Authentication

M&S Cyberattack: Timeline, Cost, and How Hackers Got In

Erica West

Head of Marketing

Front entrance of a Marks & Spencer (M&S) department store on Oxford Street, London, illustrating the M&S cyberattack.

istock.com/Stefan Sutka

In April 2025, Marks & Spencer suffered one of the most expensive cyberattacks in UK retail history. Online orders stopped for weeks, customer data was stolen, and the incident cut deep into a full year of profits.

We first covered this attack in May 2025, while it was still unfolding. This guide has been updated to reflect what has been confirmed since, including M&S's testimony to Parliament, the National Crime Agency's arrests, and final costs from the retailer's own results.

Key facts at a glance

  • Initial entry: April 17, 2025, according to M&S's chairman

  • Detection: April 19, 2025 (Easter Saturday)

  • Entry method: Impersonation of an individual, with a third party involved

  • Attribution: Linked by researchers and media to Scattered Spider and DragonForce ransomware

  • Disruption: Online clothing orders paused for about seven weeks

  • Direct costs: £131.3 million in cyber-related costs for the 2025/26 financial year

  • Data stolen: Customer contact details, dates of birth, and online order histories

  • Law enforcement: Four people arrested by the NCA in July 2025

What happened in the M&S cyberattack?

Over Easter weekend 2025, M&S customers began running into problems with Click & Collect orders, returns, and contactless payments. On April 22, the retailer disclosed a cyber incident to the London Stock Exchange.

Three days later, M&S paused all orders through its websites and apps. Stores stayed open, but many ran on manual processes while core systems were offline.

The attack affected almost every part of the business:

  • Online shopping: Clothing orders were suspended for about seven weeks, and Click & Collect for nearly four

  • Stores: Staff tracked stock and deliveries by hand, and some food shelves ran low

  • Customers: Personal data was taken, and M&S prompted every online customer to reset their password

  • Finances: The incident wiped out most of M&S's statutory profit for the first half of the year

What caused the M&S cyberattack?

According to Marks & Spencer, the attack began with social engineering. Someone impersonated an individual connected to the business, and a third party was involved in the point of entry. M&S has not described any software vulnerability as part of the initial access.

Sophisticated impersonation of an employee

Chairman Archie Norman told a parliamentary committee in July 2025 that the initial entry came through "sophisticated impersonation." The attackers presented themselves as a specific person and had that person's details ready, so the request looked genuine.

Norman framed the challenge as one of scale; around 50,000 people work on M&S systems, including store staff, contractors, and outsourced teams. And an attacker only needs to fool the right person once.

The third-party help desk connection

Norman confirmed that a third party formed part of the point of entry, but he did not name it. Three reported developments fill in some of the picture:

Why legacy systems made containment harder

M&S has traded since 1884, and Norman told MPs the business runs a mix of old and new systems. That mix makes it harder to isolate parts of the network once an attacker gets inside. CEO Stuart Machin separately attributed the breach to human error.

Early theories about the entry point

In the first weeks after the attack, coverage suggested SIM swapping, phishing emails, and MFA fatigue as possible entry methods. All three are established Scattered Spider tactics, according to CISA's advisory on the group.

M&S's account to Parliament describes impersonation involving a third party. It does not mention any of those three methods.

M&S cyberattack timeline

The table below tracks the attack from the first reported intrusion through M&S's full-year results in May 2026. The status column separates what M&S has confirmed from details that have only been reported.

Marks & Spencer (M&S) cyberattack timeline from February 2025 to May 2026, showing initial entry on April 17, detection on April 19, online orders paused April 25, NCA arrests on July 10, 2025, and full-year results on May 20, 2026.

When did attackers first get into M&S systems?

M&S says April 17, 2025. The chairman gave that date to Parliament and said M&S had complete details of the point and manner of entry, which it shared with the NCA.

The earlier February date comes from one report. On April 30, 2025, BleepingComputer cited unnamed sources saying attackers may have breached M&S as early as February and stolen the file containing its domain password hashes. That report came out before M&S gave its account, and M&S has never confirmed it.

The difference matters because the two dates describe very different attacks:

  • February start: Attackers hide inside the network for about eight weeks before striking.

  • April 17 start: Attackers go from first entry to detection in two days, with ransomware following within a week.

Many summaries of the attack still state February as fact, but the most reliable public evidence points to April 17.

How the cyberattack moved through the Marks & Spencer network

M&S has shared few technical details publicly, so most of what is known about the attack's path comes from reporting and the chairman's testimony.

The sections below follow that path in order: how attackers reportedly widened their access, how the ransomware reached so many systems at once, and why M&S's own containment steps added to the disruption.

Active Directory and the reported NTDS.dit theft

Active Directory controls who can log in to what across a Windows network. Its main database file, NTDS.dit, stores password hashes for every account in the domain.

BleepingComputer's sources reported that attackers stole this file. With it, attackers can crack passwords offline and then log in as other users, including administrators. M&S has not publicly confirmed this detail.

DragonForce ransomware on VMware ESXi

According to the same reporting, attackers deployed DragonForce ransomware to M&S's VMware ESXi hosts on April 24. ESXi hosts run many virtual servers at once, so encrypting them disables a large share of an organization's systems in a single step.

Norman told MPs that "loosely aligned parties" worked together on the attack: an instigator, plus DragonForce, which he described as a ransomware operation believed to be based in Asia. The attackers followed a double extortion model:

  1. Steal data from the network

  2. Encrypt the systems that run the business

  3. Demand payment to restore systems and to keep the stolen data private

Why M&S shut down its systems

Much of the visible disruption came from M&S's own defensive decisions. The retailer took many systems offline on purpose to contain the attackers, and its corporate affairs director told MPs that more than half of M&S's systems remained unaffected at the height of the attack.

Bringing systems back safely took months. Norman said the early recovery ran from a protected data center with no remote working allowed, which slowed the rebuild but reduced the risk of a second compromise.

How much did M&S lose from the April 2025 cyberattack?

M&S reported £131.3 million in costs linked to the cyberattack for the financial year ending March 28, 2026. The retailer's earlier estimate of around £300 million measured lost operating profit before insurance and other recoveries, and M&S received £100 million from insurers in the first half.

These figures measure different things, which is why reported totals vary so widely.

The £300 million estimate explained

In its May 2025 results, M&S estimated the attack would reduce 2025/26 operating profit by about £300 million before mitigation. The company said cost management, insurance, and other trading actions would reduce that figure.

Norman later described the £300 million to MPs as a gross estimate of lost profit before any recoveries. He said the insurance process could take up to 18 months.

What M&S reported in its half-year and full-year results

Period

Reported figure

Half year to Sept. 27, 2025

£101.6 million in incident costs: £82.7 million for response and recovery, £18.9 million for third-party costs

Half year to Sept. 27, 2025

£100 million in cyber insurance payments

Half year to Sept. 27, 2025

Statutory profit before tax fell from £391.9 million to £3.4 million

Full year to March 28, 2026

£131.3 million in cyber-related costs within £292.1 million of adjusting items

Full year to March 28, 2026

Statutory profit before tax fell 28.8% to £364.6 million

Computer Weekly, IT Pro, Retail Gazette

M&S reports incident costs separately from trading performance. The profit lost through weeks of disrupted sales shows up in the trading results.

The cost of lost online sales

Online sales drove much of the damage. Norman told MPs that a third of M&S's clothing and home business sells online, and that the retailer lost about £10 million in profit for each week it could not trade online.

Across roughly seven weeks without online clothing orders, that rate points to tens of millions of pounds in lost profit from online trading alone.

Market value and wider economic impact

The damage extended beyond M&S's own accounts:

How the different cost figures fit together

Figure

What it measures

About £300 million

M&S's May 2025 estimate of lost operating profit, before insurance and mitigation

£101.6 million

Incident costs booked in the first half of 2025/26

£100 million

Insurance payments received in the first half

£131.3 million

Cyber-related costs for the full 2025/26 year

More than £1 billion

Fall in market value in the weeks after the attack

£270 million to £440 million

CMC estimate across M&S, Co-op, and their partners

What customer data was stolen in the M&S data breach?

On May 13, 2025, M&S confirmed that some personal customer data had been taken. It said it had no evidence the data had been shared.

Data that may have been taken:

Data M&S said was not taken:

  • Usable card or payment details

  • Account passwords

As a precaution, M&S required customers to reset their password at their next login. It also warned customers about scam emails, calls, and texts pretending to come from M&S.

Who was behind the M&S cyberattack?

Researchers and media attribute the attack to Scattered Spider, a cybercrime collective known for social engineering, working alongside the DragonForce ransomware operation.

M&S has stopped short of confirming either group. UK police have made arrests connected to the wider wave of retail attacks, but no charges tied to M&S have been made public.

Scattered Spider and DragonForce

Norman told MPs that attackers do not identify themselves and that security advisers recognize them by the pattern of the attack.

Researchers and media have linked the attack to Scattered Spider, also tracked as UNC3944 and Octo Tempest. The group is best known for calling IT help desks while posing as employees, a method we covered in our post on Scattered Spider's attacks on airlines.

The NCA arrests

On July 10, 2025, the National Crime Agency arrested four people in connection with the attacks on M&S, Co-op, and Harrods:

  • Two males aged 19

  • One male aged 17

  • One female aged 20

They were arrested in the West Midlands and London on suspicion of Computer Misuse Act offenses, blackmail, money laundering, and participating in an organized crime group. As of September 2026, we have found no public record of charges related to the M&S attack.

In a separate case, two Scattered Spider members were sentenced in July 2026 for the 2024 attack on Transport for London.

M&S vs Co-op: why similar attacks ended differently

Co-op was hit days after M&S, using a similar method. Co-op's digital chief told the same committee that attackers impersonated a colleague and answered security questions to get the account reset.

Factor

M&S

Co-op

Entry method

Impersonation involving a third party

Impersonation using answers to security questions

Response

Detected two days after entry

Shut systems down before ransomware could encrypt them

Ransomware

Deployed and encrypted systems

Blocked before encryption

Customer data

Stolen

Stolen

Luxury retailer Harrods also restricted online access in May 2025 in response to a cyber incident.

The comparison shows how much the speed of detection shapes the outcome. Both attacks started the same way, with a help desk reset for a caller who had the right details.

Lessons from the M&S cyberattack

The attack worked by exploiting gaps that many organizations share: a reset process that trusted personal details, third parties with broad access, two days of undetected activity, and systems too interconnected to isolate quickly.

Each lesson below addresses one of those gaps, in that order:

1. Treat help desk resets as identity events

Names, employee IDs, and answers to security questions can all be researched or bought. A password or MFA reset should require proof that the caller is the actual account holder. We explain why account recovery is such a high-risk moment in our guide on North Korean remote IT worker fraud.

2. Hold third parties to your own verification standard

Contractors and outsourced help desks often hold the same access as employees. Any vendor staff who can reset credentials or reach core systems should meet the same identity verification standard as your own workforce.

3. Detect intrusions before attackers can move

At M&S, two days passed between entry and detection. Watch closely for unusual activity right after resets and new device enrollments, when a newly compromised account is most likely to be misused.

4. Map your systems and plan to run offline

Norman advised every business to keep a detailed map of how its systems connect and who can access each one. M&S's general counsel added that businesses should be ready to operate on pen and paper while systems are rebuilt.

How verified identity with 1Kosmos stops help desk impersonation

The M&S and Co-op attacks both began with a reset granted to a caller who had the right information. Verified identity replaces that information check with proof of the person.

With biometric identity verification in the reset process:

  • Live biometric check: The caller completes a biometric check on their own device before any reset happens

  • Enrollment match: The check is matched against an identity that was verified against a government ID at enrollment

  • Vendor access: Contractors and outsourced staff go through the same verification

  • Audit trail: Every reset leaves a record of who was verified and when

A caller who only knows an employee's details has no way to pass a live biometric match. Learn more about 1Kosmos help desk verification and account recovery here.

FAQs

Did M&S pay a ransom?

M&S has not said. Norman told MPs the company would not discuss its dealings with the attackers, including any ransom, but that it had shared full details with the NCA.

Was the M&S cyberattack a ransomware attack?

Yes. Reporting links the attack to DragonForce ransomware, which encrypted M&S's virtual servers. The attackers also stole data, which is typical of double extortion.

Did M&S have cyber insurance?

Yes. Norman told MPs that M&S had doubled its insurance cover the year before the attack. The retailer received £100 million in insurance payments in the first half of 2025/26.

How long were M&S online orders down?

Online clothing orders were suspended for about seven weeks, and Click & Collect for nearly four. Full recovery of back-end systems took several months longer.

Was TCS responsible for the M&S breach?

That has not been established. Reports said the M&S logins of TCS employees were used, but TCS said the breach happened in M&S's own environment. Both companies said the end of the help desk contract was unrelated to the attack.

Has anyone been charged over the M&S cyberattack?

As of September 2026, we have found no public record of charges related to the M&S attack. The NCA arrested four people on suspicion of offenses in July 2025.

Has M&S recovered from the cyberattack?

Largely, yes. M&S reported second-half profit growth in 2025/26 and expects profit growth to resume in its current financial year.

In April 2025, Marks & Spencer suffered one of the most expensive cyberattacks in UK retail history. Online orders stopped for weeks, customer data was stolen, and the incident cut deep into a full year of profits.

We first covered this attack in May 2025, while it was still unfolding. This guide has been updated to reflect what has been confirmed since, including M&S's testimony to Parliament, the National Crime Agency's arrests, and final costs from the retailer's own results.

Key facts at a glance

  • Initial entry: April 17, 2025, according to M&S's chairman

  • Detection: April 19, 2025 (Easter Saturday)

  • Entry method: Impersonation of an individual, with a third party involved

  • Attribution: Linked by researchers and media to Scattered Spider and DragonForce ransomware

  • Disruption: Online clothing orders paused for about seven weeks

  • Direct costs: £131.3 million in cyber-related costs for the 2025/26 financial year

  • Data stolen: Customer contact details, dates of birth, and online order histories

  • Law enforcement: Four people arrested by the NCA in July 2025

What happened in the M&S cyberattack?

Over Easter weekend 2025, M&S customers began running into problems with Click & Collect orders, returns, and contactless payments. On April 22, the retailer disclosed a cyber incident to the London Stock Exchange.

Three days later, M&S paused all orders through its websites and apps. Stores stayed open, but many ran on manual processes while core systems were offline.

The attack affected almost every part of the business:

  • Online shopping: Clothing orders were suspended for about seven weeks, and Click & Collect for nearly four

  • Stores: Staff tracked stock and deliveries by hand, and some food shelves ran low

  • Customers: Personal data was taken, and M&S prompted every online customer to reset their password

  • Finances: The incident wiped out most of M&S's statutory profit for the first half of the year

What caused the M&S cyberattack?

According to Marks & Spencer, the attack began with social engineering. Someone impersonated an individual connected to the business, and a third party was involved in the point of entry. M&S has not described any software vulnerability as part of the initial access.

Sophisticated impersonation of an employee

Chairman Archie Norman told a parliamentary committee in July 2025 that the initial entry came through "sophisticated impersonation." The attackers presented themselves as a specific person and had that person's details ready, so the request looked genuine.

Norman framed the challenge as one of scale; around 50,000 people work on M&S systems, including store staff, contractors, and outsourced teams. And an attacker only needs to fool the right person once.

The third-party help desk connection

Norman confirmed that a third party formed part of the point of entry, but he did not name it. Three reported developments fill in some of the picture:

Why legacy systems made containment harder

M&S has traded since 1884, and Norman told MPs the business runs a mix of old and new systems. That mix makes it harder to isolate parts of the network once an attacker gets inside. CEO Stuart Machin separately attributed the breach to human error.

Early theories about the entry point

In the first weeks after the attack, coverage suggested SIM swapping, phishing emails, and MFA fatigue as possible entry methods. All three are established Scattered Spider tactics, according to CISA's advisory on the group.

M&S's account to Parliament describes impersonation involving a third party. It does not mention any of those three methods.

M&S cyberattack timeline

The table below tracks the attack from the first reported intrusion through M&S's full-year results in May 2026. The status column separates what M&S has confirmed from details that have only been reported.

Marks & Spencer (M&S) cyberattack timeline from February 2025 to May 2026, showing initial entry on April 17, detection on April 19, online orders paused April 25, NCA arrests on July 10, 2025, and full-year results on May 20, 2026.

When did attackers first get into M&S systems?

M&S says April 17, 2025. The chairman gave that date to Parliament and said M&S had complete details of the point and manner of entry, which it shared with the NCA.

The earlier February date comes from one report. On April 30, 2025, BleepingComputer cited unnamed sources saying attackers may have breached M&S as early as February and stolen the file containing its domain password hashes. That report came out before M&S gave its account, and M&S has never confirmed it.

The difference matters because the two dates describe very different attacks:

  • February start: Attackers hide inside the network for about eight weeks before striking.

  • April 17 start: Attackers go from first entry to detection in two days, with ransomware following within a week.

Many summaries of the attack still state February as fact, but the most reliable public evidence points to April 17.

How the cyberattack moved through the Marks & Spencer network

M&S has shared few technical details publicly, so most of what is known about the attack's path comes from reporting and the chairman's testimony.

The sections below follow that path in order: how attackers reportedly widened their access, how the ransomware reached so many systems at once, and why M&S's own containment steps added to the disruption.

Active Directory and the reported NTDS.dit theft

Active Directory controls who can log in to what across a Windows network. Its main database file, NTDS.dit, stores password hashes for every account in the domain.

BleepingComputer's sources reported that attackers stole this file. With it, attackers can crack passwords offline and then log in as other users, including administrators. M&S has not publicly confirmed this detail.

DragonForce ransomware on VMware ESXi

According to the same reporting, attackers deployed DragonForce ransomware to M&S's VMware ESXi hosts on April 24. ESXi hosts run many virtual servers at once, so encrypting them disables a large share of an organization's systems in a single step.

Norman told MPs that "loosely aligned parties" worked together on the attack: an instigator, plus DragonForce, which he described as a ransomware operation believed to be based in Asia. The attackers followed a double extortion model:

  1. Steal data from the network

  2. Encrypt the systems that run the business

  3. Demand payment to restore systems and to keep the stolen data private

Why M&S shut down its systems

Much of the visible disruption came from M&S's own defensive decisions. The retailer took many systems offline on purpose to contain the attackers, and its corporate affairs director told MPs that more than half of M&S's systems remained unaffected at the height of the attack.

Bringing systems back safely took months. Norman said the early recovery ran from a protected data center with no remote working allowed, which slowed the rebuild but reduced the risk of a second compromise.

How much did M&S lose from the April 2025 cyberattack?

M&S reported £131.3 million in costs linked to the cyberattack for the financial year ending March 28, 2026. The retailer's earlier estimate of around £300 million measured lost operating profit before insurance and other recoveries, and M&S received £100 million from insurers in the first half.

These figures measure different things, which is why reported totals vary so widely.

The £300 million estimate explained

In its May 2025 results, M&S estimated the attack would reduce 2025/26 operating profit by about £300 million before mitigation. The company said cost management, insurance, and other trading actions would reduce that figure.

Norman later described the £300 million to MPs as a gross estimate of lost profit before any recoveries. He said the insurance process could take up to 18 months.

What M&S reported in its half-year and full-year results

Period

Reported figure

Half year to Sept. 27, 2025

£101.6 million in incident costs: £82.7 million for response and recovery, £18.9 million for third-party costs

Half year to Sept. 27, 2025

£100 million in cyber insurance payments

Half year to Sept. 27, 2025

Statutory profit before tax fell from £391.9 million to £3.4 million

Full year to March 28, 2026

£131.3 million in cyber-related costs within £292.1 million of adjusting items

Full year to March 28, 2026

Statutory profit before tax fell 28.8% to £364.6 million

Computer Weekly, IT Pro, Retail Gazette

M&S reports incident costs separately from trading performance. The profit lost through weeks of disrupted sales shows up in the trading results.

The cost of lost online sales

Online sales drove much of the damage. Norman told MPs that a third of M&S's clothing and home business sells online, and that the retailer lost about £10 million in profit for each week it could not trade online.

Across roughly seven weeks without online clothing orders, that rate points to tens of millions of pounds in lost profit from online trading alone.

Market value and wider economic impact

The damage extended beyond M&S's own accounts:

How the different cost figures fit together

Figure

What it measures

About £300 million

M&S's May 2025 estimate of lost operating profit, before insurance and mitigation

£101.6 million

Incident costs booked in the first half of 2025/26

£100 million

Insurance payments received in the first half

£131.3 million

Cyber-related costs for the full 2025/26 year

More than £1 billion

Fall in market value in the weeks after the attack

£270 million to £440 million

CMC estimate across M&S, Co-op, and their partners

What customer data was stolen in the M&S data breach?

On May 13, 2025, M&S confirmed that some personal customer data had been taken. It said it had no evidence the data had been shared.

Data that may have been taken:

Data M&S said was not taken:

  • Usable card or payment details

  • Account passwords

As a precaution, M&S required customers to reset their password at their next login. It also warned customers about scam emails, calls, and texts pretending to come from M&S.

Who was behind the M&S cyberattack?

Researchers and media attribute the attack to Scattered Spider, a cybercrime collective known for social engineering, working alongside the DragonForce ransomware operation.

M&S has stopped short of confirming either group. UK police have made arrests connected to the wider wave of retail attacks, but no charges tied to M&S have been made public.

Scattered Spider and DragonForce

Norman told MPs that attackers do not identify themselves and that security advisers recognize them by the pattern of the attack.

Researchers and media have linked the attack to Scattered Spider, also tracked as UNC3944 and Octo Tempest. The group is best known for calling IT help desks while posing as employees, a method we covered in our post on Scattered Spider's attacks on airlines.

The NCA arrests

On July 10, 2025, the National Crime Agency arrested four people in connection with the attacks on M&S, Co-op, and Harrods:

  • Two males aged 19

  • One male aged 17

  • One female aged 20

They were arrested in the West Midlands and London on suspicion of Computer Misuse Act offenses, blackmail, money laundering, and participating in an organized crime group. As of September 2026, we have found no public record of charges related to the M&S attack.

In a separate case, two Scattered Spider members were sentenced in July 2026 for the 2024 attack on Transport for London.

M&S vs Co-op: why similar attacks ended differently

Co-op was hit days after M&S, using a similar method. Co-op's digital chief told the same committee that attackers impersonated a colleague and answered security questions to get the account reset.

Factor

M&S

Co-op

Entry method

Impersonation involving a third party

Impersonation using answers to security questions

Response

Detected two days after entry

Shut systems down before ransomware could encrypt them

Ransomware

Deployed and encrypted systems

Blocked before encryption

Customer data

Stolen

Stolen

Luxury retailer Harrods also restricted online access in May 2025 in response to a cyber incident.

The comparison shows how much the speed of detection shapes the outcome. Both attacks started the same way, with a help desk reset for a caller who had the right details.

Lessons from the M&S cyberattack

The attack worked by exploiting gaps that many organizations share: a reset process that trusted personal details, third parties with broad access, two days of undetected activity, and systems too interconnected to isolate quickly.

Each lesson below addresses one of those gaps, in that order:

1. Treat help desk resets as identity events

Names, employee IDs, and answers to security questions can all be researched or bought. A password or MFA reset should require proof that the caller is the actual account holder. We explain why account recovery is such a high-risk moment in our guide on North Korean remote IT worker fraud.

2. Hold third parties to your own verification standard

Contractors and outsourced help desks often hold the same access as employees. Any vendor staff who can reset credentials or reach core systems should meet the same identity verification standard as your own workforce.

3. Detect intrusions before attackers can move

At M&S, two days passed between entry and detection. Watch closely for unusual activity right after resets and new device enrollments, when a newly compromised account is most likely to be misused.

4. Map your systems and plan to run offline

Norman advised every business to keep a detailed map of how its systems connect and who can access each one. M&S's general counsel added that businesses should be ready to operate on pen and paper while systems are rebuilt.

How verified identity with 1Kosmos stops help desk impersonation

The M&S and Co-op attacks both began with a reset granted to a caller who had the right information. Verified identity replaces that information check with proof of the person.

With biometric identity verification in the reset process:

  • Live biometric check: The caller completes a biometric check on their own device before any reset happens

  • Enrollment match: The check is matched against an identity that was verified against a government ID at enrollment

  • Vendor access: Contractors and outsourced staff go through the same verification

  • Audit trail: Every reset leaves a record of who was verified and when

A caller who only knows an employee's details has no way to pass a live biometric match. Learn more about 1Kosmos help desk verification and account recovery here.

FAQs

Did M&S pay a ransom?

M&S has not said. Norman told MPs the company would not discuss its dealings with the attackers, including any ransom, but that it had shared full details with the NCA.

Was the M&S cyberattack a ransomware attack?

Yes. Reporting links the attack to DragonForce ransomware, which encrypted M&S's virtual servers. The attackers also stole data, which is typical of double extortion.

Did M&S have cyber insurance?

Yes. Norman told MPs that M&S had doubled its insurance cover the year before the attack. The retailer received £100 million in insurance payments in the first half of 2025/26.

How long were M&S online orders down?

Online clothing orders were suspended for about seven weeks, and Click & Collect for nearly four. Full recovery of back-end systems took several months longer.

Was TCS responsible for the M&S breach?

That has not been established. Reports said the M&S logins of TCS employees were used, but TCS said the breach happened in M&S's own environment. Both companies said the end of the help desk contract was unrelated to the attack.

Has anyone been charged over the M&S cyberattack?

As of September 2026, we have found no public record of charges related to the M&S attack. The NCA arrested four people on suspicion of offenses in July 2025.

Has M&S recovered from the cyberattack?

Largely, yes. M&S reported second-half profit growth in 2025/26 and expects profit growth to resume in its current financial year.

In April 2025, Marks & Spencer suffered one of the most expensive cyberattacks in UK retail history. Online orders stopped for weeks, customer data was stolen, and the incident cut deep into a full year of profits.

We first covered this attack in May 2025, while it was still unfolding. This guide has been updated to reflect what has been confirmed since, including M&S's testimony to Parliament, the National Crime Agency's arrests, and final costs from the retailer's own results.

Key facts at a glance

  • Initial entry: April 17, 2025, according to M&S's chairman

  • Detection: April 19, 2025 (Easter Saturday)

  • Entry method: Impersonation of an individual, with a third party involved

  • Attribution: Linked by researchers and media to Scattered Spider and DragonForce ransomware

  • Disruption: Online clothing orders paused for about seven weeks

  • Direct costs: £131.3 million in cyber-related costs for the 2025/26 financial year

  • Data stolen: Customer contact details, dates of birth, and online order histories

  • Law enforcement: Four people arrested by the NCA in July 2025

What happened in the M&S cyberattack?

Over Easter weekend 2025, M&S customers began running into problems with Click & Collect orders, returns, and contactless payments. On April 22, the retailer disclosed a cyber incident to the London Stock Exchange.

Three days later, M&S paused all orders through its websites and apps. Stores stayed open, but many ran on manual processes while core systems were offline.

The attack affected almost every part of the business:

  • Online shopping: Clothing orders were suspended for about seven weeks, and Click & Collect for nearly four

  • Stores: Staff tracked stock and deliveries by hand, and some food shelves ran low

  • Customers: Personal data was taken, and M&S prompted every online customer to reset their password

  • Finances: The incident wiped out most of M&S's statutory profit for the first half of the year

What caused the M&S cyberattack?

According to Marks & Spencer, the attack began with social engineering. Someone impersonated an individual connected to the business, and a third party was involved in the point of entry. M&S has not described any software vulnerability as part of the initial access.

Sophisticated impersonation of an employee

Chairman Archie Norman told a parliamentary committee in July 2025 that the initial entry came through "sophisticated impersonation." The attackers presented themselves as a specific person and had that person's details ready, so the request looked genuine.

Norman framed the challenge as one of scale; around 50,000 people work on M&S systems, including store staff, contractors, and outsourced teams. And an attacker only needs to fool the right person once.

The third-party help desk connection

Norman confirmed that a third party formed part of the point of entry, but he did not name it. Three reported developments fill in some of the picture:

Why legacy systems made containment harder

M&S has traded since 1884, and Norman told MPs the business runs a mix of old and new systems. That mix makes it harder to isolate parts of the network once an attacker gets inside. CEO Stuart Machin separately attributed the breach to human error.

Early theories about the entry point

In the first weeks after the attack, coverage suggested SIM swapping, phishing emails, and MFA fatigue as possible entry methods. All three are established Scattered Spider tactics, according to CISA's advisory on the group.

M&S's account to Parliament describes impersonation involving a third party. It does not mention any of those three methods.

M&S cyberattack timeline

The table below tracks the attack from the first reported intrusion through M&S's full-year results in May 2026. The status column separates what M&S has confirmed from details that have only been reported.

Marks & Spencer (M&S) cyberattack timeline from February 2025 to May 2026, showing initial entry on April 17, detection on April 19, online orders paused April 25, NCA arrests on July 10, 2025, and full-year results on May 20, 2026.

When did attackers first get into M&S systems?

