Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
British retail giant Marks & Spencer (M&S) recently made headlines as it fell victim to a sophisticated cyber attack. Its operations were disrupted and online services halted. This inflicted significant financial and reputational damage to the retailer. The breach, attributed to the hacking group Scattered Spider, serves as a stark reminder of the escalating cyber threats facing organisations worldwide.
M&S has reportedly faced losses to the tune of £1billion due to this devastating attack. It has also, apparently, shed over 12 per cent of its value or £1.05billion since the hack on Easter weekend.
We’ve captured everything that took place in this headline-making cybersecurity incident in our Marks & Spencer Cyber Attack Timeline and Visual Summary Image.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
In April 2025, Marks & Spencer (M&S) was hit by a major cyber attack that disrupted its operations for weeks. The retailer was forced to pause online and app orders, suspend Click & Collect and contactless payments, and move some internal systems offline. Stores stayed open but faced empty shelves in places. M&S later confirmed that customer personal data had been stolen, and estimated the attack would reduce its annual profits by around £300 million. It is widely regarded as one of the most damaging cyber attacks ever suffered by a UK retailer.
The disruption began over the Easter weekend, with problems to contactless payments and Click & Collect first appearing around 21 April 2025. M&S publicly disclosed the incident to the London Stock Exchange on 22 April 2025. Online orders were paused from 25 April, customer data theft was confirmed on 13 May, and M&S said online disruption would continue into July 2025 as it restored services. Reporting later indicated the attackers may have first gained access as early as February 2025.
Reporting linked the attack to a hacking collective known as Scattered Spider (also tracked by Microsoft as Octo Tempest), using ransomware from a group calling itself DragonForce. Security experts noted that, unlike many ransomware crews, Scattered Spider’s members appear to be native English speakers, which aids their social-engineering tactics. M&S did not formally name the group, and some attribution remained based on expert assessment and media reporting rather than official confirmation.
According to M&S and multiple reports, the attackers did not break through M&S’s own digital defences directly. Instead they used social engineering against a third-party contractor, reportedly Tata Consultancy Services (TCS), which managed M&S’s help desk, phishing employees and using their stolen login credentials to gain access. Reporting suggested attackers may have been in the systems for a period before the disruption surfaced. CEO Stuart Machin described the entry point as relating to ‘human error’ rather than under-investment.
Yes. On 13 May 2025, M&S confirmed that customer personal data had been stolen, with reporting indicating up to around 9.4 million online customers could be affected. M&S stressed that the stolen data did not include usable payment or card details, or account passwords, and said there was no evidence the information had been shared. As a precaution, customers were prompted to reset their account passwords. M&S notified the NCSC and the relevant data protection authorities.
M&S estimated the attack would hit its annual profits by around £300 million, roughly a third of its profit, before any insurance recovery. During the disruption, reporting put lost online sales at tens of millions of pounds, with one expert estimate of around £3.5 million per day, and more than £1 billion was at one point wiped from M&S’s stock-market value. Reports also indicated M&S could file a cyber-insurance claim of up to around £100 million.
Reporting indicated that M&S did have cyber insurance in place and could file a claim of up to around £100 million, though the company itself said any pay-out would only partly cover the estimated £300 million profit impact. Coverage was noted as a point of contrast with some other affected UK retailers, which were reported to have had little or no cyber insurance.
M&S did not confirm whether a ransom was demanded or paid. CEO Stuart Machin declined to comment on any ransom demand, citing advice from government agencies and law enforcement. No verified ransom payment by M&S was confirmed in public reporting.
The disruption lasted well over a month. Online and app ordering was paused from late April, and M&S said services would continue to be disrupted through June and into July 2025 as it restarted and ramped up operations. The company moved affected systems offline, engaged external cybersecurity specialists — reported to include CrowdStrike, Microsoft and Fenix24 — and worked with the NCSC, the Metropolitan Police Cyber Crime Unit and the National Crime Agency.
M&S disclosed the incident to the London Stock Exchange, engaged external cybersecurity experts, and proactively took systems offline to contain the attack and protect customers, colleagues and suppliers. It reported the breach to the NCSC and data protection authorities, paused online orders, kept customers updated through public statements, and prompted password resets as a precaution. Law enforcement, including the Metropolitan Police and National Crime Agency, investigated the incident.
Scattered Spider is a financially motivated cybercrime collective (tracked by Microsoft as Octo Tempest) known for sophisticated social engineering rather than purely technical exploits. Its members are reported to be native English speakers, which helps them convincingly impersonate staff or IT helpdesks and trick employees into resetting passwords or multi-factor authentication. The group has been linked to attacks on several UK retailers, making it a key example of why human-focused defences and helpdesk verification matter.
The M&S attack shows that strong technical defences can be bypassed through a third party and human error, and that the fallout, lost sales, a falling share price, stolen customer data and reputational damage, can run into hundreds of millions. The key lessons are managing third-party and supply-chain risk, hardening IT helpdesk and identity-verification processes against social engineering, and rehearsing the response in advance. Cyber Management Alliance helps organisations build this resilience through incident response planning, playbooks, cyber crisis tabletop exercises and staff awareness training.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.