Enterprise reporter & Cyber correspondent

Some Marks & Spencer (M&S) shops have been left with empty meals cabinets because the retailer continues to wrestle with a cyber assault affecting its operations.
On-line orders have been paused on the corporate’s web site and app since Friday, following issues with contactless pay and Click on & acquire over the Easter weekend.
The BBC understands meals availability needs to be again to regular by the top of the week.
In the meantime, safety specialists say a cyber crime group calling itself DragonForce is behind the mayhem.
The comparatively new group is predicted to be asking the grocery store for a multi-million pound ransom to carry the cyber assault to an finish.
The BBC has requested M&S for remark.
“Primarily based on monitoring of community exercise and ransomware teams, M&S are coping with a ransomware gang who’re making an attempt to extort them,” mentioned safety researcher Kevin Beaumont.
Like all ransomware gangs, DragonForce makes use of malicious software program to scramble the info on as a lot of their victims computer systems as doable. Additionally they normally steal as a lot confidential info as they will to make use of it as a bargaining chip.
DragonForce began attacking victims worldwide round August 2023.
It really works on what is called a “ransomware as a service” mannequin, which means that any cyber felony can hire the malicious software program to contaminate victims’ programs so long as they provide DragonForce a lower.
It is not recognized who the person hackers answerable for the M&S hack are however some specialists are pointing in the direction of a loosely run group known as Scattered Spider.

Noticeable shortages
It’s not clear how widespread the empty cabinets are however the retailer confirmed “pockets of restricted availability in some shops”.
The disruption in provide has come about as a result of the agency has needed to take a few of its food-related programs offline. It’s utilizing totally different processes to enhance availability, so it may possibly function as usually as quickly as doable.
In M&S’s Marble Arch retailer in central London, indicators on among the meals cabinets that had been lacking objects mentioned: “Please bear with us whereas we repair some technical points affecting product availability.”
Dot, 52, who outlets at M&S often, mentioned among the cabinets had been fairly empty.
“I used to be in search of my favorite biscuits and could not discover them,” she mentioned.
Ken, 76, additionally mentioned the restricted inventory was “positively noticeable”, though the workers had been “completely charming” contemplating the cyber assault.
The agency can be managing disruption to a small proportion of merchandise that it provides to Ocado, which delivers M&S on-line orders and which is part-owned by M&S.
Though points with contactless pay, Click on & Accumulate and reward playing cards have since been resolved, clients can nonetheless not place on-line orders.
A few third of M&S’s clothes and family items gross sales within the UK are by way of its on-line platforms and had been price some £1.2bn, in accordance with its newest monetary outcomes.
Though its share worth was up barely on Tuesday morning, it has fallen 4.6% during the last 5 days – with a notable dip on Friday when the agency introduced it was stopping online orders.
‘Like chopping off a limb’
The issues come throughout a busy retailing interval, as clients put together for the nice climate and buy out of doors backyard tools, barbecue objects and social gathering meals.
The aftershocks of the cyber assault will dent its earnings, analysts have told the BBC, as many shoppers go elsewhere to buy as an alternative.
Stopping on-line orders was “nearly like chopping off certainly one of your limbs”, mentioned Nayna McIntosh, former government committee member of M&S and the founding father of Hope Trend.
“It can have been a really troublesome determination to have made on Friday and because it enters into its second week for them nonetheless to be there can be extremely painful,” she informed the BBC.
However she added that M&S was a preferred model so clients had been doubtless to offer it some leeway so long as they’ve transparency.
M&S has not disclosed the character of the cyber assault.
“As a part of our proactive administration of the incident, we took a choice to take a few of our programs quickly offline,” a spokesperson mentioned.
“Consequently, we presently have pockets of restricted availability in some shops. We’re working exhausting to get availability again to regular throughout the property.”
M&S isn’t the one agency to endure disruption to its on-line programs in current instances. Grocery store Morrisons faced problems with its Christmas order in 2024, whereas banks Barclays and Lloyds had been hit by outages earlier in 2025.
Further reporting by Shakira Abdi