Desk live·
ForensicPost
Ransomware/Retail/File 26-0411

M&S and Co-op Intrusions Assessed as a Single Event Costing up to £440 Million

The M&S and Co-op intrusions have been assessed as a single combined event costing between £270 million and £440 million. The route in both was social engineering against an IT help desk.

Constructed geometry · not a chart of case data
TargetMarks & Spencer and Co-op
ActorScattered Spider
S. Rosler & D. Kennedy13 min readConfidence: high3 sources reviewed

The attacks on Marks & Spencer and the Co-op, beginning in April 2025 and attributed to the crew tracked as Scattered Spider or UNC3944, have been assessed as a single combined cyber event with a total impact estimated between £270 million and £440 million. M&S alone has been reported at roughly £300 million.

M&S chairman Archie Norman has said publicly that the attackers impersonated an employee and called a service desk operated by a third party, which carried out a password reset.

The Same Technique, Still

Readers of this desk will recognise the sequence from the Charter file in 26-0526, and from the account ShinyHunters gives of its own intrusion at 26-0714: a phone call, an identity restored to the wrong person, and access that looks entirely legitimate from the moment it is granted.

What distinguishes this case is the outcome. Identity compromise in a retailer with integrated logistics does not produce a data breach; it produces empty shelves. The consequence moved from the database to the supply chain within days.

Why A Company Confirming The Mechanism Matters

Very few organisations describe their own initial access route in public, and the reticence is understandable — it invites blame and helps the next attacker.

It is nonetheless the single most useful thing an affected company can do. A named mechanism lets every peer organisation check one specific control this week. Without it, the sector receives a warning about "sophisticated attackers" and cannot act on it.

A Combined Event Is A Category Worth Having

Assessing two victims as one event is an unusual and sensible move. The crew, the technique and the window were shared, so treating them as independent incidents would understate the systemic nature of what happened and misprice the risk for everyone else in the sector.

How we reported this

Compiled from public reporting and published loss assessment, listed below. Cost figures are modelled third-party estimates, not company disclosures. The initial access description is as stated publicly by M&S. Corrections: corrections@forensicpost.com.

Sources
  1. Scattered Spider behind cyberattacks on M&S and Co-op, causing up to $592M in damagesThe Hacker News
  2. M&S, Co-op attacks a ‘Category 2 cyber hurricane’, say UK expertsComputer Weekly
  3. M&S ransomware hack: what happened and the key security lessonsSpecops
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary