M&S believes April cyberattack was carried out by DragonForce
M&S chair Archie Norman has told MPs that the retailer believes the cyberattack which hit the business in April was carried out by ransomware group DragonForce.
Speaking to a parliamentary select committee this week, Norman said the attack was carried out by “loosely aligned parties” and suggested that DragonForce — believed to be based in Asia — was responsible for executing the breach.
M&S took a heavy financial hit to its profits following the cyberattack, with an estimated 300m in profit loss.
Norman said in a statement reported by The Independent: “The attacker is working through intermediaries too, so we believe in this case there was the instigator of the attack, and then—believed to be DragonForce—who are a ransomware operation based, we believe, in Asia.
Subscribe to Grocery Gazette for free
Sign up here to get the latest grocery and food news each morning
So you’ve got loosely aligned parties working together. We took an early decision that nobody at M&S would deal with the threat actor directly—we felt the right thing was to leave this to the professionals who have experience in the matter.”
Additionally, media reports blamed a hacking group called Scattered Spider for the attack; however, the identity of the hackers remains unknown.
Norman commented: “When this happens, you don’t know who the attacker is, and in fact, they never send you a letter signed Scattered Spider; that doesn’t happen.”
Further details on the negotiations with the hackers were not disclosed; however, Norman maintained that operations underwent significant disruptions due to the attack.
However, the high street retailer’s chief executive confirmed last week that it is on the road to recovery and expects most operations to return by August.




