Skip to main content

B2B Blog     |     Resources

How the Marks & Spencer Cyberattack Revealed a New Era of Social Engineering

An investigation into the Scattered Spider attack—
and why reducing your human attack surface may matter more than recognizing the next phishing email.

Keegan Henckel-Miller

July 24, 2026
14 Minute Read
Part I

Reconstructing the
Marks & Spencer Cyberattack


Easter weekend 2025 had just begun at Marks & Spencer. 
Store associates straightened the spring displays before the first customers arrived. Easter treats were stacked neatly onto shelves. Elsewhere, IT support staff settled into their desks and put on their headsets, ready for another day’s queue of forgotten passwords, locked accounts, and routine support requests.

Then, somewhere inside the company, someone answered what sounded like another routine support request. Nothing about the conversation suggested it would become the first domino in one of the most destructive cyberattacks in the company’s history.

In the days that followed, one of Britain’s most iconic retailers ground to a halt. Online orders stopped. Distribution systems faltered. Some stores struggled to keep shelves stocked. What began as a single compromised account spread into a company-wide crisis that would ultimately cost Marks & Spencer hundreds of millions of pounds. For customers, the attack wasn’t visible as lines of malicious code. It looked like empty shelves, unavailable orders, and a retailer that suddenly couldn’t keep its promises. Inside the company, teams were still trying to understand what they were looking at.

As investigators pieced together what had happened, they eventually identified one of the attack’s earliest confirmed events: 
an employee’s password had been reset by the IT help desk. 
Once inside, the attackers expanded their access before eventually disrupting systems across the company.

The password reset wasn’t what crippled Marks & Spencer. It was simply the moment the attackers were invited inside. Everything that followed happened after the front door had already been opened.

The breach, in sequence

The visible crisis lasted days. The attack itself began weeks earlier.


Weeks before

Reconnaissance. Employee IDs, addresses, start dates, and internal terminology are quietly assembled from public sources.

Easter weekend

The call. A routine-sounding request reaches the IT help desk. An employee’s password is reset.

Days after

Expansion. Access spreads from a single account into systems across the company.

Weeks after

Disruption. Online orders stop, distribution falters, and losses climb into the hundreds of millions of pounds.

It was the first real break in the case. But while it answered one question—how did the attackers gain access to the network?—it immediately raised another: how did a complete stranger convince someone inside Marks & Spencer to hand them the keys to a billion-pound empire?

There is no public transcript of that help desk call. No official reconstruction of the conversation. No single moment to point to and say, “This is where everything went wrong.”

So if the conversation itself is lost, how do you solve the case?

The same way every mystery gets solved: by working backward from the evidence until the picture comes into focus.

Part II

The Suspect: Scattered Spider


If you were asked to imagine the person on the other end of that phone call, there’s a good chance you would picture someone like Frank Abagnale.

The man immortalized in Catch Me If You Can became famous for impersonating airline pilots, lawyers, doctors, and federal agents while staying one step ahead of the FBI. Whether every detail of that story is true almost doesn’t matter. It’s how we’ve come to imagine the mythos of the confidence man ever since.

They’re impossibly charming. Quick on their feet. Masters of improvisation. The kind of people who can talk their way through a locked door with nothing but a wink and a smile.

At first glance, the attack on Marks & Spencer seems to fit that mold perfectly. Somewhere out there, a stranger had picked up the phone, spun a golden yarn, and convinced another human being to let them walk away with the master key.

It was a satisfying theory. But investigators still needed evidence.

Then they got their first real break.

Researchers were able to pin this attack to a pattern of similar intrusions carried out in the months leading up to the attack.

Those attacks had been publicly attributed to a cybercriminal group known as Scattered Spider. By then, the group was already well-known. They had been linked to a string of high-profile intrusions against major organizations, and unlike many ransomware groups, they weren’t known for discovering sophisticated software vulnerabilities. They were known for something much more unusual: painstaking reconnaissance, convincing impersonations, and a consistent social engineering playbook. That consistency provided something the case had lacked until now—a body of previous attacks they could study.

No recording of the Marks & Spencer call has been made public. But researchers have analyzed recordings from other Scattered Spider operations that followed the same playbook. Those recordings provide the closest window into how the interaction likely unfolded.

If the answer to the mystery was hidden somewhere inside those conversations, this was the closest anyone was ever going to get to hearing it for themselves.

While investigators pieced together the past, engineers were racing to restore the present. Store employees reverted to pen and paper where they could. Distribution teams improvised around missing systems. Shelves that should have been stocked for the Easter rush sat conspicuously empty while the company tried to understand what had actually happened.

Part III

What the Recordings Revealed


When former NSA cyber intelligence analyst Jon DiMaggio listened to recordings from attacks attributed to Scattered Spider, he expected to hear the social engineering equivalent of a virtuoso performance.

The first recording was nothing remarkable.

Someone had forgotten a password. The help desk verified their identity. The password was reset.

Then another.

Another forgotten password. Another routine verification. Another successful reset.

Then another.

What surprised him wasn’t what the callers said. It was how little they had to say. There was nothing cinematic about the conversations. They didn’t sound like scenes from Catch Me If You Can. They sounded like Tuesday morning. If you’d overheard one from the next cubicle, you probably wouldn’t have looked up.

The callers didn’t sound extraordinary. They sounded rehearsed.

