Full Report
British retailer giant Marks & Spencer (M&S) has suspended online orders while working to recover from a recently disclosed cyberattack. [...]
Analysis Summary
# Incident Report: Marks & Spencer Online Services Disruption Following Cyberattack
## Executive Summary
Marks & Spencer (M&S) confirmed a cybersecurity incident resulting in the decision to pause new online orders via their websites and apps as a proactive management measure. The attack, disclosed mid-week, disrupted various internal services, including contactless payments and Click & Collect functionality in stores, and caused delivery delays. M&S engaged industry-leading external cybersecurity experts to manage and resolve the situation without immediate attribution to any threat group.
## Incident Details
- Discovery Date: Tuesday (Implied, based on first disclosure)
- Incident Date: Began prior to Tuesday's disclosure
- Affected Organization: Marks & Spencer (M&S)
- Sector: Retail/E-commerce
- Geography: United Kingdom (LSE listed, FTSE100)
## Timeline of Events
### Initial Access
- Date/Time: Unknown (Prior to Tuesday disclosure)
- Vector: Not specified in the provided text.
### Lateral Movement
- Details: Unknown. The impact suggests internal disruption, but movement specifics are not detailed.
### Data Exfiltration/Impact
- Details: Company services were disrupted, including contactless payments and Click & Collect operations in physical stores. Online ordering capabilities were paused. The possibility of data exfiltration exists if ransomware was involved, though none has claimed responsibility.
### Detection & Response
- **Detection:** Disclosed via a press release to the London Stock Exchange on Tuesday.
- **Response actions taken:**
1. Engaged external, industry-leading cybersecurity experts.
2. Took some processes offline proactively to protect partners, suppliers, and business operations.
3. Paused taking new orders on M&S.com websites and apps.
4. Communicated service disruptions (contactless payments, Click & Collect delays) to customers on Wednesday.
5. Informed customers that all existing orders would be held pending resolution due to ongoing issues.
## Attack Methodology
- Initial Access: Unknown
- Persistence: Unknown
- Privilege Escalation: Unknown
- Defense Evasion: Unknown
- Credential Access: Unknown
- Discovery: Unknown
- Lateral Movement: Unknown
- Collection: Unknown (Potential, if data exfiltration occurred)
- Exfiltration: Unknown
- Impact: Operational disruption of e-commerce, in-store payment (contactless), and fulfillment services (Click & Collect).
## Impact Assessment
- Financial: Not explicitly stated, but business disruption noted, impacting online sales (£13 billion annual revenue context).
- Data Breach: Unknown. No confirmation of data exfiltration, but threat actors may have stolen data for leverage if ransomware is involved.
- Operational: Significant disruption to online ordering, in-store contactless payments, and Click & Collect fulfillment.
- Reputational: Public apologies issued; potential customer inconvenience and erosion of trust due to service unavailability.
## Indicators of Compromise
- **Network indicators - defanged:** None provided.
- **File indicators:** None provided.
- **Behavioral indicators:** Disruption of core business systems (online ordering, payments).
## Response Actions
- **Containment measures:** Took some processes offline to protect partners, suppliers, and business operations.
- **Eradication steps:** Being managed with the support of "industry-leading experts."
- **Recovery actions:** Working hard to restore services; all existing online orders are being held until resolution.
## Lessons Learned
- The incident demonstrated the vulnerability of critical IT infrastructure supporting both online commerce and in-store operations (contactless payments).
- The reliance on external experts was immediate and necessary for incident management.
## Recommendations
- Conduct a thorough forensic investigation to determine the initial access vector and scope of data compromise.
- Review and segment networks supporting e-commerce platforms from critical in-store processing systems to limit blast radius.
- Enhance monitoring capabilities for internal processes, especially around payment gateways and point-of-sale systems.