Back to the archive

The encyclopedia · Software & IT · Operational decision · 2025

M&S's £300M ransomware attack — a cyber breach that nearly halved its profits

Marks & Spencer was hit by a ransomware attack over Easter 2025 that forced its online store offline for 46 days and wiped 55.4% off its half-year profit.

Marks & Spencer · 2025-04-21

What happened

In April 2025, Marks & Spencer, the 140-year-old British retail institution, was hit by a ransomware attack carried out by the Scattered Spider gang. The attackers gained access over the Easter weekend, encrypting parts of M&S's infrastructure. Customers reported payment issues and delays in online orders, and the company was forced to freeze its online clothing store for 46 days while rebuilding core systems from scratch.

The financial impact was severe. M&S warned investors of a potential £300 million profit hit, with direct costs estimated at £136 million. Underlying pre-tax profits tumbled 55.4% to £184.1 million in the six months following the attack. The UK's Cyber Monitoring Centre classified the combined damage from attacks on M&S and Co-op at between £270 million and £440 million. Warehouse systems went offline, shelves emptied in some stores, and the company's digital transformation — a key pillar of its turnaround strategy — was effectively reset to zero.

The attack exploited a gap in M&S's cybersecurity posture. The company had invested heavily in store refurbishment and product innovation but had treated cybersecurity as a back-office cost rather than an operational risk. The 46-day online store closure was not just a revenue loss — it was a customer trust event, as shoppers who had moved to online ordering during the disruption had to find alternatives.

Why it happened

  • M&S treated cybersecurity as a cost centre, not a risk — the investment in firewalls and incident response never kept pace with the complexity of the infrastructure being protected
  • The 46-day offline period showed that M&S had no viable disaster-recovery plan for its e-commerce platform — a single point of failure for a modern retailer
  • The attack exploited a 'just enough' security posture — compliant with minimum standards, but not designed to withstand a determined ransomware gang
What it cost£300M profit hit; 55.4% profit drop; 46 days offlinecostly

The lesson

A retailer's digital infrastructure is its storefront — and a ransomware attack that closes it for 46 days reveals that 'just enough' security is not enough at all

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →