Marks & Spencer
Incident posture
Linked entities
- Victim
- Marks & Spencer
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Marks & Spencer experienced a ransomware attack in 2025, contributing to over 300 UK firms hit; no specific threat actor attributed in the report.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Between April 2025 and March 2026, UK organizations faced a sustained wave of ransomware activity, with the City of London Police's Report Fraud service receiving reports from 323 corporate victims over the twelve-month period. This equated to an average of more than 26 successful ransomware attacks each month, with small and mid-sized enterprises (SMEs) accounting for more than half of all reports submitted to the service. The financial toll on affected businesses was substantial, with average losses associated with these incidents rising by roughly 50% year-on-year to approximately £270,000 (around $357,000) per victim. The police force acknowledged that this figure was likely a significant underestimate, as many businesses chose not to fully disclose the true cost of the incidents. Of the victims who confirmed their industry sector, manufacturing was the most frequently reported vertical with 42 cases, followed by the scientific and technical sector with 21 reports and education with 19 reports.
The period was marked by several high-profile breaches that had an outsized impact on the UK economy. Among the most prominent incidents were attacks on Marks & Spencer, the Co-op Group, and Jaguar Land Rover, which collectively cost the national economy billions of pounds. The Jaguar Land Rover attack drew particular attention when, in the same week the broader ransomware statistics were published, Russian hackers were blamed for the intrusion. Security experts analyzing that incident suggested the attack may have been designed with sabotage rather than purely financial motives in mind, distinguishing it from typical extortion-focused ransomware operations. Industry observers noted that the true scale of ransomware breaches across the UK during the year was likely considerably higher than the reported figures suggested, as many incidents continued to go undisclosed.
In response to the growing threat, Report Fraud's head of operations, Chief Superintendent Amanda Wolf, emphasized that preparation represented the best form of defense for organizations. She encouraged businesses to adopt proactive measures including regular data backups, strong access controls, keeping systems up to date, and following guidance issued by the National Cyber Security Centre. Talion CEO Kevin Knight echoed these sentiments and specifically urged corporate victims not to pay ransom demands to their extorters, noting that returned data is rarely complete and often arrives in a format that differs entirely from its original structure. Knight further explained that even when organizations do pay, decryption keys do not always function properly, meaning victims can still be left unable to rebuild their data after complying with extortion demands. Timon Johnson, a principal Cyber Essentials assessor at Closed Door, argued that resilience and prevention should be the primary focus, noting that ransomware, while damaging, no longer represents an existential threat to companies that adopt proper practices such as maintaining regular and thorough backups, implementing appropriate access controls, and keeping data in cold storage. The UK government continued to consider plans for mandatory ransomware reporting and a potential ban on ransom payments from public sector bodies and critical infrastructure providers, though no such framework had been implemented at the time of reporting.
Sources
Sources available to members: 1 source.