Few things feel more routine than tapping your card for a grocery run or a new shirt. But in April 2025, M&S customers across the UK found their contactless payments and online orders suddenly grinding to a halt — the visible symptom of a sophisticated cyber attack that would ultimately cost the retailer £101 million in direct losses and expose personal customer data. What started as quiet system glitches soon became a full-blown ransomware crisis linked to the notorious hacking group Scattered Spider, and the fallout is still being felt today.
Direct financial loss (BBC): £101 million ·
Total estimated impact (including lost revenue): Hundreds of millions of pounds ·
Online sales disruption: Several weeks ·
Attacker group: Scattered Spider ·
Customer data compromised: Yes (personal data taken) ·
Recovery timeline: Ongoing, several months
Quick snapshot
- M&S disclosed a cyber incident in April 2025 (The Sun, UK news outlet)
- Attack disrupted contactless payments and online sales (Al Jazeera, international news)
- Personal customer data was taken (The Sun, UK news outlet)
- Direct loss of £101m (BBC, UK public broadcaster)
- Reportedly expected to hit annual profits by around £300 million (CM-Alliance, security consultancy)
- Rival Next saw sales boost during disruption (BBC, UK public broadcaster)
- Attributed to Scattered Spider group (The Guardian, UK newspaper)
- Used social engineering and ransomware (Al Jazeera, international news)
- Targeted service desk and Active Directory (HotMinute, security analysis blog)
- Check if your data was exposed — M&S is contacting affected customers (ICO, UK data regulator)
- Understand your rights under UK data protection law (ICO, UK data regulator)
- Consider filing a compensation claim if you suffered distress or loss (ICO, UK data regulator)
Six key facts give a quick overview of the incident’s core details.
| Label | Value | Source |
|---|---|---|
| Date of incident disclosure | April 2025 | The Sun |
| Attacker group | Scattered Spider | The Guardian |
| Data compromised | Personal customer data (not shared per M&S) | The Sun |
| Direct financial loss (BBC) | £101 million | BBC |
| Operational disruption | Weeks of online and in-store payment issues | Al Jazeera |
| Recovery status | Ongoing as of late 2025 | CM-Alliance |
What happened in the M&S cyber attack?
Timeline of the attack
- Problems first appeared around , with contactless payments and Click & Collect failing in stores (The Sun, UK news outlet).
- M&S publicly confirmed the cyber incident on and said it was managing the issue with external cybersecurity experts (The Sun).
- On , M&S suspended all online clothing and home orders (Al Jazeera, international news).
- By , media and cybersecurity reports linked the attack to the hacking group Scattered Spider (The Guardian, UK newspaper).
- Some analysis suggests the initial breach may have occurred as early as February 2025, well before public disruption became visible (Threatpedia Wiki, cybersecurity wiki).
Initial disclosure and impact
M&S notified the UK National Cyber Security Centre and the Information Commissioner’s Office during the incident response (The Sun). The retailer’s official statement confirmed that personal customer data had been taken but stated there was no evidence it had been shared. The attack also disrupted additional in-store and back-office services beyond online sales and payments (The Guardian).
How did the M&S cyber attack cost £300m and help Next?
Direct costs vs. lost revenue
In November 2025, the BBC reported that M&S profits were nearly wiped out, with a direct loss of £101 million (BBC, UK public broadcaster). Cybersecurity analysis from CM-Alliance, a security consultancy, estimates that daily online-sales losses during the disruption ran at about £3.5 million per day. When remediation, lost revenue, and reputational damage are added, some sources put the total financial impact at over £300 million (Threatpedia Wiki, cybersecurity wiki). This aligns with the PAA question that references a £300m figure, though the exact breakdown remains unconfirmed by M&S itself.
How rivals like Next benefited
The disruption to M&S’s online operations created an opening for competitors. According to the BBC, rival retailer Next saw a measurable increase in sales during the period M&S was unable to fulfil online orders (BBC, UK public broadcaster).
M&S’s pain became Next’s gain — but the vulnerability that made it possible (a compromised service desk) could affect any retailer. The sector’s interconnectivity means one breach can reshape the competitive landscape overnight.
