limited to, ransomware and data extortion – is rampant. Attacks like this are becoming more and more common. And all organisations, of all sizes, need to be prepared.”

Investigators have confirmed that it was a ransomware attack. Ransomware is malicious software that infiltrates computer systems, encrypts critical data or files, and demands payment, often under threat of leaking or selling the stolen information.

Security experts speaking to the BBC have attributed the breach to a ransomware group known as “DragonForce,” which rents its malware tools to other criminals. This arrangement makes it difficult to identify the exact actors, though many in the cybersecurity community suspect a teen hacker collective called Scattered Spider. Meanwhile, the Metropolitan Police have confirmed they are investigating the incident.

  • Published On May 7, 2025 at 09:15 AM IST

Join the community of 2M+ industry professionals

Subscribe to our newsletter to get latest insights & analysis.

Download ETCISO App

  • Get Realtime updates
  • Save your favourite articles


Scan to download App

Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

 

 

 

 

 

 

 

 

 

 

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket