M&S Chairman Remains Silent on Ransom Payment Rumors

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

M&S Chairman Skirts Questions on Ransom Payment Post-Cyber Attack

In the wake of a ransomware incident that struck Marks & Spencer (M&S) in April, the company’s chairman, Archie Norman, has chosen not to divulge whether the retailer paid a ransom to regain control of its systems. This revelation came during a session with lawmakers from the Business and Trade Committee.

Key Details Surrounding the Attack

During the panel discussion, Norman emphasized that discussing specifics of M&S’s interactions with the hackers would not serve the public’s interest. "We’ve said that we are not discussing any of the details of our interaction with the threat actor," he remarked, pointing to the sensitive nature of ongoing law enforcement matters.

The Ransomware Group Behind the Attack

Norman clarified that no one from M&S had engaged directly with the attackers, a group he identified as the DragonForce ransomware gang. He noted, "We believe there was the instigator of the attack and then, believed to be DragonForce, who were a ransomware operation based, we believe, in Asia." Past reports had also associated another hacking group, Scattered Spider, with this incident.

The Uncertainty of Cyber Attacks

The nature of cybercrime often creates uncertainty. Norman explained that during an attack, it’s common not to know the identity of the attacker. "In fact, they never send you a letter signed Scattered Spider; that doesn’t happen," he stated, highlighting the unpredictable landscape of cybersecurity threats.

A Need for Mandatory Reporting

In addition to addressing the specific attack on M&S, Norman advocated for a stronger legal framework around cyberattack reporting. He expressed concern that two significant cyber incidents involving large British companies had recently gone unreported. "Quite a large number never get reported," he stated, stressing the importance of transparency in such critical matters.

He proposed that businesses of a certain size should have a legal obligation to report material cyberattacks to the National Cyber Security Centre (NCSC) within a defined timeframe. "I don’t think it would be regulatory overkill to say if you have a material attack…you are required within a time limit to report those to the NCSC," he asserted.

Implications for UK Businesses

Norman’s comments have stirred discussions about the current state of cybersecurity in the UK. With increasing reports of cyberattacks affecting various sectors, many experts agree that standardized reporting could enhance the overall security posture of British businesses. Implementing such regulations might encourage better preparedness, response strategies, and sharing of information across industries.

Conclusion

While Marks & Spencer remains tight-lipped about the specifics surrounding the ransom payment, the broader implications of the incident highlight significant gaps in cybersecurity reporting and preparedness among UK firms. As threats like those from DragonForce and Scattered Spider loom, strengthening legal frameworks around reporting could be a crucial next step in protecting businesses and consumers alike.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Finnish Appeals Court Revives Prosecution of Eagle S Officers for Subsea Cable Damage

A Finnish appeals court has revived the prosecution of three senior officers of the Eagle S, a Russia-linked oil tanker, for severing multiple subsea...

OpenAI’s Postmortem Reveals Gaps in Security Oversight Before Hugging Face Hack

Security Oversight Gaps Identified in OpenAI's Postmortem OpenAI's recent postmortem regarding the Hugging Face hack has revealed significant lapses in security oversight prior to the...

Veeam to Showcase Cyber Recovery and AI Solutions at LEAP 2026 in Saudi Arabia

Veeam is set to showcase its advanced cyber recovery and artificial intelligence solutions at LEAP 2026 in Saudi Arabia, marking its sixth consecutive year...

TeamViewer security advisory AV26-852 warns of vulnerabilities across multiple products

Advisory Number: AV26-852 Date: August 26, 2026 TeamViewer Vulnerabilities Identified As of August 26, 2026, TeamViewer has reported vulnerabilities affecting several of its products. The affected software...