In April 2025, Marks & Spencer was hit by a highly sophisticated ransomware attack. This wasn’t a simple virus or a careless click, it was a coordinated campaign conducted by a cybercriminal syndicate known as DragonForce, linked with the notorious Scattered Spider group. 
 
The result? 
- Over seven weeks of disruption, 
- A £300 million impact on M&S’s profits, 
- And a clear warning for every other UK business: Even the best-known brands with serious IT budgets aren’t immune. 
 
If your business relies on customer data, online services, or critical IT infrastructure, you need to take this seriously. 

What Actually Happened, In Plain English 

1. They talked their way in 

The attackers tricked an external IT helpdesk into resetting credentials for high-privilege accounts bypassing multi-factor authentication. This tactic is known as vishing (voice phishing). 
 
Key takeaway: Strong systems can be undone by human error. Training and process matter as much as firewalls. 

2. They quietly explored the network 

Once inside, the hackers: 
- Stole the password database from M&S’s identity system (Active Directory), 
- Used legitimate IT tools (like PowerShell and RDP) to move around unnoticed, 
- Avoided detection by not installing malware right away. 
 
Key takeaway: This was a “living off the land” attack, no obvious malware, just built-in tools. You need behavioural monitoring, not just antivirus. 

3. They took control of the core infrastructure 

They targeted VMware ESXi servers  the foundation for many M&S business systems. By encrypting these, they effectively shut down: 
- Online shopping, 
- Click & Collect, 
- In-store payments, 
- Warehouse and logistics platforms. 
 
Key takeaway: Taking out the virtual infrastructure is like cutting power to a whole office building. This wasn't just a breach, it was a business outage. 

4. They stole data AND locked systems 

The attack was double extortion: 
- First, steal customer data (names, contact details, DOBs), 
- Then, encrypt systems and demand a ransom, 
- Threaten to leak the data if M&S didn’t pay. 
 
M&S refused to pay and chose to recover on their own. It took 46 days to get the website back up and it was still being reported as not fully “back to normal” months later. 

Why This Matters for SMEs 

You might think: “We're not M&S, no one’s coming for us.” But here’s the truth: 


- SMEs are easier to breach: fewer security layers, limited monitoring, weaker controls. 
- Ransomware gangs are automating their method: they can hit hundreds of companies at once. 
- Even indirect access (via suppliers or IT partners) can put you at risk. 

What’s the Solution? A Managed Security Operations Centre (SOC) 

A Managed SOC gives your business access to the kind of 24/7 protection M&S needed, without hiring a full-time security team. 

SOC Capability 

What It Does for You 

24/7 Monitoring 

Detects unusual logins, admin activity, and risky behaviour; even without malware present. 

Rapid Response 

If something’s wrong, systems are isolated and contained fast;  before ransomware spreads. 

Expert Analysis 

SOC analysts investigate incidents, not just alert you; they provide answers, not just alarms. 

Reporting & Compliance 

Clear dashboards and reports for the boardroom or regulators. No jargon, just clarity. 

 

What Should You Do Right Now? 

For IT & Technology Leaders: 

  • Review access control and admin privileges. 
  • Enforce MFA and ensure helpdesks can't override it without robust checks. 
  • Patch all VMware or virtual infrastructure. 
  • Set up alerts for odd behaviour (logins at strange hours, sudden file movements). 
  • Back up key systems offline. 

 

For Business Leaders and Executives: 

  • Ask: “What would we do if we had to shut down for a week?” 
  • Ask you internal teams and suppliers about what precautions and processes are in play 
  • Ensure cyber risk is part of business continuity planning. 
  • Take continuous training of your people seriously 
  • Budget for security as an operational essential, not an optional extra. 

 

Final Word 

The attack on M&S was professional, patient, and brutal. It bypassed traditional defences and crippled critical operations. It cost them £300 million and weeks of business and they’re one of the best-resourced retailers in the UK. 
 
For SMEs, the threat is even more real. 
 
The good news? You don’t need to solve this alone. We offer a Managed SOC designed for growing businesses: 


- Affordable, scalable, and built to match the threats of today. 
- Backed by UK-based analysts and enterprise-grade technology. 
- Gives you peace of mind and a clear path to cyber resilience. 

Get in touch today to see how our Managed SOC can help your business stay secure, compliant, and in control. 

OTHER NEWS

Cyber Security vs AI: What Accountants Told Us at Accountex 2025

At Accountex 2025, we posed a simple but revealing question to visitors at the T-Tech stand:

“If you could only invest in either AI or Cyber Security in 2025, which would it be?”

READ MORE

In the Pressure Cooker: Tax Deadlines and Cyber Threats Facing UK Accountants This January

January can be the month that some UK accountants dread most. With the self-assessment tax return deadline looming on the 31st, accountancy tax practices find themselves working at full throttle. It’s a time of intense pressure, long hours, and...

READ MORE

Cybersecurity: Why it’s more important than ever for professionals to be prepared

The importance of cybersecurity cannot be overstated, especially for industries that handle sensitive financial and personal data, such as accounting and professional services. Cyber threats are evolving at an unprecedented pace, making it...

READ MORE

Bringing It All Together: A Comprehensive Cybersecurity Strategy for Your Firm

Over the course of our series, we’ve traversed the landscape of cybersecurity for UK accountancy firms, from the external defences akin to a home’s locks and alarms to the internal safeguards that protect the valuables within. It’s clear that in the...

READ MORE

Fortifying Your Firm From The Inside: Advanced Internal Safeguards

In our first instalment, we explored the digital equivalent of external home security measures, underscoring the importance of robust defences like two-factor authentication, Cyber Essentials Plus certification, and regular penetration testing....

READ MORE

The Accountex 2024 Survey: A Convergence of Cybersecurity and AI in Accountancy

T-Tech recently exhibited at Accountex in London. During this event, we wanted to understand the genuine thoughts of accounting professionals on emerging AI & Cybersecurity technologies and assess the industry's preparedness to integrate them into...

READ MORE

Understanding the Cybersecurity Threat Landscape for UK Accountancy Firms

In recent years, the UK accountancy sector has witnessed a significant rise in cybersecurity threats, exemplified by the ransomware attacks on notable firms such as SJD Accountancy, Parasol, and Nixon Williams. These incidents highlight the...

READ MORE