The attacks on Marks & Spencer and the Co-op, beginning in April 2025 and attributed to the crew tracked as Scattered Spider or UNC3944, have been assessed as a single combined cyber event with a total impact estimated between £270 million and £440 million. M&S alone has been reported at roughly £300 million.
M&S chairman Archie Norman has said publicly that the attackers impersonated an employee and called a service desk operated by a third party, which carried out a password reset.
The Same Technique, Still
Readers of this desk will recognise the sequence from the Charter file in 26-0526, and from the account ShinyHunters gives of its own intrusion at 26-0714: a phone call, an identity restored to the wrong person, and access that looks entirely legitimate from the moment it is granted.
What distinguishes this case is the outcome. Identity compromise in a retailer with integrated logistics does not produce a data breach; it produces empty shelves. The consequence moved from the database to the supply chain within days.
Why A Company Confirming The Mechanism Matters
Very few organisations describe their own initial access route in public, and the reticence is understandable — it invites blame and helps the next attacker.
It is nonetheless the single most useful thing an affected company can do. A named mechanism lets every peer organisation check one specific control this week. Without it, the sector receives a warning about "sophisticated attackers" and cannot act on it.
A Combined Event Is A Category Worth Having
Assessing two victims as one event is an unusual and sensible move. The crew, the technique and the window were shared, so treating them as independent incidents would understate the systemic nature of what happened and misprice the risk for everyone else in the sector.
Compiled from public reporting and published loss assessment, listed below. Cost figures are modelled third-party estimates, not company disclosures. The initial access description is as stated publicly by M&S. Corrections: corrections@forensicpost.com.