Marks & Spencer (M&S), Co-op Group and Harrods cyber attack – Technical Analysis

Sharing is caring!

&NewLine;<figure class&equals;"wp-block-image size-large is-resized"><img src&equals;"https&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2025&sol;04&sol;Screenshot-2025-04-30-at-15&period;45&period;48-1-1024x561&period;png" alt&equals;"" class&equals;"wp-image-900" style&equals;"width&colon;610px&semi;height&colon;auto"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>The recent <strong>Marks &amp&semi; Spencer &lpar;M&amp&semi;S&rpar;&comma; Co-op Group and Harrods<&sol;strong> <strong>cyber attack<&sol;strong> &lpar;reported in May 2025&rpar; involved a sophisticated <strong>ransomware attack<&sol;strong> that disrupted operations&comma; including online orders&comma; warehouse logistics&comma; and customer service systems&period; Below is a <strong>deep technical analysis<&sol;strong> along with <strong>key lessons learned<&sol;strong> from the incident&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading">Attack Timeline and Methodology<&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list">&NewLine;<li><strong>Initial Breach &lpar;February 2025&rpar;&colon;<&sol;strong> The attackers reportedly infiltrated M&amp&semi;S&&num;8217&semi;s systems as early as February&comma; exfiltrating the NTDS&period;dit file—a critical component of Windows Active Directory that contains hashed credentials&period; This allowed them to crack passwords offline and gain elevated access across the network &period;&ZeroWidthSpace; <&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li>The attack is attributed to the hacking collective known as Scattered Spider&comma; also referred to as UNC3944&comma; Octo Tempest&comma; and Muddled Libra&period; This group is known for sophisticated social engineering techniques&comma; including phishing&comma; SIM swapping&comma; and multi-factor authentication &lpar;MFA&rpar; fatigue attacks&period; Such methods likely facilitated initial access to M&amp&semi;S&&num;8217&semi;s systems&period; &ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Extraction of NTDS&period;dit File<&sol;strong>&colon; Once inside the network&comma; the attackers reportedly exfiltrated the NTDS&period;dit file&comma; which contains Active Directory data&comma; including user account information and password hashes&period; By obtaining this file&comma; the attackers could perform offline password cracking&comma; enabling them to escalate privileges and move laterally within the network&period; &ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Lateral Movement and Reconnaissance&colon;<&sol;strong> With administrative credentials&comma; the attackers moved laterally within M&amp&semi;S&&num;8217&semi;s IT environment&comma; identifying key assets and systems&period;&ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Deployment of DragonForce Ransomware<&sol;strong>&colon; After establishing a foothold&comma; the attackers deployed DragonForce ransomware on April 24&comma; 2025&comma; targeting M&amp&semi;S&&num;8217&semi;s VMware ESXi servers&period; This action encrypted virtual machines&comma; disrupting various services&comma; including online orders and contactless paymentsnal disruptions <&sol;li>&NewLine;<&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading">Impact on Operations<&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list">&NewLine;<li><strong>Online Services&colon;<&sol;strong> M&amp&semi;S suspended online orders and click-and-collect services&comma; affecting a significant revenue stream&comma; as online sales accounted for over £1&period;27 billion in the previous year &period;&ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>In-Store Operations&colon;<&sol;strong> Contactless payments were temporarily disabled&comma; and gift card transactions were disrupted&period;&ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Workforce&colon;<&sol;strong> Approximately 200 agency workers at the Castle Donington distribution center were instructed to stay home due to operational slowdowns &period;&ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Financial Repercussions&colon;<&sol;strong> The company&&num;8217&semi;s market valuation dropped by nearly £700 million in the days following the attack &period;&ZeroWidthSpace;<&sol;li>&NewLine;<&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading">Lessons Learned<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading">1&period; <strong>Importance of Proactive Threat Detection<&sol;strong><&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<p>The attackers maintained a presence within M&amp&semi;S&&num;8217&semi;s systems for an extended period before deploying ransomware&period; This underscores the need for continuous monitoring and advanced threat detection capabilities to identify and mitigate threats before they escalate&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading">2&period; <strong>Strengthening Authentication Mechanisms<&sol;strong><&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<p>The exploitation of MFA fatigue and social engineering tactics highlights the necessity of robust authentication protocols&period; Implementing phishing-resistant MFA methods&comma; such as hardware tokens or biometric verification&comma; can enhance security&period;&ZeroWidthSpace;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading">3&period; <strong>Regular Auditing and Credential Management<&sol;strong><&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<p>The theft of the NTDS&period;dit file emphasizes the critical need for regular auditing of privileged accounts and the implementation of stringent credential management practices&comma; including the use of unique&comma; complex passwords and regular rotation&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading">4&period; <strong>Network Segmentation and Least Privilege Access<&sol;strong><&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<p>Limiting lateral movement through network segmentation and enforcing the principle of least privilege can contain breaches and prevent attackers from accessing critical systems&period;&ZeroWidthSpace;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading">5&period; <strong>Incident