Cyber-Attack Timeline: Marks & Spencer

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

M&S TimeLine M&S Timeline Summary (1)

Download Our Educational Cyber-Attack Timeline: Marks & Spencer

British retail giant Marks & Spencer (M&S) recently made headlines as it fell victim to a sophisticated cyber attack. Its operations were disrupted and online services halted. This inflicted significant financial and reputational damage to the retailer. The breach, attributed to the hacking group Scattered Spider, serves as a stark reminder of the escalating cyber threats facing organisations worldwide.

M&S has reportedly faced losses to the tune of £1billion due to this devastating attack. It has also, apparently, shed over 12 per cent of its value or £1.05billion since the hack on Easter weekend.

We’ve captured everything that took place in this headline-making cybersecurity incident in our Marks & Spencer Cyber Attack Timeline and Visual Summary Image. 

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed Marks & Spencer Cyber Attack timeline document and summary.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs about the Marks & Spencer Attack

  • What happened in the Marks & Spencer (M&S) cyber attack?

    In April 2025, Marks & Spencer (M&S) was hit by a major cyber attack that disrupted its operations for weeks. The retailer was forced to pause online and app orders, suspend Click & Collect and contactless payments, and move some internal systems offline. Stores stayed open but faced empty shelves in places. M&S later confirmed that customer personal data had been stolen, and estimated the attack would reduce its annual profits by around £300 million. It is widely regarded as one of the most damaging cyber attacks ever suffered by a UK retailer.

  • When did the M&S cyber attack happen?

    The disruption began over the Easter weekend, with problems to contactless payments and Click & Collect first appearing around 21 April 2025. M&S publicly disclosed the incident to the London Stock Exchange on 22 April 2025. Online orders were paused from 25 April, customer data theft was confirmed on 13 May, and M&S said online disruption would continue into July 2025 as it restored services. Reporting later indicated the attackers may have first gained access as early as February 2025.

  • Who was behind the M&S cyber attack?

    Reporting linked the attack to a hacking collective known as Scattered Spider (also tracked by Microsoft as Octo Tempest), using ransomware from a group calling itself DragonForce. Security experts noted that, unlike many ransomware crews, Scattered Spider’s members appear to be native English speakers, which aids their social-engineering tactics. M&S did not formally name the group, and some attribution remained based on expert assessment and media reporting rather than official confirmation.

  • How did the attackers get into M&S’s systems?

    According to M&S and multiple reports, the attackers did not break through M&S’s own digital defences directly. Instead they used social engineering against a third-party contractor, reportedly Tata Consultancy Services (TCS), which managed M&S’s help desk, phishing employees and using their stolen login credentials to gain access. Reporting suggested attackers may have been in the systems for a period before the disruption surfaced. CEO Stuart Machin described the entry point as relating to ‘human error’ rather than under-investment.

  • Was customer data stolen in the M&S cyber attack?

    Yes. On 13 May 2025, M&S confirmed that customer personal data had been stolen, with reporting indicating up to around 9.4 million online customers could be affected. M&S stressed that the stolen data did not include usable payment or card details, or account passwords, and said there was no evidence the information had been shared. As a precaution, customers were prompted to reset their account passwords. M&S notified the NCSC and the relevant data protection authorities.

  • How much did the M&S cyber attack cost?

    M&S estimated the attack would hit its annual profits by around £300 million, roughly a third of its profit, before any insurance recovery. During the disruption, reporting put lost online sales at tens of millions of pounds, with one expert estimate of around £3.5 million per day, and more than £1 billion was at one point wiped from M&S’s stock-market value. Reports also indicated M&S could file a cyber-insurance claim of up to around £100 million.

  • Did M&S have cyber insurance?

    Reporting indicated that M&S did have cyber insurance in place and could file a claim of up to around £100 million, though the company itself said any pay-out would only partly cover the estimated £300 million profit impact. Coverage was noted as a point of contrast with some other affected UK retailers, which were reported to have had little or no cyber insurance.

  • Did M&S pay a ransom?

    M&S did not confirm whether a ransom was demanded or paid. CEO Stuart Machin declined to comment on any ransom demand, citing advice from government agencies and law enforcement. No verified ransom payment by M&S was confirmed in public reporting.

  • How long was M&S disrupted, and how did it recover?

    The disruption lasted well over a month. Online and app ordering was paused from late April, and M&S said services would continue to be disrupted through June and into July 2025 as it restarted and ramped up operations. The company moved affected systems offline, engaged external cybersecurity specialists — reported to include CrowdStrike, Microsoft and Fenix24 — and worked with the NCSC, the Metropolitan Police Cyber Crime Unit and the National Crime Agency.

  • How did M&S respond to the cyber attack?

    M&S disclosed the incident to the London Stock Exchange, engaged external cybersecurity experts, and proactively took systems offline to contain the attack and protect customers, colleagues and suppliers. It reported the breach to the NCSC and data protection authorities, paused online orders, kept customers updated through public statements, and prompted password resets as a precaution. Law enforcement, including the Metropolitan Police and National Crime Agency, investigated the incident.

  • What is Scattered Spider, and why is it significant?

    Scattered Spider is a financially motivated cybercrime collective (tracked by Microsoft as Octo Tempest) known for sophisticated social engineering rather than purely technical exploits. Its members are reported to be native English speakers, which helps them convincingly impersonate staff or IT helpdesks and trick employees into resetting passwords or multi-factor authentication. The group has been linked to attacks on several UK retailers, making it a key example of why human-focused defences and helpdesk verification matter.

  • What can other organisations learn from the M&S cyber attack?

    The M&S attack shows that strong technical defences can be bypassed through a third party and human error, and that the fallout, lost sales, a falling share price, stolen customer data and reputational damage, can run into hundreds of millions. The key lessons are managing third-party and supply-chain risk, hardening IT helpdesk and identity-verification processes against social engineering, and rehearsing the response in advance. Cyber Management Alliance helps organisations build this resilience through incident response planning, playbooks, cyber crisis tabletop exercises and staff awareness training.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.