When a retailer as established as Marks & Spencer suddenly goes quiet online and shelves start looking bare, it’s a signal that something serious has happened behind the scenes. The M&S cyber attack of 2025 did exactly that — knocking out payment systems, halting online orders, and ultimately costing the company an estimated £300 million in profit impact.

Sales loss reported: £101 million (BBC) ·
Estimated profit impact: £300 million (The Conversation) ·
Attacker group: Scattered Spider (Specopssoft) ·
Click & Collect return delay: 15 weeks (BBC) ·
System restoration: By June 2025 (M&S corporate)

Quick snapshot

1Confirmed facts
2What’s unclear
  • Exact ransom amount demanded or paid
  • Full extent of data compromised (M&S says no customer data exposed but unclear)
  • Whether Synnovis ransom was paid (separate attack)
3Timeline signal
4What’s next
  • M&S faces ongoing reputational recovery
  • Competitor Next gained market share during disruption
  • Retail sector reviewing third-party IT supplier risks

Seven key facts, one pattern: the attack hit M&S across every operational layer — from payment terminals to supply chain logistics.

Fact Detail
Attack disclosure date April 2025
Attacker identity Scattered Spider
Attack type Ransomware
Sales loss £101 million (BBC News)
Estimated profit hit £300 million (The Conversation)
Customer action advised No password change needed, but beware phishing
Services restored June 2025

What caused the M&S cyber attack and who was behind it?

How did Scattered Spider infiltrate M&S?

  • The attack is attributed to Scattered Spider, an English-speaking social-engineering group known for targeting large enterprises (Computer Weekly).
  • Initial access reportedly came through a third-party IT supplier — Tata Consulting Services, which ran the M&S IT helpdesk — with tech support staff credentials stolen via social engineering (Computer Weekly referencing Reuters).
  • Security analysis suggests the attackers may have gained access as early as February 2025, weeks before the main disruption (The Web People).

What was the role of ransomware?

  • The attack was ultimately confirmed as a ransomware attack that paralysed M&S online shopping systems and affected in-store services (The Web People).
  • Security researchers identified DragonForce ransomware as the malware used (The Web People).
  • M&S immediately took steps to protect its systems and engaged leading cybersecurity experts after the incident (Marks & Spencer – Cyber Update).
The catch

M&S outsourced its IT helpdesk to Tata Consulting Services — a common cost-saving move in retail. That third-party relationship became the entry point for Scattered Spider, exposing a systemic vulnerability in how retailers manage supplier security.

The implication: the M&S cyber attack wasn’t a brute-force hack — it was a targeted social-engineering operation that exploited a trusted supplier relationship, a pattern increasingly common in retail breaches.

Is M&S still under cyber attack? Latest update

What is the current status of M&S systems?

  • M&S announced that systems were restored by June 2025, with normal operations resuming (Marks & Spencer – Cyber Update).
  • There is no evidence of an ongoing attack as of the latest updates.
  • M&S reported the incident to relevant government authorities and law enforcement and continued to work closely with them (Marks & Spencer – Cyber Update).

Has M&S fully recovered?

  • M&S believed recovery could take at least another month and that the incident could cost a minimum of £300 million (Computer Weekly).
  • M&S was unable to provide contactless payment or click-and-collect services on 22 April 2025 (Computer Weekly).
  • M&S shut down online sales on 25 April 2025 while containing and mitigating the attack (Computer Weekly).
Why this matters

For a retailer that generates a significant portion of revenue through online and contactless payments, even a few days of downtime translates into millions in lost sales — and months of reputational repair.

The pattern: M&S moved from crisis containment to full recovery in roughly two months — a relatively fast timeline for a ransomware attack of this scale, but the financial damage was already done.

How much did M&S lose and how did the attack help Next?

The £300m profit hit explained

  • BBC reported that M&S profits were almost wiped out after the cyber hack hit sales, with a £101 million sales loss (BBC News).
  • The Conversation estimated the cyber-attack on Marks & Spencer will lead to an estimated £300 million hit to profits (The Conversation).
  • Computer Weekly reported that the incident could cost a minimum of £300 million (Computer Weekly).

Why did Next benefit from M&S’s misfortune?

  • Competitor Next gained market share during the disruption period as customers shifted their spending to the rival retailer.
  • M&S was unable to process online orders or in-store contactless payments for days, pushing customers to competitors.
  • The market shift highlights how operational fragility in one retailer can directly benefit a competitor in a concentrated retail sector.
The trade-off

M&S’s £300 million loss wasn’t just a cost of recovery — it was a direct transfer of market share to Next, illustrating how cyber attacks don’t just damage the target but reshape competitive dynamics.

What this means: the financial impact of the M&S cyber attack extends beyond direct recovery costs — it includes lost revenue that permanently shifted to competitors, a harder-to-quantify but equally damaging consequence.

Why are M&S shelves empty? The broader operational impact

Impact on Click & Collect and returns

  • Click & Collect returns were delayed by up to 15 weeks (BBC News).
  • M&S was unable to provide contactless payment or click-and-collect services on 22 April 2025 (Computer Weekly).
  • The disruption affected both online and in-store operations, creating a backlog of orders and returns.

Supply chain disruption

  • Shelves were reported empty due to logistical disruption caused by the IT systems outage.
  • The attack paralysed M&S online shopping systems and affected in-store services (The Web People).
  • M&S shut down online sales on 25 April 2025 while containing and mitigating the attack (Computer Weekly).
The upshot

Empty shelves weren’t a supply problem — they were a data problem. When the IT systems that manage inventory, logistics, and order fulfilment go down, physical stores grind to a halt.

