October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
business continuity

M&S suspended online sales during its April 2025 cyber incident—what happened and how it recovered

M&S's April 25, 2025 online-sales suspension was a containment measure during a wider cyber incident. Stores stayed open, but warehouses, click and collect, data security and profits were affected before systems were restored.

By TheFinanceBase Team 6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Marks & Spencer (M&S) paused orders on its UK and Ireland websites and mobile apps on April 25, 2025, while responding to a cyber incident. Customers could still browse products online and visit open stores, but checkout was unavailable; earlier disruption had also affected contactless payments, delivery timing and click-and-collect operations. This was a 2025 event, not an ongoing online-sales outage in 2026. M&S later restored customer-facing systems and reported a return to sales and profit growth in the second half of its 2025/26 financial year.

The initial announcement did not establish that the attack was ransomware, identify the perpetrators or prove that the entire ecommerce platform had been destroyed. Subsequent disclosures showed wider operational disruption, some personal data taken and substantial financial costs.

What M&S actually suspended

In its April 25, 2025 update, M&S said it had paused orders through its websites and apps as a precaution while managing the incident. The distinction between browsing and buying mattered:

Service or operation Status during the disruption
Website and app product browsing Still available
Website and app checkout Orders paused
Physical stores Open and trading
Click and collect Disrupted; collections and processing were affected
Contactless payments Previously disrupted, according to M&S’s April 23 update
Delivery and fulfilment Delays and operational disruption were reported
Geographic scope UK and Ireland websites and apps, plus some M&S-operated international websites, according to the 2025 financial statements

The April 23 operational statement is available from M&S. Keeping a catalogue visible did not mean that inventory, warehouse or fulfilment systems were functioning normally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline: from operational problems to recovery

  1. April 2025: M&S began taking selected processes offline while responding to a cyber incident.
  2. April 21–23: Customers reported contactless-payment and click-and-collect problems. M&S acknowledged operational disruption. Contemporary chronology is documented by Al Jazeera.
  3. April 25: Website and app orders were paused, although browsing and store trading continued. See the company announcement.
  4. Late April and May: Disruption spread through warehouses, logistics, replenishment, recruitment and other processes. Stores used manual workarounds, and reports described stock shortages and delays.
  5. Summer 2025: M&S said customer-facing systems were progressively restored and that practically all operational systems had been recovered by its half-year reporting period.
  6. August 2025: Click and collect was reported as returning as recovery continued.
  7. November 2025: M&S quantified sales losses, incident costs and insurance proceeds in its half-year results.
  8. May 2026: M&S reported that sales and profit growth had resumed in the second half of 2025/26 in its full-year results.

Why an online outage affected stores and supply chains

This was not simply a broken checkout page. M&S said it disconnected warehouse-management systems as part of its response. That helped contain the incident but also interrupted the systems that connect online orders, stock visibility, fulfilment, click and collect, store ordering and replenishment.

The operational chain

  • Warehouse management: Disconnecting systems reduced the ability to pick, pack and route orders automatically.
  • Inventory visibility: Stores and websites could not reliably use normal real-time stock information.
  • Replenishment: Ordering and forecasting moved to manual processes, increasing delays and the risk of shortages.
  • Customer services: Click-and-collect processing and delivery commitments became harder to manage.
  • Financial effects: Extra labour, logistics, waste and markdowns added to lost sales.

M&S described manual methods for trading, forecasting, ordering and replenishment in its half-year results. Stores remaining open therefore did not mean that every backend system was available.

What is known about the attack

Confirmed at the time

M&S publicly called the event a cyber incident. Its April 25 statement did not confirm ransomware, a criminal group, the initial access route or the full extent of data access. Contemporary coverage noted that the breadth of the shutdown prompted expert speculation about ransomware or extortion, but those were interpretations rather than findings established by M&S at that point. See Computer Weekly.

Later attribution reports

Security researchers and later reporting linked the incident to the Scattered Spider/Octo Tempest ecosystem and DragonForce ransomware. Those links should remain attributed: M&S’s public disclosures concentrated on the incident’s consequences rather than publishing a complete, independently verifiable technical attribution. It is not established here that Scattered Spider definitely carried out the attack, that DragonForce was definitively the malware used by M&S, that a help desk was certainly compromised, or that M&S paid a ransom. Claims that the M&S, Co-op and Harrods incidents were one coordinated operation also remain a matter for attributed reporting, not an uncontested fact. Al Jazeera’s account provides the relevant attribution context: https://www.aljazeera.com/news/2025/5/2/harrods-ms-hit-by-cyberattack-what-happened-who-was-behind-it.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened to customer data

The data position changed as the investigation developed. Early April 25 coverage said there was no indication then that personal information had been exposed. M&S later told customers that some personal data had been taken. Its cyber update and customer FAQ listed potentially affected information as:

  • Names
  • Email and postal addresses
  • Telephone numbers
  • Dates of birth
  • Online order history
  • Household information
  • Masked payment-card details used for online purchases

M&S said the data did not include usable payment details or account passwords and that it had no evidence the information had been shared. “No usable payment details” is more precise than saying no card information existed: masked card details could be included, but not details usable to make payments. The company said it reported the incident to relevant authorities, including the UK’s National Cyber Security Centre and Information Commissioner’s Office, in its 2025 financial statements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What customers should do

M&S’s guidance does not require every customer to cancel a card or change every password. The practical steps are narrower:

  1. Be alert to emails, calls and texts claiming to be from M&S, especially messages about refunds, vouchers, deliveries or password resets.
  2. Do not provide a username, password or other account information in response to unsolicited contact.
  3. Handle links and attachments in incident-related messages cautiously; use the official M&S site or verified company channels instead.
  4. Reset your M&S password when prompted at the next website or app login.
  5. Monitor bank and other account activity for suspicious transactions or login alerts.

Be particularly wary of reused passwords: an M&S credential reused on another service could create a separate risk even though M&S said its own account passwords were not part of the taken data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How serious was the business impact?

M&S first estimated that the incident could reduce 2025/26 operating profit by approximately £300 million, before mitigation, insurance and other trading actions. That was an estimate of operating-profit impact, not a statement that M&S had simply “lost £300 million.” The estimate appeared in its 2024/25 full-year results.

Measure Reported result Qualification
Adjusted profit before tax, first half 2025/26 £184.1 million, versus £413.1 million a year earlier M&S half-year results
Fashion, Home & Beauty sales, first half Down 16.4% M&S half-year results
Incident-related adjusting costs, first half £101.6 million M&S half-year results
Insurance proceeds £100 million Reported in the half-year and full-year disclosures
Adjusted profit before tax, full year 2025/26 £671.4 million, versus £881.1 million M&S full-year results
Incident-related adjusting costs, full year £131.3 million M&S full-year results
Fashion, Home & Beauty sales, full year Down 7.7% M&S full-year results

Insurance reduced the accounting effect, but it did not restore missed sales, lost customer time, disrupted operations or trust. M&S said second-half sales and profit growth returned after the severe first-half disruption, indicating recovery rather than an absence of damage. The company’s complete figures are in its 2025/26 results.

What the incident shows about retail cyber resilience

  • Containment has a continuity cost: Taking warehouse and ordering systems offline may limit compromise while immediately damaging fulfilment and stock flow.
  • Retail is tightly interconnected: Ecommerce, inventory, warehouses, payments and stores depend on shared operational data.
  • Manual fallback must work at scale: It can keep stores trading, but usually requires more labour and creates delays, waste and markdowns.
  • Public information evolves: Early statements can be necessarily incomplete while forensics and legal notifications proceed; later data findings should supersede assumptions based only on the first update.
  • Recovery is progressive: A browseable website or restored checkout does not prove that every backend system has recovered simultaneously.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.