If they can hit Marks & Spencer, what’s stopping them from hitting you?
In May 2025, something big and unsettling happened… High street heavyweight Marks & Spencer fell victim to a serious ransomware cyberattack. It wasn’t just a ‘hiccup’. We’re talking online orders paused, in-store systems disrupted and customer data accessed. And they weren’t alone. Retailers like the Co-op and Harrods were also in the firing line.
Who was behind all of this? A ransomware group called DragonForce. (No, not the heavy metal band.)
Unfortunately, they’re a lot more sinister. This group of cybercriminals, once associated with hacktivism, now runs full time ransomware operations. They specialise in breaching large organisations and locking down systems until a ransom is paid.
The price tag of poor cybersecurity
Let’s put this into perspective. M&S reportedly lost hundreds of millions in market value after the breach. Daily online sales of roughly £3.8 million were put on hold. Analysts estimate the total financial hit could be upwards of £200 million.
Around 150GB of data was stolen by the cybercriminals, forcing M&S to shut down their systems. This led to nationwide disruptions for deliveries and click & collect orders, leaving millions of disgruntled customers. The after effects of this breach are huge, with M&S chairman, Archie Norman, expecting complete recovery by October or November this year.
But it’s not just the big numbers that matter. It’s the trust. M&S had to admit that personal data was accessed. That’s a reputational blow that money alone can’t fix.
Here’s the real takeaway for Sheffield SMEs
You might be thinking, “We’re not M&S, we’re a small business in Sheffield. Why would hackers target us?”
That’s exactly the mindset that puts local businesses at risk.
Hackers like DragonForce aren’t picky. They often rely on volume, casting a wide net with phishing emails, exploiting outdated systems and taking advantage of businesses without robust cybersecurity measures.
And here’s the kicker. Smaller businesses are easier targets. Less security. Fewer resources. Often no dedicated IT team. And unfortunately, these attacks are becoming more frequent, more sophisticated and more damaging.
What does ‘preventative IT’ really mean?
At Daffodil IT, we talk a lot about proactive, preventative IT. But what does that really mean?
It’s about stopping problems before they happen:
- Keeping your systems patched and updated.
- Using strong, multi factor authentication (MFA).
- Regularly backing up your data (and testing those backups!)
- Training your staff to spot phishing and scams.
- Monitoring your network 24/7 for suspicious activity.
In short, it’s about building your defences before someone comes knocking (or kicking) the digital door in.
Your wake up call, courtesy of DragonForce
We’re not trying to scare you, but let’s be real, the M&S attack is a wake up call for every business. Whether you’re selling Yorkshire tea or managing logistics in the Peaks.
You don’t need to have a million customers or be a household name to be a target. You just need to be online.
Let’s secure your business before it’s too late
If you’re based in South Yorkshire, Sheffield, Rotherham, Barnsley, Doncaster (or further afield!), we’re here to help. Our job is to make sure your systems are locked down and your data is protected, no matter what cybercriminals throw your way.
Get in touch for a free security audit and to find out how our team of cybersecurity experts can support your business.
Remember: cybersecurity isn’t a luxury, it’s a necessity.
Stay safe, stay secure, stay ahead.






