You are here:

From Click to Crisis: The Cyberattack That Cost M&S £1 Billion

Marks & Spencer's April 2025 cyberattack caused major disruptions, compromising customer data and resulting in a significant financial loss and market decline.

On April 22, 2025, Marks & Spencer (M&S) disclosed a significant cyberattack that has since disrupted its operations. The breach, attributed to a ransomware hacking group led to unauthorized access to customer data, including names, contact information, and order histories. Notably, payment details and passwords were not compromised .

The financial repercussions have been substantial. M&S’s share price has declined by approximately 15% since the incident, erasing over £1 billion in market capitalization . With online sales accounting for about a third of its clothing and home revenue, the suspension of online orders has resulted in estimated losses of £4 million per day .


The Cyberattack: A Timeline of Events

  • Easter Weekend (April 19-21, 2025): M&S experienced initial disruptions in contactless payments and online services.
  • April 22: The company publicly acknowledged a cyber incident, initiating investigations and containment efforts.
  • April 25: M&S suspended online orders, affecting its website, app, and phone services.
  • May 13: M&S confirmed that personal customer data, including names, contact information, and order histories, had been compromised. Importantly, payment details and passwords remained secure.


Financial and Operational Impact

The cyberattack had profound implications for M&S’s financial health and operational capabilities:

  • Revenue Loss: Analysts estimate that the suspension of online sales resulted in losses of approximately £26 million per week in clothing and home sales, with an additional £17 million per week from affected in-store food sales and contactless payments.
  • Share Price Decline: Since the disclosure of the cyberattack, M&S’s share price has fallen by about 15%, erasing over £1 billion in market capitalization.
  • Operational Disruptions: The breach disrupted various services, including online ordering, click-and-collect, and Sparks loyalty offers. Some stores experienced stock shortages due to supply chain issues.


The Perpetrators

A ransomware group called DragonForce claimed the responsibility of the attack. This group employs social engineering tactics, such as impersonating employees and exploiting multi-factor authentication, to gain unauthorized access to systems. Similar attacks previously targeted major organizations, including MGM Resorts and Caesars Entertainment.


Lessons Learned: Strengthening Cybersecurity by establishing at least Minimum Viable Security

The M&S cyberattack serves as a stark reminder of the evolving cyber threats facing businesses today. To mitigate such risks, organizations should consider the following measures:


1. Implement Robust Identity and Access Management

  • Multi-Factor Authentication (MFA): Require MFA for all users to add an extra layer of security.
  • Regular Access Reviews: Periodically review user access rights to ensure appropriate permissions.


2. Enhance Incident Detection and Response

  • Real-Time Monitoring: Utilize security information and event management (SIEM) systems to detect anomalies.
  • Incident Response Plan: Develop and regularly update a comprehensive incident response plan.


3. Strengthen Email Security and Phishing Protection

  • Employee Training: Conduct regular training sessions to educate employees about phishing threats.
  • Advanced Email Filtering: Implement email security solutions to detect and block malicious emails.


4. Establish Data Backup and Recovery Protocols

  • Regular Backups: Perform frequent backups of critical data and systems.
  • Disaster Recovery Testing: Regularly test recovery procedures to ensure data can be restored promptly.


5. Engage with Cybersecurity Experts

  • Third-Party Assessments: Engage external cybersecurity firms to conduct security assessments, penetration testing and red team testing.
  • Stay Informed: Keep abreast of the latest cybersecurity threats and trends to adapt defenses accordingly.


Conclusion

The cyberattack on M&S highlights the critical need for proactive cybersecurity strategies. As cyber threats become increasingly sophisticated, businesses must prioritize the protection of their digital assets and customer data. By implementing comprehensive security measures and fostering a culture of cybersecurity awareness, organizations can enhance their resilience against future attacks.

Frequently Asked Questions (FAQs)

1. What happened in the Marks & Spencer cyberattack?

Marks & Spencer experienced a ransomware attack in April 2025 that disrupted online orders, contactless payments, click-and-collect services, and parts of its supply chain. The attackers also accessed certain customer information, prompting the retailer to suspend several digital services while it investigated the incident.


2. What customer data was exposed in the M&S cyberattack?

M&S confirmed that the attackers accessed customer names, contact details, dates of birth, account information, and order histories. However, payment card details, payment card verification values (CVVs), and account passwords were not compromised.


3. Who was behind the M&S cyberattack?

The attack was attributed to the ransomware group DragonForce, which reportedly used social engineering techniques to gain unauthorized access. The incident highlights how attackers increasingly target user identities rather than exploiting technical vulnerabilities alone.


4. How did the cyberattack impact Marks & Spencer?

The attack forced M&S to suspend online shopping for several weeks, disrupted in-store operations, affected customer services, and caused supply chain delays. It also resulted in significant financial losses, a decline in share price, and reputational damage.


5. Why was the M&S cyberattack so damaging despite no payment data being stolen?

Operational disruption was the biggest impact. Even without exposing payment data, the ransomware attack interrupted business-critical systems, preventing customers from placing online orders and affecting inventory, logistics, and customer experience.


6. What cybersecurity weaknesses do ransomware groups commonly exploit?

Modern ransomware groups commonly exploit stolen credentials, phishing emails, weak identity controls, compromised third-party accounts, unpatched systems, and inadequate monitoring. Identity-based attacks have become one of the most common initial access vectors.


7. How can organizations reduce the risk of ransomware attacks?

Organizations should implement multi-factor authentication (MFA), enforce least-privilege access, continuously monitor user activity, patch vulnerabilities promptly, conduct regular penetration testing, maintain offline backups, and train employees to recognize phishing attacks.


8. Why is incident response planning critical for ransomware preparedness?

A well-defined incident response plan enables organizations to quickly detect, contain, investigate, and recover from cyber incidents. Faster response reduces downtime, limits financial losses, and minimizes the impact on customers and business operations.


9. What is Minimum Viable Security (MVS)?

Minimum Viable Security (MVS) is a baseline set of cybersecurity controls that every organization should implement before investing in advanced security solutions. It includes identity protection, endpoint security, email security, vulnerability management, backup and recovery, security monitoring, and employee awareness training.


10. What can businesses learn from the M&S cyberattack?

The M&S incident demonstrates that cyber resilience is just as important as cyber prevention. Organizations should continuously strengthen identity security, test their defenses through security assessments and red team exercises, maintain effective backup and recovery processes, and establish a proactive incident response capability to minimize the impact of future attacks.

Table of Contents

Protect Your Business from Cyber Threats Today!

Safeguard your business with tailored cybersecurity solutions. Contact us now for a free consultation and ensure a secure digital future!

Ready to Secure Your Future?

We partner with ambitious leaders who shape the future, not just react to it. Let’s achieve extraordinary outcomes together.

I want to talk to your experts in:

Related Blogs

Compliance folders labeled Violations, Documentation, and Regulations on a keyboard, representing the need for a Unified Controls Framework to streamline multiple governance and security standards.
Wooden blocks labeled HITRUST e1 and SOC 2 representing healthcare compliance frameworks for cybersecurity, data protection, and healthcare security.
Modern office desk with data dashboards representing HITRUST readiness assessment and security compliance preparation.