ADVERTISEMENT

M&S confirms month-long breach result of third-party vendor phishing attack

Marks & Spencer (M&S) has confirmed a Cybernews report that Scattered Spider hackers were able to infiltrate the UK retailer’s networks by phishing employees of a third-party vendor and stealing their login credentials. This is as unnamed sources on Tuesday identified Tata Consulting Services (TCS) as that vendor.

M&S

Image by Carlos Jasso | Reuters

Stefanie Schappert
Stefanie Schappert Senior Journalist
May 21, 2025 Updated: May 22, 2025 4 min read
Tata Consultancy Services
Image by PradeepGaurs | Shutterstock

Widespread disruption unleashed on UK retail sector

justinasv Ernestas Naprys Konstancija Gasaityte Niamh Ancell
Get our latest stories today on Google News
Add us as your Preferred Source on Google.

M&S recovery still months away

Marks & Spencer out of order
Image by Suzanne Plunkett | Reuters
ADVERTISEMENT
M&S customer data statement
corporate.marksandspencer.com
M&S CEO Stuart Machin
Image by Marks & Spencer

Scattered Spider chaos

ADVERTISEMENT