M&S says April 17, 2025. The chairman gave that date to Parliament and said M&S had complete details of the point and manner of entry, which it shared with the NCA.

The earlier February date comes from one report. On April 30, 2025, BleepingComputer cited unnamed sources saying attackers may have breached M&S as early as February and stolen the file containing its domain password hashes. That report came out before M&S gave its account, and M&S has never confirmed it.

The difference matters because the two dates describe very different attacks:

  • February start: Attackers hide inside the network for about eight weeks before striking.

  • April 17 start: Attackers go from first entry to detection in two days, with ransomware following within a week.

Many summaries of the attack still state February as fact, but the most reliable public evidence points to April 17.

How the cyberattack moved through the Marks & Spencer network

M&S has shared few technical details publicly, so most of what is known about the attack's path comes from reporting and the chairman's testimony.

The sections below follow that path in order: how attackers reportedly widened their access, how the ransomware reached so many systems at once, and why M&S's own containment steps added to the disruption.

Active Directory and the reported NTDS.dit theft

Active Directory controls who can log in to what across a Windows network. Its main database file, NTDS.dit, stores password hashes for every account in the domain.

BleepingComputer's sources reported that attackers stole this file. With it, attackers can crack passwords offline and then log in as other users, including administrators. M&S has not publicly confirmed this detail.

DragonForce ransomware on VMware ESXi

According to the same reporting, attackers deployed DragonForce ransomware to M&S's VMware ESXi hosts on April 24. ESXi hosts run many virtual servers at once, so encrypting them disables a large share of an organization's systems in a single step.

Norman told MPs that "loosely aligned parties" worked together on the attack: an instigator, plus DragonForce, which he described as a ransomware operation believed to be based in Asia. The attackers followed a double extortion model:

  1. Steal data from the network

  2. Encrypt the systems that run the business

  3. Demand payment to restore systems and to keep the stolen data private

Why M&S shut down its systems

Much of the visible disruption came from M&S's own defensive decisions. The retailer took many systems offline on purpose to contain the attackers, and its corporate affairs director told MPs that more than half of M&S's systems remained unaffected at the height of the attack.

Bringing systems back safely took months. Norman said the early recovery ran from a protected data center with no remote working allowed, which slowed the rebuild but reduced the risk of a second compromise.

How much did M&S lose from the April 2025 cyberattack?

M&S reported £131.3 million in costs linked to the cyberattack for the financial year ending March 28, 2026. The retailer's earlier estimate of around £300 million measured lost operating profit before insurance and other recoveries, and M&S received £100 million from insurers in the first half.

These figures measure different things, which is why reported totals vary so widely.

The £300 million estimate explained

In its May 2025 results, M&S estimated the attack would reduce 2025/26 operating profit by about £300 million before mitigation. The company said cost management, insurance, and other trading actions would reduce that figure.

Norman later described the £300 million to MPs as a gross estimate of lost profit before any recoveries. He said the insurance process could take up to 18 months.

What M&S reported in its half-year and full-year results

Period

Reported figure

Half year to Sept. 27, 2025

£101.6 million in incident costs: £82.7 million for response and recovery, £18.9 million for third-party costs

Half year to Sept. 27, 2025

£100 million in cyber insurance payments

Half year to Sept. 27, 2025

Statutory profit before tax fell from £391.9 million to £3.4 million

Full year to March 28, 2026

£131.3 million in cyber-related costs within £292.1 million of adjusting items

Full year to March 28, 2026

Statutory profit before tax fell 28.8% to £364.6 million

Computer Weekly, IT Pro, Retail Gazette

M&S reports incident costs separately from trading performance. The profit lost through weeks of disrupted sales shows up in the trading results.

The cost of lost online sales

Online sales drove much of the damage. Norman told MPs that a third of M&S's clothing and home business sells online, and that the retailer lost about £10 million in profit for each week it could not trade online.

Across roughly seven weeks without online clothing orders, that rate points to tens of millions of pounds in lost profit from online trading alone.

Market value and wider economic impact

The damage extended beyond M&S's own accounts:

How the different cost figures fit together

Figure

What it measures

About £300 million

M&S's May 2025 estimate of lost operating profit, before insurance and mitigation

£101.6 million

Incident costs booked in the first half of 2025/26

£100 million

Insurance payments received in the first half

£131.3 million

Cyber-related costs for the full 2025/26 year

More than £1 billion

Fall in market value in the weeks after the attack

£270 million to £440 million

CMC estimate across M&S, Co-op, and their partners

What customer data was stolen in the M&S data breach?

On May 13, 2025, M&S confirmed that some personal customer data had been taken. It said it had no evidence the data had been shared.

Data that may have been taken:

Data M&S said was not taken:

  • Usable card or payment details

  • Account passwords

As a precaution, M&S required customers to reset their password at their next login. It also warned customers about scam emails, calls, and texts pretending to come from M&S.

Who was behind the M&S cyberattack?

Researchers and media attribute the attack to Scattered Spider, a cybercrime collective known for social engineering, working alongside the DragonForce ransomware operation.

