ZeroFox Intelligence Flash Report - Marks & Spencer Cyber Incident
|by Alpha Team

ZeroFox Intelligence Flash Report - Marks & Spencer Cyber Incident
Product Serial: F-2025-04-30b
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the ongoing disruption of retail organization Marks & Spencer, which has been linked to a possible digital extortion attack.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On April 22, 2025, Marks & Spencer (M&S), one of the United Kingdom’s leading retailers, publicly confirmed that it was managing a cyber incident.
- While M&S has not officially stated a cyberattack has occurred, the characteristics observed in this incident are consistent with ransomware attacks.
- Investigations remain ongoing, with M&S confirming it has called in the UK’s National Cyber Security Centre to assist in containing and resolving the incident. M&S has also reported the incident to the Information Commissioners Officer (ICO).
- The M&S cyber incident highlights the growing cybersecurity risks faced by the UK retail sector. Disruption to services critical to customer experience can have an immediate impact on reputation and consumer trust.
Tags: dark web, retail/cpg, threat actor, eu/russia