Ransomware

Scattered Spider suspected to be behind Marks & Spencer compromise

Cyber basics

Outages experienced by major UK multinational food and clothing retailer Marks & Spencer since last week have been attributed to an attack by the hacking collective Scattered Spider, which was initially reported by the company to have disrupted its contactless payment and online ordering systems, according to BleepingComputer. M&S was first compromised by Scattered Spider also known as 0ktapus, Octo Tempest, Muddled Libra, Scatter Swine, and UNC3944 using a stolen Windows domain's NTDS.dit file containing Windows account password hashes, which were later leveraged for lateral movement and data exfiltration before the eventual distribution of the DragonForce encryptor to VMware ESXi hosts on Thursday, noted sources close to the investigation into the incident. Such a development comes more than a year after Scattered Spider first dabbled in social engineering intrusions following initial social media and financial fraud attacks, with the group targeting MGM Resorts with the BlackCat ransomware in September 2023.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds