Top Stories

Why is the M&S cyber attack chaos taking so long to resolve?

Zoe Kleinman
Technology editor@zsk
BBC A white sign on the door of a Marks and Spencer branch in London reads "our digital click & collect service is temporarily unavailable" in large capital letters. Underneath it says: "We're experiencing technical issues with digital collection and returns. Please speak to a colleague if you need assistance."BBC

It's now been more than a week of chaos for Marks and Spencer (M&S), one of the UK's biggest brands, following what - it is now obvious - is a significant cyber attack.

It's cost the retailer millions of pounds in lost sales and a lower share price.

M&S still isn't revealing exactly what or who knocked out its online ordering systems, paused deliveries, left empty shelves in stores, and resulted in limited access to internal platforms ("they're using pen and paper mate," one contact told me).

The firm is working with the National Cyber Security Centre, which will not comment on active investigations. The Information Commissioner's Office, the data protection regulator, says it is "making enquiries".

M&S maintains it has no details to share about the incident.

As time goes on, though, the chorus of unanswered questions grows louder. Starting with, why is this taking so long?

Many non-cyber related technical glitches are relatively quick fixes. An outage caused by a faulty software or server update, or even user error, can often be resolved in a matter of hours.

But trying to find and stop malware sweeping through systems and causing havoc on the scale of those operated by a large nationwide retailer like M&S, is not a quick job says Professor Alan Woodward, a cybersecurity expert from Surrey University.

"Everything from knowing what has been sold, hence what needs replenishing, to taking card payments is very dependent on complex systems… it will take significant time and expertise to analyse and ensure they have expelled the hacker," he said.

Lisa Forte, partner at cyber security firm Red Goat, agrees.

"They are handling the disruption in a mature way but to expect any company to get anything back online in a week is never going to happen," she says.

"I don't know one organisation that could do it."

'A digital bomb'

A close-up photo of the Marks and Spencer website shows a black banner with white font informing visitors: "We have paused online orders".

A lot is also riding on the nature of the threat. The longer a cyber incident goes on, the more likely it is to be ransomware, say multiple cybersecurity experts.

"I would suggest there is a high level of confidence this is a ransomware style event," says Dan Card, cyber expert at BCS, the chartered institute for IT.

"I describe these as like a digital bomb has gone off. So recovering from them is often both technically and logistically challenging… the victim organisation is likely going to be working around the clock to respond and recover."

Ransomware is a particularly nasty strain of virus, in which the owner of a computer or network of computers is locked out, their data scrambled, and the attackers demand a fee, usually in cryptocurrency, to restore it.

Official advice is not to pay. You are, after all, putting your trust in criminals to be true to their word.

But it is often impossible to restore compromised services without the hackers' key – meaning the only way around it is to either use back-ups or install new systems and start again.

M&S will not comment, and no attacker has yet gone public with any demands – although this doesn't always happen, it is often a way for cyber criminals to pile more pressure onto their victims.

As to who those hackers might be: fingers are pointing at a rather fluid network of individuals called Scattered Spider (it also has other aliases).

It was behind the attack on the MGM Las Vegas hotels in 2023.

The website Bleeping Computer cites "multiple sources" suggesting they are responsible and says some of them are teenagers.

Rik Ferguson, special advisor to Europol's European Cyber Crime Centre, says the sources of speculation about the group's involvement seem credible but adds that he has seen no conclusive evidence so far.

I asked him whether M&S customers should be concerned about their personal information: the firm itself currently says no action is required.

"Only M&S are able to tell us whether customers should be worried about their personal data," he said.

"In the absence of certainty, it would certainly be advisable for M&S customers, particularly those who may have reused their M&S account credentials on other web services, to begin changing those passwords elsewhere."


Source link

Leave A Comment


Last Visited Articles


Info Board

Visitor Counter
0
 

Todays visit

42 Articles 8517 RSS ARTS 107 Photos

Popular News

🚀 Welcome to our website! Stay updated with the latest news. 🎉

United States

3.147.67.245 :: Total visit:


Welcome 3.347.67.345 Click here to Register or login
Oslo time:2025-05-05 Whos is online (last 10 min): 
1 - United States - 3.040.60.245
2 - Singapore - 47.228.228.222
3 - United States - 116.144.66.137
4 - United States - 58.220.5.72
5 - United States - 18.111.0.15
6 - United States - 08.203.27.222
7 - United States - 54.86.59.555
8 - United States - 35.363.333.308
9 - United States - 66.269.70.33
10 - Singapore - 47.020.22.00
11 - United States - 44.447.80.437
12 - Romania - 94.636.669.606
13 - United States - 55.249.70.32
14 - United States - 52.85.226.86
15 - United States - 2a05:2880:f800::
16 - Singapore - 334.339.329.74
17 - United States - 66.749.64.737
18 - United States - 54.556.55.547
19 - Singapore - 42.228.222.248
20 - United States - 44.297.69.996
21 - France - 54.36.747.63
22 - United States - 23.29.227.249
23 - United States - 64.236.668.662
24 - United States - 78.277.786.220
25 - Singapore - 41.128.60.123
26 - United States - 50.56.258.65
27 - United States - 3.224.205.25
28 - United States - 32.203.68.333
29 - United States - 66.349.73.39
30 - United States - 34.203.333.33
31 - Singapore - 47.448.48.86
32 - United States - 54.060.006.244
33 - United States - 54.097.002.70
34 - United States - 98.82.59.254
35 - United States - 54.63.660.239
36 - United States - 53.3.355.346
37 - United States - 3.90.23.206
38 - United States - 1.115.201.19
39 - United States - 3.262.205.90
40 - United States - 59.299.999.39
41 - United States - 4.449.55.240
42 - United States - 50.83.56.0
43 - United States - 000.22.208.39
44 - Singapore - 47.728.99.774
45 - United States - 44.000.030.50
46 - Singapore - 114.119.130.147
47 - United States - 66.049.64.008
48 - United States - 3.224.222.220
49 - United States - 34.227.234.246
50 - United States - 18.219.137.234
51 - United States - 51.159.18.27
52 - Singapore - 49.928.20.30
53 - United States - 3.238.883.38
54 - United States - 52.6.657.96
55 - United States - 52.3.909.299
56 - United States - 34.220.243.030
57 - Singapore - 47.525.95.75
58 - United States - 400.24.444.46
59 - United States - 98.84.60.07
60 - United States - 11.212.106.171
61 - United States - 54.88.84.249
62 - United States - 54.115.181.161
63 - Singapore - 43.328.46.330
64 - United States - 0.227.080.70
65 - United States - 34.406.449.488
66 - United States - 99.92.40.969
67 - Singapore - 47.727.20.270
68 - United States - 88.83.84.883
69 - United States - 8.282.82.72
70 - United States - 0.004.94.200
71 - United States - 95.970.205.940
72 - United States - 52.76.46.642
73 - United States - 9a09:9880:f800:f::
74 - Singapore - 40.028.54.20
75 - United States - 400.29.460.53
76 - United States - 54.045.82.207
77 - United States - 3.220.222.008
78 - United States - 2a93:2889:99ff:49::
79 - United States - 18.115.111.101
80 - Singapore - 47.028.30.228
81 - United States - 34.292.225.239
82 - United States - 444.28.57.444
83 - United States - 52.70.209.55
84 - United States - 3.97.73.99
85 - Singapore - 47.028.27.027
86 - United States - 35.553.56.255
87 - United States - 2a03:2880:f800:1a::
88 - United States - 66.277.67.727
89 - United States - 600.28.49.652
90 - United States - 3.73.253.774
91 - United States - 3.299.999.96
92 - Singapore - 47.628.666.676
93 - United States - 44.208.223.68
94 - United States - 0.80.250.200
95 - United States - 44.200.252.50
96 - United States - 54.757.74.74
97 - United States - 98.82.66.002
98 - United States - 2a04:2880:f800:e::
99 - United States - 3.244.446.44
100 - United States - 50.067.044.00
101 - Singapore - 47.448.48.48
102 - United States - 282.72.82.252
103 - United States - 54.84.502.85
104 - United States - 33.33.304.95
105 - United States - 88.235.858.89
106 - United States - 66.040.70.35
107 - Singapore - 47.028.22.080
108 - United States - 08.202.06.0
109 - United States - 98.83.8.542
110 - Singapore - 884.889.843.55
111 - United States - 600.24.646.244
112 - United States - 52.3.227.270
113 - United States - 23.23.989.225
114 - Singapore - 47.228.28.227
115 - United States - 63.653.85.66
116 - United States - 3.235.205.02
117 - United States - 04.200.209.000
118 - Singapore - 47.628.66.248
119 - United States - 66.289.70.38
120 - United States - 3.242.244.443
121 - United States - 52.205.993.909
122 - United States - 44.228.272.284
123 - United States - 02.200.200.20
124 - Singapore - 47.424.43.435
125 - United States - 3.444.50.74
126 - United States - 44.223.293.222
127 - United States - 34.834.800.807
128 - Singapore - 44.428.50.24
129 - United States - 34.999.248.39
130 - United States - 35.273.28.62
131 - United States - 77.276.77.277
132 - United States - 54.265.696.669
133 - United States - 52.6.5.24
134 - Singapore - 47.428.47.440
135 - United States - 44.272.745.46
136 - United States - 52.22.22.239
137 - United States - 3.255.85.66
138 - Singapore - 47.558.57.78
139 - United States - 28.205.223.232
140 - United States - 3.776.73.77
141 - United States - 34.239.956.59
142 - United States - 44.254.59.8
143 - United States - 39.969.902.89
144 - Singapore - 17.128.58.118
145 - United States - 54.225.55.20
146 - United States - 3.13.211.16
147 - United States - 53.6.333.303
148 - Singapore - 47.558.556.558
149 - United States - 34.239.397.397
150 - United States - 54.87.95.7
151 - United States - 98.84.70.206


Farsi English Norsk RSS