The catch: M&S’s operational model — heavily reliant on integrated IT systems for Click & Collect, returns, and inventory management — became its biggest vulnerability during the attack.

Should I change my M&S password? Security advice

What action does M&S recommend?

  • M&S said: “You do not need to take any action, but be cautious of phishing” (Marks & Spencer – Cyber Update).
  • M&S said the incident did not include useable card or payment details or account passwords (Marks & Spencer – Cyber Update).
  • However, M&S was forced to reset passwords for affected customers (The Web People).

General password security tips

  • Use strong, unique passwords for each online account.
  • Enable two-factor authentication where available.
  • Be cautious of phishing emails that may reference the M&S breach.
  • The UK’s National Cyber Security Centre (NCSC – UK government cybersecurity authority) provides guidance on password security and phishing awareness.
What to watch

Even if M&S says no action is needed, the stolen personal data — contact details, date of birth, online order history, and household information — is valuable for targeted phishing campaigns. Stay alert for suspicious emails claiming to be from M&S.

The trade-off: M&S’s reassurance that “no action needed” balances customer convenience against security caution — but the safest approach is to change your password anyway and remain vigilant.

Timeline of the M&S cyber attack

  • February 2025: Attackers likely gained initial access to M&S systems via compromised third-party supplier credentials (The Web People).
  • April 2025: M&S discloses a cyberattack that severely disrupts IT systems. Contactless payments and Click & Collect services go down (Computer Weekly).
  • 25 April 2025: M&S shuts down online sales while containing and mitigating the attack (Computer Weekly).
  • 13 May 2025: M&S confirms personal customer information was breached and begins resetting customer passwords (CM-Alliance).
  • May 2025: Click & Collect returns delayed; shelves reported empty.
  • June 2025: M&S announces systems restored; normal operations resume (Marks & Spencer – Cyber Update).
  • November 2025: BBC reports £101m sales loss; The Conversation estimates £300m profit impact (BBC News).

Confirmed facts vs. what remains unclear

Confirmed facts

  • Attack attributed to Scattered Spider (Computer Weekly)
  • M&S sales loss of £101 million (BBC News)
  • Estimated £300 million profit impact (The Conversation)
  • Systems restored by June 2025 (Marks & Spencer – Cyber Update)
  • Personal data breached (contact details, order history) (Marks & Spencer – Cyber Update)
  • No payment card data or account passwords exposed (Marks & Spencer – Cyber Update)

What’s unclear

  • Exact ransom amount demanded or paid
  • Full extent of data compromised (M&S says no customer data exposed but unclear)
  • Whether Synnovis ransom was paid (separate attack)
  • Whether the attackers accessed financial systems beyond the IT helpdesk

Expert perspectives on the M&S cyber attack

“You do not need to take any action, but be cautious of phishing.”

— M&S official statement (Marks & Spencer – Cyber Update)

“The cyber-attack on Marks & Spencer will lead to an estimated £300 million hit to profits.”

— The Conversation analyst (The Conversation)

“M&S profits almost wiped out after cyber hack hit sales – £101 million loss.”

— BBC report (BBC News)

Summary: What the M&S cyber attack means for retail

The M&S ransomware attack exposed a fundamental truth about modern retail: operational resilience depends on IT security, and a single breach can cascade through every layer of the business — from payment terminals to supply chains to customer trust. For UK retailers, the choice is clear: invest in third-party supplier security audits and incident response plans, or risk becoming the next cautionary tale.

Related reading: What Is DNS Cache? · How to Update iPhone Apps

Additional sources

mti.com

For the latest on how the retailer is recovering, see the update on M&S online status after the attack.

Frequently asked questions

What is ransomware?

Ransomware is a type of malicious software that encrypts a victim’s files or systems, with attackers demanding a ransom payment to restore access. In the M&S attack, DragonForce ransomware was used to paralyse IT systems (The Web People).

How did M&S respond to the attack?

M&S immediately took steps to protect its systems, engaged leading cybersecurity experts, shut down online sales, and reported the incident to government authorities and law enforcement (Marks & Spencer – Cyber Update).

Did M&S pay the ransom?

It is unclear whether M&S paid the ransom. The exact ransom amount demanded or paid has not been disclosed.

What should M&S customers do to protect themselves?

M&S advises that no action is needed regarding passwords, but customers should be cautious of phishing emails. The stolen data includes contact details and order history, which could be used in targeted scams (Marks & Spencer – Cyber Update).

How did the attack affect M&S employees?

The attack disrupted IT systems used by employees for order processing, inventory management, and customer service. M&S engaged cybersecurity experts and worked with authorities to restore operations.

Will M&S compensate customers for the disruption?

M&S has not announced any compensation plan for customers affected by the disruption. The company focused on restoring systems and securing customer data.

How can retailers prevent similar attacks?

Retailers should conduct regular third-party supplier security audits, implement multi-factor authentication, provide cybersecurity training for staff, and develop incident response plans. The UK’s National Cyber Security Centre (NCSC – UK government cybersecurity authority) provides guidance on ransomware prevention.

Bottom line: The M&S cyber attack was a ransomware operation by Scattered Spider that exploited a third-party IT supplier, costing the retailer £101 million in sales and an estimated £300 million in profit impact. For customers: no urgent action needed, but stay alert for phishing. For retailers: third-party supplier security is now a board-level risk.