They knew employee IDs. They knew employment start dates. They knew where employees lived. They understood how the help desk verified identities because they had spent weeks gathering information long before they picked up the phone. When the verification questions came, the answers didn’t require improvisation. They had already been researched.

Every conversation followed roughly the same script. A routine request. A handful of verification questions. A successful password reset. There was never a dramatic moment where trust was won. Each answer simply gave the help desk one less reason to doubt the person on the other end of the line.

If there was a magic trick, it wasn’t happening over the phone. The illusion had been constructed weeks earlier. The call was simply the final reveal.

The recordings stopped looking like performances to analyze and started looking like the culmination of a much longer story.

The question was no longer, “How did they talk their way in?”

It was, “Why did the help desk believe they belonged there in the first place?”

Part IV

How Public Information Becomes a Social Engineering Attack


Every answer helped reconstruct how the attackers got in. None of it helped Marks & Spencer reopen systems any faster, restock shelves any sooner, or recover the business it had already lost.

Investigators stopped studying the call logs and started asking a different question: Where had the answers come from?

An employee ID can appear in a leaked database. A manager’s name might be listed on LinkedIn. A home address can often be purchased from a data broker for less than the price of lunch. Job postings reveal the software a company uses. Internal terminology leaks into documentation, support forums, and public presentations.

Each answer reinforced the last. Every routine verification removed one more reason to question the caller’s identity. By the time the help desk employee reached the end of the process, there was no dramatic moment where trust had been won. It had simply accumulated.

The attackers weren’t relying on a brilliant performance to manufacture trust. They were relying on publicly available information to manufacture familiarity.

Part V

The Lesson Behind the Attack


By the time the response team had reconstructed the attack, Marks & Spencer employees had already spent weeks improvising around system failures, rebuilding operations, and counting the cost. The central mystery had been solved. But solving it had uncovered something much larger than a single retailer’s breach: the attackers hadn’t relied on an extraordinary act of persuasion. They had relied on an ordinary process that had been painstakingly optimized.

It’s tempting to walk away from stories like this with the simple lessons. People need better security awareness training. Help desk employees should ask more questions. Organizations need to be more skeptical.

But that’s not what this case actually shows. When people talk about famous confidence men like Frank Abagnale, the conversation usually ends with the same conclusion: people are gullible. The real lesson is almost the opposite: People trust for good reasons.

Everyone develops a code for navigating a world that contains deception—a set of instincts for where to place their trust and where to remain skeptical. You can shrink the first bucket and expand the second, but you can never eliminate trust entirely. As long as people need to trust one another to get work done, there will always be an opportunity for someone to exploit that trust.

 

There’s a lot of money in this game. That means attackers have every incentive to invest in making themselves look legitimate long before they ever make contact.

Telling people not to fall for social engineering is a little like telling a baseball player not to swing at pitches outside the strike zone. The pitcher’s entire job is to make a bad pitch look like a good one. They wouldn’t be pitching professionally if they weren’t exceptionally good at it.

That’s why the Marks & Spencer breach ultimately points somewhere much larger than a single help desk call.

If attackers can manufacture familiarity from publicly available information, then every exposed employee record, every data broker listing, and every piece of organizational metadata becomes another piece of reconnaissance that enables the next social engineering attack.

If the problem is that people are gullible, the solution is better training.

But if the problem is that attackers can manufacture legitimacy from the information we’ve already left lying around, then the case has been pointing toward a different solution all along.

Part VI

Human Attack Surface Management


We began this investigation with a simple question: How did a complete stranger convince someone inside Marks & Spencer to hand them the keys to a billion-pound empire?

The answer turned out to be surprisingly simple.

They didn’t.

They didn’t persuade the help desk to trust them. They systematically removed every reason not to.

Each piece of publicly available information became another piece of currency that could be exchanged for one less question, one less hesitation, one less reason to stop the call. By the time the phone rang, the attackers had accumulated enough of it that there was almost nothing left to doubt.

This revelation points toward a broader conclusion. For years, organizations have treated social engineering primarily as a training problem: teach employees to recognize deception, ask better questions, and become more skeptical. Those remain important defenses. But they focus on the moment the attack begins.

The Marks & Spencer breach suggests the attack began much earlier.

It began while attackers were assembling the reconnaissance needed to impersonate an insider using information the organization had already left exposed.

That’s the idea behind Human Attack Surface Management (HASM). Rather than asking only, “How do we help employees recognize increasingly sophisticated social engineering?” HASM asks a different question: “How do we make those attacks dramatically harder to construct in the first place?”

Organizations can’t function without trust. In lieu of eliminating trust, the solution is to reduce the raw material attackers use to manufacture credibility before they ever make contact.

That means reducing the information attackers rely on to execute social engineering attacks: removing exposed personal information from data brokers, limiting unnecessary employee information across public sources, and identifying organizational details that reveal reporting structures, internal systems, and authentication processes.

None of those steps prevent social engineering outright. Nothing can. What they do is change the economics of the attack.

Every employee profile removed, every outdated data broker listing deleted, and every unnecessary piece of organizational metadata taken offline deprives attackers of the intelligence they need to build convincing social engineering pretexts. Instead of handing attackers the ingredients for trust, organizations force them to spend more time, gather more intelligence, accept greater uncertainty, and take greater risks before they ever place the call.

The goal isn’t to eliminate trust.

The goal is to make social engineering attacks significantly harder to execute by denying attackers the information they need to earn that trust.