M&S has stopped short of confirming either group. UK police have made arrests connected to the wider wave of retail attacks, but no charges tied to M&S have been made public.

Scattered Spider and DragonForce

Norman told MPs that attackers do not identify themselves and that security advisers recognize them by the pattern of the attack.

Researchers and media have linked the attack to Scattered Spider, also tracked as UNC3944 and Octo Tempest. The group is best known for calling IT help desks while posing as employees, a method we covered in our post on Scattered Spider's attacks on airlines.

The NCA arrests

On July 10, 2025, the National Crime Agency arrested four people in connection with the attacks on M&S, Co-op, and Harrods:

  • Two males aged 19

  • One male aged 17

  • One female aged 20

They were arrested in the West Midlands and London on suspicion of Computer Misuse Act offenses, blackmail, money laundering, and participating in an organized crime group. As of September 2026, we have found no public record of charges related to the M&S attack.

In a separate case, two Scattered Spider members were sentenced in July 2026 for the 2024 attack on Transport for London.

M&S vs Co-op: why similar attacks ended differently

Co-op was hit days after M&S, using a similar method. Co-op's digital chief told the same committee that attackers impersonated a colleague and answered security questions to get the account reset.

Factor

M&S

Co-op

Entry method

Impersonation involving a third party

Impersonation using answers to security questions

Response

Detected two days after entry

Shut systems down before ransomware could encrypt them

Ransomware

Deployed and encrypted systems

Blocked before encryption

Customer data

Stolen

Stolen

Luxury retailer Harrods also restricted online access in May 2025 in response to a cyber incident.

The comparison shows how much the speed of detection shapes the outcome. Both attacks started the same way, with a help desk reset for a caller who had the right details.

Lessons from the M&S cyberattack

The attack worked by exploiting gaps that many organizations share: a reset process that trusted personal details, third parties with broad access, two days of undetected activity, and systems too interconnected to isolate quickly.

Each lesson below addresses one of those gaps, in that order:

1. Treat help desk resets as identity events

Names, employee IDs, and answers to security questions can all be researched or bought. A password or MFA reset should require proof that the caller is the actual account holder. We explain why account recovery is such a high-risk moment in our guide on North Korean remote IT worker fraud.

2. Hold third parties to your own verification standard

Contractors and outsourced help desks often hold the same access as employees. Any vendor staff who can reset credentials or reach core systems should meet the same identity verification standard as your own workforce.

3. Detect intrusions before attackers can move

At M&S, two days passed between entry and detection. Watch closely for unusual activity right after resets and new device enrollments, when a newly compromised account is most likely to be misused.

4. Map your systems and plan to run offline

Norman advised every business to keep a detailed map of how its systems connect and who can access each one. M&S's general counsel added that businesses should be ready to operate on pen and paper while systems are rebuilt.

How verified identity with 1Kosmos stops help desk impersonation

The M&S and Co-op attacks both began with a reset granted to a caller who had the right information. Verified identity replaces that information check with proof of the person.

With biometric identity verification in the reset process:

  • Live biometric check: The caller completes a biometric check on their own device before any reset happens

  • Enrollment match: The check is matched against an identity that was verified against a government ID at enrollment

  • Vendor access: Contractors and outsourced staff go through the same verification

  • Audit trail: Every reset leaves a record of who was verified and when

A caller who only knows an employee's details has no way to pass a live biometric match. Learn more about 1Kosmos help desk verification and account recovery here.

FAQs

Did M&S pay a ransom?

M&S has not said. Norman told MPs the company would not discuss its dealings with the attackers, including any ransom, but that it had shared full details with the NCA.

Was the M&S cyberattack a ransomware attack?

Yes. Reporting links the attack to DragonForce ransomware, which encrypted M&S's virtual servers. The attackers also stole data, which is typical of double extortion.

Did M&S have cyber insurance?

Yes. Norman told MPs that M&S had doubled its insurance cover the year before the attack. The retailer received £100 million in insurance payments in the first half of 2025/26.

How long were M&S online orders down?

Online clothing orders were suspended for about seven weeks, and Click & Collect for nearly four. Full recovery of back-end systems took several months longer.

Was TCS responsible for the M&S breach?

That has not been established. Reports said the M&S logins of TCS employees were used, but TCS said the breach happened in M&S's own environment. Both companies said the end of the help desk contract was unrelated to the attack.

Has anyone been charged over the M&S cyberattack?

As of September 2026, we have found no public record of charges related to the M&S attack. The NCA arrested four people on suspicion of offenses in July 2025.

Has M&S recovered from the cyberattack?

Largely, yes. M&S reported second-half profit growth in 2025/26 and expects profit growth to resume in its current financial year.

About the author

Erica West

Head of Marketing

Erica West is the Head of Marketing at 1Kosmos, where she drives messaging, positioning, and content strategy for identity verification and passwordless authentication solutions.

The latest in identity security.

Enter our orbit.

The latest in identity security.

Enter our orbit.

The latest in identity security.

Enter our orbit.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.