- M&S Chairman Archie Norman attributed the recent Rainsmare attack to the Dragon Force
- Law enforcement agencies are still included, and we do not know any details of ransom
- Norman is demanding maximum transparency and cybertack reporting
The M&S is still refusing to confirm whether it has paid a ransom after the recent major cybertack, but at least we have a signal of its purpose.
It is believed that the attack was carried out by the Dragon Force, it is believed that a renasmare operation is based in Asia or Russia.
M&S Chairman Archie Norman explained that the details of any ransom would not be revealed in the public interest, because law enforcement agencies are still involved in the matter.
You can like
M&S shares more information related to attack
“We have said that we are not discussing any details of our interaction with the danger actor,” Norman said while addressing a UK parliament on CyberTrax in the retail sector.
Now we know that the initial violation was through social engineering, the attacker has imitated the M&S worker and has cheated a third party to reset the employee’s password.
Financial times Only weeks after CyberTek revealed that Tata Consultancy Services, a third party that uses to help handle the M&S Help Desk support, could inadvertently be in violation.
The attackers threatened to leak the data obtained, but they also secreted it from the M&S, which is known as the double extortion attack. In May, M&S confirmed that the name, address dates, addresses, phone numbers, household information and order date were all included.
The M&S closed systems were reportedly stolen to prevent further spread of 150GB of data, which disrupted delivery. Recovery efforts are still underway, Norman is expected to recover from October or November 2025.
The Dragon Force has not published M&S data, possibly indicating whether the ransom can be paid or the talks are underway.
Looking forward, Norman is calling for more transparency about CyberTrax reporting: “We have the reason to believe that in the past four months there have been two major cyberrtexes on large British companies that have been reported non -reports,” he said.
By Reuters


