The Attack On M&S Reverberates Three Weeks Later

The chaotic problems at British retail giant Marks & Spencer (M&S) are being caused by a ransomware attack believed to be conducted by threat actors known as Scattered Spider.  

M&S is a British multinational retailer that employs 64,000 employees and sells various products, including clothing, food, and home goods in over 1,400 stores worldwide. The retailer is dealing with some major issues, with empty shelves not replenished and delays to its online shopping services.

Now, M&S have disclosed that customers’ personal data has been taken and must comply with the legal requirement to report this to the UK Information Commissioner's Office (ICO) under the 2018 UK Data Protection Act.

M&S's assessment that customers don't need to take immediate action is based on the critical fact that payment details and passwords were not compromised, which does significantly reduce the most severe and immediate financial risks however, after any cyber incident it is important to remain alert after any data breach. Here are some simple tips to maintain security - 

  • Remain Alert of suspicious communications: Be extra cautious of any emails, calls, or texts claiming to be from people associated with M&S or other companies, especially if they ask for personal or financial information, or contain links you're unsure about. 
  • Use strong, unique passwords: consider changing passwords immediately to maintain secure access, it is good practice to use unique and strong passwords for all your online accounts. If you've reused your M&S password on other sites, consider changing them all also. 
  • Enable Two-Factor Authentication (2FA): If the option is available always apply 2FA for your accounts. This adds an extra layer of security and makes it harder for attackers to gain access to sensitive systems 
  • Monitor your accounts: Keep an eye on your online accounts for anything unusual. 

Scattered Spider is known for its ability to target large multisite companies and breaching their data. Since the attack commenced last weekend M&S has lost more than £700 million, wiped off its stock market valuation.

Shoppers are still able to browse online and shop in M&S’s physical stores using cash or cards, but some major problems continue in stores, with gift cards not currently being accepted. Returning goods is only possible in clothing and homeware stores or via post. Food stores are not currently able to accept returns.

In expert comment, Chief Security Officer & EVP Information Security, Tim Grieveson at ThingsRecon said "It is noted that M&S is indicating a lower risk due to the exclusion of sensitive financial and password data, however in my opinion it does not mean that customers are not at risk even when these specific details are not compromised. As we know, these scams are on the rise and might try to convince customers into revealing passwords, financial details, or clicking on malicious links. Email addresses and other contact information could also be sold to spammers or other malicious actors, leading to an increase in unsolicited emails, calls, or texts.   

"M&S has stated that customers will be prompted to reset their password the next time they log in as an "extra peace of mind" measure. While this isn't a direct result of passwords being stolen, it's a good security practice to ensure existing credentials aren't compromised by other means or used in credential stuffing attacks where attackers try stolen username/password combinations from other breaches on your M&S account”. 

Scattered Spider, also known as 0ktapus, Starfraud, Scatter Swine and Muddled Libra is a classification of threat actors that are adept at using social engineering attacks, phishing, multi-factor authentication (MFA) bombing (targeted MFA fatigue), and SIM swapping to gain initial network access on large organisations.

Scattered Spider members have typically engaged in data theft for extortion and have been known to use BlackCat ransomware.

This hacking group includes young members as young as 16 and is based in the UK and US, with a range of skills and the group began hacking in financial fraud and social media but now steals crypto-currency and hacks company data in extortion attacks. Some Scattered Spider members are thought to be part of The Comm, a group involved in high-profile cyber incidents and they use of different individuals for each attack make them difficult to track.

One of Scattered Spider's biggest exploits was at the gaming giant MGM Resorts International in September 2023, when guests reported difficulty accessing rooms and using casino games. MGM operates over 30 hotel and gaming venues around the world was alerted to a potential hack when Scattered Spider brought MGM systems to a halt after they gained access to the company's management systems and were able deploy ransomware.

In that exploit, MGM confirmed that some customers personal data was stolen, including names, dates of birth and driving license numbers. In some cases, social security numbers and passport numbers were also involved. 

In the latest exploit against M&S, Grievson concludes that "While the risk is indeed lower than a breach involving payment or password details, it's not entirely absent. Staying informed and practicing good online security habits is always the best defence as well as staying alert and practicing good digital hygiene." 

ITV   |   Bleeping Computer   |   Drapers   |   The Times   |  Guardian  |   BBC 

Image: Ideogram

You Might Also Read:

CISOs Guide To Compliance & Cyber Hygiene:


If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 






 

« Five Top-Rated Threat Intelligence Platforms
Co-op Shuts Down IT Systems After Attempted Hack »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Malware.lu

Malware.lu

Malware.lu is a repository of malware and technical analysis. The goal of the project is to provide samples and technical analysis to security researchers.

Digitus Biometrics

Digitus Biometrics

Digitus Biometrics is a market leader in biometric access control. We can secure access to any entry point, from the front door to the server rack cabinet.

Tinfoil Security

Tinfoil Security

Tinfoil is a simple, developer friendly service that lets you scan your website for vulnerabilities and fix them quickly and easily.

KFSensor

KFSensor

KFSensor is an advanced 'honeypot' intrusion and insider threat detection system for Windows networks.

StationX

StationX

StationX is a leading provider of cyber security training, consultancy and services.

Greensafe IT

Greensafe IT

Greensafe offer various onsite and offsite data erasure services, aimed at increasing data security whilst reducing any risk of data loss during transit.

ToucanX

ToucanX

ToucanX has eliminated remote attack vectors without sacrificing productivity. We’ve brought embedded near real time virtualization to the enterprise endpoint.

Securosys

Securosys

Securosys is a technology company dedicated to securing data and communications. We develop, produce, and distribute hardware, software and services that protect and verify data and their transmission

Indevis

Indevis

Indevis provides IT security, datacenter and network solutions, accompanied by professional consulting, management and support services.

Willyama Services

Willyama Services

Willyama Services is a certified Information Technology and Cybersecurity professional services business providing services to government and private sector clients.

Carahsoft Technology Corp

Carahsoft Technology Corp

Carahsoft Technology is The Trusted Government IT Solutions Provider, supporting Public Sector organizations across Federal, State and Local Government agencies and Education and Healthcare markets.

Beetles Cyber Security

Beetles Cyber Security

Beetles is a crowdsourced penetration testing platform designed to build a trusted, hacker-centric approach to protectan organization’s digital attack surface.

Boecore

Boecore

Boecore is an aerospace and defense engineering company that specializes in software solutions, systems engineering, cybersecurity, enterprise networks, and mission operations.

Axient

Axient

Axient advances defense and civilian missions from aerospace to cyberspace with multi-domain test and analysis, mission engineering and operations, and advanced technologies.

Certcube Labs

Certcube Labs

Certcube Labs provide a broad range of services in the areas of Assessments, Development, Risk Advisory, Blockchain, Forensics Investigations, Managed Security Solutions, and IT Security Trainings.

Vantyr

Vantyr

Vantyr's core mission is to safeguard the business-led adoption of SaaS applications by automating the lifecycle management and security of non-human identities.

Transcendental Technologies

Transcendental Technologies

Transcendental is a consulting organization which specializes in customized assurance services in the fields of Localization, Mobile Software Solutions, Web Design, Cyber Security & Cyber Forensics.