It started with the small stuff. Over the Easter weekend, Marks & Spencer shoppers found contactless payments failing and click-and-collect broken; by Monday, April 21, the disruption was too widespread to ignore. On Tuesday, April 22, M&S formally disclosed a "cyber incident" to the London Stock Exchange, apologising to customers while keeping its stores open. According to later BBC reporting, attackers using the DragonForce name had emailed CEO Stuart Machin from a compromised employee account around April 23, claiming to have encrypted the company's servers — and the DragonForce encryptor was reportedly deployed on M&S's VMware ESXi hosts on April 24, two days after the public disclosure. On Friday, April 25, M&S suspended all online orders, a pause on internet clothing sales that would not lift until June 10.
The intrusion was linked by researchers and press to the Scattered Spider (UNC3944) community, who reportedly got in through social engineering of third-party IT support — no zero-day, just a convincing phone call to someone with the power to reset access. It was the template for the whole spring: attackers who understood that the softest part of a hardened company is the human at the help desk. And M&S was only the first domino — the Co-op disclosed its own intrusion on April 30, Harrods on May 1, and the British high street settled in for a siege whose full cost, £300 million to M&S alone, would only become clear the following month.
What made April feel precarious wasn't just the retail hack. It was that, the same week, the invisible scaffolding the entire security industry stands on nearly collapsed.
24 hours from losing the CVE program
Every security tool on earth speaks a common language of vulnerability IDs — CVE-2025-53770 and its millions of siblings — maintained for 25 years by the non-profit MITRE under US government contract. On April 15, a leaked MITRE letter warned that the funding contract would expire the next day. For 24 hours, the industry stared at the prospect of its shared reference catalog going unmaintained. On the morning of April 16, CISA executed an 11-month option period on MITRE's expiring contract — a contract reported at $57.8 million — averting the lapse — and, chastened, a group of CVE Board members announced the CVE Foundation to move the catalog off dependence on a single government sponsor. The vulnerability everyone had ignored was the funding model itself.
The breach ledger fills with patients
April's quieter carnage was medical. Yale New Haven Health began notifying 5,556,702 patients that their data was stolen in a March network attack — then 2025's largest US healthcare breach. Blue Shield of California disclosed that a Google Analytics misconfiguration had been quietly sharing member health data with Google Ads from 2021 to 2024, affecting up to 4.7 million people — a breach with no hacker at all. Dialysis provider DaVita found ransomware in its network on April 12 (roughly 2.7 million eventually affected), and Hertz confirmed customer data stolen via zero-days in Cleo's file-transfer software. Healthcare: data-rich, security-poor, and perennially top of the victim list.
Nippon Life India's twelve dark days
Late on April 9, 2025, Nippon Life India Asset Management — the country's fourth-largest fund house, with roughly 20 million unique investors — reported a cyberattack on its IT infrastructure and notified the exchanges the next day. The company shut down affected systems, leaving its website, investor portal, and mobile app offline for about 12 days before service was restored around April 21. Crucially, transactions stayed available through exchanges and partner platforms throughout, and no customer-data breach was reported. It was, in a sense, a model disclosure — prompt, contained, honest about the outage — but the twelve-day downtime of a major asset manager's public face was its own quiet lesson for an Indian financial sector racing to digitise faster than it hardens.
⏳ Time capsule — April 2025
- April 2 — "Liberation Day" — brought the sweeping US tariffs, with a universal 10% import levy from April 5 and weeks of market convulsions.
- Spot gold broke $3,500 an ounce for the first time ever on April 22, as trade-war fear drove a flight to safe havens.
- On April 14, Blue Origin's NS-31 flew Katy Perry, Gayle King, and Lauren Sánchez on the first all-female spaceflight since 1963.
- Pope Francis died on April 21 at 88, a day after a final Easter Sunday appearance in St Peter's Square.
The people were the perimeter
April 2025 opened the retail siege that defined Britain's cyber year, and its through-line — Scattered Spider talking past the help desk — became the single most-studied attack pattern of the era, cited in every 2026 identity-verification mandate. The CVE near-death, meanwhile, jolted the industry into treating its shared infrastructure as something that needs deliberate stewardship rather than assumed permanence, a debate still live as the CVE Foundation matures. And the month's healthcare bloodletting set a floor the sector never rose above. The lesson April taught — that the softest attack surface is a human with administrative rights, and the most fragile system is often the one everyone assumes someone else is funding — is the one our current editions keep re-proving.