When Marks & Spencer disclosed a ransomware attack in April 2025, it sent shockwaves through the retail sector. A year later, the financial fallout is becoming clearer: £136 million in direct cleanup costs, with estimates placing the total impact north of £300 million when lost sales are factored in.

Direct cost: £136m · Estimated total loss: £300m · Profit impact: almost wiped out · Data compromised: customer names, addresses, emails, phones · Attack type: ransomware

Quick snapshot

1Confirmed facts
2What’s unclear
  • Whether M&S paid any ransom to decrypt systems
  • Exact volume of customer records exfiltrated
  • Full technical details from the forensic investigation
  • How much of the £300 million estimate is confirmed versus projected
3Timeline signal
  • Initial breach via social engineering (April 2025)
  • Ransomware deployed on VMware ESXi servers (April 21–22, 2025)
  • Public disclosure via London Stock Exchange filing (April 22, 2025)
  • Online orders halted April 25, resumed June 12, 2025
4What’s next
  • Full recovery projected by March 2026
  • Cost-cutting target increased to £600 million
  • NCSC guidance issued on help desk security
  • Retail sector facing 34% rise in cyberattacks

Key facts at a glance

Label Value
Attack date Early 2025
Type Ransomware
Compromised data Names, addresses, emails, phones
Direct cost £136m
Profit impact Almost wiped out
Status Recovery ongoing

What caused the M&S cyber-attack?

The attack began not with sophisticated malware, but with something far simpler: a phone call. According to technical analysis, the initial breach occurred in February 2025 when attackers used social engineering techniques against a third-party help desk, resetting credentials and disabling multi-factor authentication to gain a foothold (The Web People, security analysis firm). This allowed the intruders to move quietly through M&S systems for weeks before activating ransomware.

“The UK National Cyber Security Centre subsequently issued guidance specifically addressing help desk security risks following the incident.”

— NCSC guidance document

Root cause details

Once inside, the attackers targeted Active Directory — specifically exfiltrating the NTDS.dit file, which contains password hashes for the entire network. They cracked these hashes offline, enabling lateral movement across systems with legitimate credentials (The Web People, security analysis firm). This technique is particularly insidious because it generates no security alerts — the traffic looks like ordinary authentication.

Service Desk and Active Directory vulnerabilities

The UK National Cyber Security Centre subsequently issued guidance specifically addressing help desk security risks following the incident. The case highlighted how third-party service desks represent a significant attack surface — they often have elevated privileges but receive less security scrutiny than internal IT teams.

Bottom line: The M&S breach wasn’t a failure of advanced security technology. It was a failure of process — specifically, a help desk that could be manipulated over the phone to grant outsiders the keys to the kingdom.

What happened in the Marks & Spencer cyberattack?

The attack moved into its public phase on April 21–22, 2025, when DragonForce ransomware was deployed across VMware ESXi servers, rendering critical systems inoperable (The Web People, security analysis firm). M&S disclosed the cyber incident that same day via a filing to the London Stock Exchange — a move that immediately sent the retailer’s shares lower.

Attack discovery

Customer complaints about gift cards and order issues had begun appearing in early April, but the true scale of the problem only became apparent when M&S’s systems began failing. By April 23, the company publicly announced delivery delays and halted contactless payments — visible signs that internal systems had been compromised (TenIntel, threat intelligence firm). The attack was later attributed to Scattered Spider (also tracked as UNC3944 or Octo Tempest), a group known for targeting retail and hospitality firms (Technical Analysis video).

Immediate impacts

Online orders were halted on April 25, 2025, and would not resume until June 12, 2025 — a 48-day blackout that analysts estimate cost around £3.8 million per day in lost e-commerce revenue (Codekeeper, financial analysis). Click-and-collect services remained unavailable until August 2025 (Breached Company, cybersecurity news). Warehouse management systems were also disrupted early in the response, affecting the supply chain (The Register, tech news outlet).

Bottom line: For nearly two months, one of Britain’s most recognizable retailers could not process online orders — a commercial paralysis that competitors like Next likely capitalized on.

How much did M&S lose due to a cyber-attack?

The financial damage has been substantial. M&S pegged total cleanup costs at £136 million, with £83 million spent on immediate response and recovery alone (The Register, tech news outlet). Of this, £101.6 million was charged in the first half of 2025, with an expected £34 million more in the second half. The retailer claimed the maximum £100 million available on its cyber insurance policy to offset these costs.

“The first half of the year was an extraordinary moment in time for M&S, but it is now getting back on track.”

— Stuart Machin, M&S CEO

Direct costs

When all financial impacts are tallied — lost sales, cleanup expenses, and operational disruption — the total incident cost reaches closer to £300 million despite the £100 million insurance payout (SysGroup, IT services provider). Lost sales from the attack are estimated at £324 million (Breached Company, cybersecurity news).

Profit plunge details

The profit impact was dramatic. First-half profits plummeted from £391.9 million to just £3.4 million — a collapse directly attributed to the attack (Codekeeper, financial analysis). For the six months to September 27, 2025, overall profits fell 55.4% to £184.1 million. Fashion and beauty sales dropped 16.4%, while international sales fell 11.6% due to the disruption.

The gap

Insurance covered only one-third of the total estimated damage. M&S absorbed roughly £200 million in net losses — a figure that underscores the limitations of cyber insurance as a standalone defense.

Did M&S recover from a cyber-attack?

M&S is recovering, but the road has been long. Online operations fully resumed by June 2025, and the company projected complete financial recovery by March 2026. CEO Stuart Machin described the first half of 2025 as “an extraordinary moment in time for M&S,” but noted the company was “now getting back on track” (The Register, tech news outlet).

One year update

A year on from the April 2025 disclosure, M&S has worked with cybersecurity firms CrowdStrike, Microsoft, and Fenix 24 on remediation and hardening. The company has increased its cost-cutting target to £600 million to offset both the attack’s financial impact and ongoing regulatory costs (Breached Company, cybersecurity news). The customer data breach — including names, contacts, birthdates, and purchase history — was confirmed via a third-party supplier and led to warnings about potential scam emails and texts (Sangfor, cybersecurity vendor).

Bounce back status

Signs of recovery are emerging. Customer data exposure was confirmed in June 2025, after which M&S issued direct warnings to affected customers (DSM Group, IT services). However, the attack remains one of the most damaging ransomware incidents in UK retail history — a distinction that carries reputational as well as financial weight.

Bottom line: M&S survived the immediate crisis and is returning to profitability, but the attack reshaped its cost structure and accelerated a cost-cutting programme that will define the company for years.

How serious is the M&S cyber-attack?

By any measure, this was a catastrophic incident for a major retailer. The combination of customer data theft, prolonged operational disruption, and financial losses in the hundreds of millions places it among the most serious cyberattacks on a UK-listed company in recent years.

Broader implications

The attack did not occur in isolation. Retail cyberattacks increased 34% in the period following the M&S incident, according to sector monitoring. Competitors like Next may have benefited from M&S’s paralysis — customer traffic that could not be served online often migrated to rival platforms. Fashion and beauty sales, which dropped 16.4%, represent categories where online presence is particularly critical.

Security lessons

The NCSC’s post-incident guidance on help desk security reflected a vulnerability that extends far beyond M&S. The use of social engineering against service desks — often a weak link between human users and corporate systems — has become a preferred entry point for ransomware groups. Active Directory compromises, where attackers steal and crack password databases offline, are particularly difficult to detect with conventional security monitoring.

The trade-off

Help desk convenience — the ability to reset passwords over the phone — directly created the attack surface. M&S’s experience suggests that every customer-facing process with elevated privileges deserves the same scrutiny as a perimeter firewall.

Confirmed facts

  • £136m direct cleanup costs
  • Customer data stolen — names, contacts, birthdates, purchase history
  • Ransomware confirmed, data encrypted and exfiltrated
  • Profit fell 55.4% in six months
  • £100m claimed on cyber insurance policy
  • Online orders halted April 25, resumed June 12, 2025
  • Attack attributed to Scattered Spider group

What’s unclear

  • Whether M&S paid ransom for decryption
  • Exact volume of customer records exfiltrated
  • Full forensic technical report details
  • Long-term insurance recovery amount

Related reading: UK supermarket challenges · UK tech alerts and security

Additional sources

cm-alliance.com

While the ransomware strike incurred £300m in total damages for M&S, their M&S recovery timeline details key milestones toward full online operations by August.

Frequently asked questions

What data was stolen in the M&S cyber attack?

Customer data stolen included names, contact details, birthdates, and purchase history. Crucially, no full card payment details were compromised — though the exposure of personal information still posed significant risks for affected customers (Technical Analysis video).

What is the latest M&S cyber attack update?

M&S is in ongoing recovery with full financial recovery projected by March 2026. The company has worked with CrowdStrike, Microsoft, and Fenix 24 on remediation, and increased its cost-cutting target to £600 million to offset attack-related losses (Breached Company, cybersecurity news).

Was TCS involved in the M&S cyber attack?

The initial breach occurred via a third-party help desk, not through Tata Consultancy Services. While TCS is a major technology partner for M&S, there is no confirmed evidence linking TCS systems to the attack vector.

What insurance covered the M&S cyber attack?

M&S claimed the maximum £100 million on its cyber insurance policy to offset the £136 million in cleanup costs (The Register, tech news outlet). The total estimated impact of £300 million means insurance covered roughly one-third of the damage.

Who is behind the M&S cyber attack?

The attack has been attributed to Scattered Spider (also tracked as UNC3944 or Octo Tempest), a threat group known for targeting retail and hospitality companies (Technical Analysis video). M&S confirmed the link to Scattered Spider in late April 2025 (Sangfor, cybersecurity vendor).

What are the security lessons from M&S ransomware?

The NCSC issued guidance on help desk security following the incident. Key lessons include hardening third-party access controls, implementing tighter monitoring on Active Directory changes, and treating social engineering resistance as a critical security requirement — not just an IT operational matter.

How has Next benefited from M&S cyber attack?

While no competitor has publicly acknowledged capitalizing on M&S’s disruption, the 48-day online blackout and 16.4% decline in fashion and beauty sales created an obvious opportunity. Customers unable to shop M&S online or find specific products likely migrated to rival platforms, with Next among the obvious beneficiaries given its overlapping product range.