Marks & Spencer breach linked to Scattered Spider ransomware attack
ID: 5f2a89cb-e8fe-50f1-8493-bacaddbe9fa1
STIX ID: report--5f2a89cb-e8fe-50f1-8493-bacaddbe9fa1
Feed Name: Bleeping Computer
Marks & Spencer is experiencing ongoing outages from a ransomware attack attributed to threat actors linked to the Scattered Spider/Octo Tempest cluster who allegedly exfiltrated the Windows domain NTDS.dit, laterally moved through the environment, and deployed the DragonForce encryptor against VMware ESXi hosts on April 24, causing disruption to contactless payments, online ordering, and warehouse operations while incident response firms including CrowdStrike and Microsoft assist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
