Enterprise reporter & Cyber correspondent

Some Marks & Spencer (M&S) shops have been left with empty meals cabinets because the retailer continues to battle with a cyber assault affecting its operations.
On-line orders have been paused on the corporate’s web site and app since Friday, following issues with contactless pay and Click on & acquire over the Easter weekend.
The BBC understands meals availability needs to be again to regular by the tip of the week.
In the meantime, safety consultants say a cyber crime group calling itself DragonForce is behind the mayhem.
The comparatively new group is anticipated to be asking the grocery store for a multi-million pound ransom to deliver the cyber assault to an finish.
The BBC has requested M&S for remark.
“Primarily based on monitoring of community exercise and ransomware teams, M&S are coping with a ransomware gang who’re making an attempt to extort them,” mentioned safety researcher Kevin Beaumont.
Like all ransomware gangs, DragonForce makes use of malicious software program to scramble the information on as lots of their victims computer systems as attainable. Additionally they normally steal as a lot confidential data as they’ll to make use of it as a bargaining chip.
DragonForce began attacking victims worldwide round August 2023.
It really works on what is called a “ransomware as a service” mannequin, that means that any cyber felony can hire the malicious software program to contaminate victims’ techniques so long as they offer DragonForce a lower.
It is not identified who the person hackers accountable for the M&S hack are however some consultants are pointing in direction of a loosely run group referred to as Scattered Spider.

Noticeable shortages
It isn’t clear how widespread the empty cabinets are however the retailer confirmed “pockets of restricted availability in some shops”.
The disruption in provide has come about as a result of the agency has needed to take a few of its food-related techniques offline. It’s utilizing totally different processes to enhance availability, so it might probably function as usually as quickly as attainable.
In M&S’s Marble Arch retailer in central London, indicators on a few of the meals cabinets that had been lacking objects mentioned: “Please bear with us whereas we repair some technical points affecting product availability.”
Dot, 52, who retailers at M&S usually, mentioned a few of the cabinets had been fairly empty.
“I used to be searching for my favorite biscuits and could not discover them,” she mentioned.
Ken, 76, additionally mentioned the restricted inventory was “positively noticeable”, though the employees had been “completely charming” contemplating the cyber assault.
The agency can be managing disruption to a small proportion of merchandise that it provides to Ocado, which delivers M&S on-line orders and which is part-owned by M&S.
Though points with contactless pay, Click on & Accumulate and present playing cards have since been resolved, clients can nonetheless not place on-line orders.
A couple of third of M&S’s clothes and family items gross sales within the UK are via its on-line platforms and had been value some £1.2bn, in line with its newest monetary outcomes.
Though its share worth was up barely on Tuesday morning, it has fallen 4.6% over the past 5 days – with a notable dip on Friday when the agency introduced it was stopping online orders.
‘Like reducing off a limb’
The issues come throughout a busy retailing interval, as clients put together for the great climate and buy out of doors backyard gear, barbecue objects and celebration meals.
The aftershocks of the cyber assault will dent its earnings, analysts have told the BBC, as many shoppers go elsewhere to buy as an alternative.
Stopping on-line orders was “virtually like reducing off considered one of your limbs”, mentioned Nayna McIntosh, former government committee member of M&S and the founding father of Hope Trend.
“It’s going to have been a really tough resolution to have made on Friday and because it enters into its second week for them nonetheless to be there can be extremely painful,” she informed the BBC.
However she added that M&S was a well-liked model so clients had been probably to provide it some leeway so long as they’ve transparency.
M&S has not disclosed the character of the cyber assault.
“As a part of our proactive administration of the incident, we took a choice to take a few of our techniques briefly offline,” a spokesperson mentioned.
“In consequence, we at the moment have pockets of restricted availability in some shops. We’re working arduous to get availability again to regular throughout the property.”
M&S isn’t the one agency to undergo disruption to its on-line techniques in current instances. Grocery store Morrisons faced problems with its Christmas order in 2024, whereas banks Barclays and Lloyds had been hit by outages earlier in 2025.
Further reporting by Shakira Abdi