What has happened to M&S online?
Disruption to online orders
M&S suspended online clothing and home orders on , leaving customers unable to buy from the retailer’s core e‑commerce channel (Al Jazeera, international news). In-store contactless payments also failed, forcing shoppers to use chip-and-PIN or cash. Logistical backlogs built up as click-and-collect orders went unfulfilled (The Sun, UK news outlet).
Restoration of services
M&S began restoring services in May 2025, but full recovery took several months. The company engaged external cybersecurity experts to help bring systems back online securely (The Sun). As of late 2025, operational recovery was still ongoing, with some internal processes yet to be fully restored (CM-Alliance, security consultancy).
For a retailer like M&S, which relies on a seamless omnichannel experience, weeks of online downtime translates directly into lost customer trust and revenue. Every day offline costs market share that may never return.
Who committed the M&S cyber attack?
Scattered Spider group
The attack has been attributed to the hacking group known as Scattered Spider (The Guardian, UK newspaper). This group is notorious for using social engineering techniques to gain initial access to corporate networks, often targeting service desks and IT support teams. They have been linked to previous attacks on major organisations, including Caesars Entertainment and other high‑profile victims (Al Jazeera, international news).
Modus operandi of the attackers
According to post-incident analysis, the attackers gained access by impersonating an M&S employee during a call to the company’s third‑party IT service desk, successfully resetting a password (HotMinute, security analysis blog). The initial intrusion is believed to have occurred around . Once inside, they escalated privileges through Active Directory, deployed DragonForce ransomware, and exfiltrated personal customer data (Al Jazeera).
The attack vector — a compromised service desk — is a vulnerability that exists in nearly every large organisation. One convincing phone call can undo years of perimeter security. For IT leaders: verify every password reset request with a second factor.
What is the root cause of the Marks and Spencer hack?
Compromised service desk accounts
The root cause centres on the attackers’ ability to compromise the service desk. By impersonating an M&S employee, they tricked a third‑party IT support agent into resetting a password, giving them a foothold in the corporate network (HotMinute, security analysis blog). This social‑engineering tactic is a hallmark of Scattered Spider’s playbook.
Active Directory vulnerabilities
Once inside, the attackers exploited weaknesses in M&S’s Active Directory environment to escalate privileges and move laterally across systems (HotMinute). Active Directory misconfigurations are a common vector for such privilege escalation, allowing attackers to gain domain‑admin level access and deploy ransomware across the entire network.
The implication is clear: identity and access management must be treated as a primary security pillar, not an afterthought. MFA alone would not have prevented the initial password reset, but step‑up authentication and strict service‑desk verification protocols could have blocked the breach at the front door.
Timeline of the M&S cyber incident
- February 2025 (speculative): Initial breach may have occurred, according to some cybersecurity analysis (Threatpedia Wiki, cybersecurity wiki).
- c. 17 April 2025: Attackers gain access via service‑desk impersonation (HotMinute, security analysis blog).
- 21 April 2025: M&S confirms cyber incident; contactless payments and Click & Collect fail (The Sun, UK news outlet).
- 25 April 2025: All online clothing and home orders suspended (Al Jazeera, international news).
- 29 April 2025: Attack attributed to Scattered Spider (The Guardian, UK newspaper).
- May 2025: Services begin to be restored; data breach confirmed (The Sun).
- November 2025: BBC reports direct loss of £101m (BBC, UK public broadcaster).
- Late 2025: Recovery still ongoing (CM-Alliance, security consultancy).
Confirmed facts vs. what remains unclear
Confirmed facts
- M&S disclosed a cyber incident in April 2025 (The Sun).
- Personal customer data was taken (The Sun).
- Scattered Spider was the attacker group (The Guardian).
- Direct financial loss of £101m (BBC).
- Service desk and Active Directory were compromised (HotMinute).
- M&S notified the NCSC and ICO (The Sun).
What’s unclear
- Exact total financial impact — some sources cite £300 million including lost sales (Threatpedia Wiki).
- Number of affected customers — not disclosed by M&S.
- Whether M&S paid a ransom — no confirmation.
- Full extent of data stolen — types of personal data not detailed.
- Whether the initial breach occurred as early as February 2025 (Threatpedia Wiki).
- Exact method of impersonation used on the service desk.
What the experts say
“The nature of the incident means that some personal customer data has been taken, but there is no evidence that it has been shared.”
— M&S official statement (The Sun)
“M&S profits almost wiped out after cyber hack hit sales, costing £101m.”
— BBC News
“The retail giant fell victim to a significant cyber-attack attributed to the hacking group known as Scattered Spider.”
— HotMinute, security analysis blog
For UK retailers, the lesson is brutal: a single compromised service desk call can cascade into a £100m‑plus crisis. The decision to invest in robust identity verification and employee training is no longer optional — it is the difference between a secure operation and a catastrophic breach that hands market share to competitors. Understanding phishing links and other social‑engineering tactics is a baseline defence every organisation must prioritise.
Can I claim for the M&S data breach?
Eligibility for compensation
Under UK data protection law (UK GDPR and the Data Protection Act 2018), individuals may be entitled to compensation for material damage (financial loss) and non‑material damage (distress) resulting from a personal data breach (ICO, UK data regulator). M&S has not confirmed a mass payout scheme, but affected customers who have suffered specific harm — such as identity theft, fraud, or significant distress — could pursue a claim. The ICO has been notified and may investigate the breach for regulatory action.
Steps to file a claim
- Check if you were affected: M&S is contacting customers whose data was compromised. If you haven’t been contacted but suspect exposure, contact M&S directly.
- Gather evidence: Keep records of any suspicious activity on your accounts, identity theft attempts, or financial losses incurred.
- Seek legal advice: Data breach claims are often handled by solicitors specialising in privacy law. Many offer no‑win‑no‑fee arrangements.
- File a complaint with the ICO: If M&S does not respond adequately, you can escalate to the Information Commissioner’s Office (ICO, UK data regulator).
Understanding how attackers gain initial access is critical for preventing future incidents. For a deeper look at one of the primary methods, read our guide on what a MAC address is — a fundamental building block of network identification that can be misused in lateral movement.
csc.gov.im, linkedin.com, briefing.today, blog.2bacademy.in, nquiringminds.com, hoit.uk
Frequently asked questions
What type of personal data was stolen in the M&S breach?
M&S has not published a detailed breakdown. Their official statement said “personal customer data” was taken but there is no evidence it has been shared. This likely includes names, addresses, and contact details, but the full scope remains unclear.
Did M&S pay the ransom to the attackers?
M&S has not confirmed whether a ransom was paid. Ransom payments are a sensitive operational decision, and companies rarely disclose them. There is no public evidence of a payment.
How did M&S notify customers about the data breach?
M&S said it would contact affected customers directly. They also notified the National Cyber Security Centre and the Information Commissioner’s Office as part of regulatory compliance.
What is Scattered Spider and what other attacks have they done?
Scattered Spider is a hacking collective known for social engineering, SIM swapping, and ransomware attacks. They have been linked to breaches at Caesars Entertainment, MGM Resorts, and other large organisations. Their tactics often involve impersonating employees to reset passwords.
How can I check if my M&S data was exposed?
Check your email and postal mail for a notification from M&S. If you haven’t received one, you can contact M&S customer service to ask if your account was affected. Do not open suspicious links claiming to be from M&S — go directly to the official website.
What steps should I take to protect myself after the M&S data breach?
Monitor your bank accounts and credit cards for unusual transactions. Change your M&S account password and any other accounts that use the same password. Enable two-factor authentication where available. Be alert for phishing emails that may use your M&S data to appear legitimate.
Is M&S still vulnerable to further cyber attacks?
No organisation can guarantee absolute security. M&S has engaged external cybersecurity experts and likely strengthened its identity and access management controls. However, the stolen data remains at risk of being used for future targeted attacks against customers.
How long did it take M&S to fully recover from the attack?
Full operational recovery took several months. Online sales were restored within weeks, but deeper system restoration and remediation continued into late 2025, with some processes still ongoing.