Response Planning and Communication<&sol;strong><&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<p>M&amp&semi;S&&num;8217&semi;s response involved collaboration with cybersecurity firms and notification of relevant authorities&period; However&comma; some customers expressed dissatisfaction with the communication regarding the incident &ZeroWidthSpace;&period; This highlights the importance of transparent and timely communication during cybersecurity incidents&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<hr class&equals;"wp-block-separator has-alpha-channel-opacity"&sol;>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading">🛡️ Recommendations for Organizations<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<ol class&equals;"wp-block-list">&NewLine;<li><strong>Implement Advanced Threat Detection&colon;<&sol;strong> Utilize behavioral analytics and anomaly detection tools to identify suspicious activities promptly&period;&ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Enhance Employee Training&colon;<&sol;strong> Conduct regular training sessions to educate employees about phishing&comma; social engineering&comma; and other common attack vectors&period;&ZeroWidthSpace;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Regularly Update and Patch Systems&colon;<&sol;strong> Ensure all systems and applications are up-to-date with the latest security patches to mitigate known vulnerabilities&period;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Develop Comprehensive Incident Response Plans&colon;<&sol;strong> Establish and routinely test incident response protocols to ensure preparedness for potential cyber incidents<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li><strong>Engage in Threat Intelligence Sharing&colon;<&sol;strong> Participate in information-sharing initiatives to stay informed about emerging threats and attack methodologies&period;&ZeroWidthSpace;<&sol;li>&NewLine;<&sol;ol>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading">Conclusion<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>The May 2025 cyberattack on British retail stores is a stark reminder of the evolving threat landscape and the necessity for organizations to adopt a proactive and comprehensive approach to cybersecurity&period;&ZeroWidthSpace;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>If I had to speculate based on Scattered Spider’s historical behaviour&colon;<&sol;strong> <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list">&NewLine;<li><strong>Spear phishing of privileged users<&sol;strong> is a strong candidate — they’ve pulled this off successfully before&comma; often using LinkedIn scraping and MFA fatigue&period;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li>The <strong>exfiltration of the NTDS&period;dit file<&sol;strong> suggests they were able to achieve Domain Admin privileges early — possibly via misconfigured identity federation&comma; legacy auth protocols like NTLM&comma; or <strong>exploiting hybrid AD&sol;Entra ID misconfigurations<&sol;strong>&period;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li>If <strong>VMware ESXi servers<&sol;strong> were targeted again&comma; it may also hint at <strong>vCenter exposure<&sol;strong>&comma; especially if it&&num;8217&semi;s not behind a hardened management plane or VPN&period;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li>We shouldn’t rule out <strong>ZeroLogon-like exploitation<&sol;strong> or even <strong>vulnerabilities in endpoint agents<&sol;strong> with elevated privileges&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Until details emerge&comma; I’d say it’s vital for other orgs to&colon;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list">&NewLine;<li>Conduct <strong>AD tiering audits<&sol;strong>&comma;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li>Enforce <strong>Privileged Access Workstations &lpar;PAWs&rpar;<&sol;strong>&comma;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li>Review <strong>MFA enrollment methods<&sol;strong> &lpar;and ban SMS-based and push-only setups&rpar;&comma;<&sol;li>&NewLine;&NewLine;&NewLine;&NewLine;<li>And implement <strong>credential guard<&sol;strong> and <strong>LSASS hardening<&sol;strong> where feasible&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<hr class&equals;"wp-block-separator has-alpha-channel-opacity"&sol;>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Credit &amp&semi; Sources<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>&period;&ZeroWidthSpace;<a href&equals;"https&colon;&sol;&sol;www&period;bleepingcomputer&period;com&sol;news&sol;security&sol;marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack&sol;&quest;utm&lowbar;source&equals;chatgpt&period;com" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">The Sun&plus;4BleepingComputer&plus;4Bloomberg&plus;4<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>&ZeroWidthSpace;<a href&equals;"https&colon;&sol;&sol;www&period;techzine&period;eu&sol;blogs&sol;security&sol;130892&sol;what-the-marks-spencer-cyberattack-can-teach-retailers&sol;&quest;utm&lowbar;source&equals;chatgpt&period;com" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">The Guardian&plus;2Techzine Global&plus;2The Standard&plus;2<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;the-independent&period;com&sol;news&sol;uk&sol;home-news&sol;marks-and-spencer-cyber-attack-hack-staff-online-orders-b2740682&period;html&quest;utm&lowbar;source&equals;chatgpt&period;com" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">Silicon Republic&plus;17The Independent&plus;17Latest news &amp&semi; breaking headlines&plus;17<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;thetimes&period;co&period;uk&sol;article&sol;m-and-s-cyber-attack-data-bg0nqvprm&quest;utm&lowbar;source&equals;chatgpt&period;com" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">The Guardian&plus;9Latest news &amp&semi; breaking headlines&plus;9TechRadar&plus;9<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;ft&period;com&sol;content&sol;1d46953a-5f2d-4395-85b9-af337a4747db&quest;utm&lowbar;source&equals;chatgpt&period;com" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">Latest news &amp&semi; breaking headlines&plus;4<&sol;a><&sol;p>&NewLine;