Free tools Windows power users keep installed
One-click scans. No signup required.
Marks & Spencer’s 2025 cyber attack produced £131.3 million of incident-related costs in the year ended 28 March 2026. The retailer also recognised £100 million of insurance proceeds. Adjusted profit before tax fell 23.8% to £671.4 million, while statutory profit before tax fell 28.8% to £364.6 million.
Those figures are different from the approximately £300 million warning issued in May 2025. That was an early estimate of the incident’s potential effect on operating profit before mitigation, not a confirmed final bill or a direct-cost total.
How the financial impact changed
M&S’s disclosures answer different questions, so the figures should not be treated as interchangeable.
| Date or period | Disclosure | What it means |
|---|---|---|
| 22 April 2025 | Cyber incident disclosed | M&S began containing the incident and taking systems offline. |
| 21 May 2025 | Approximately £300 million | Estimated reduction in 2025/26 operating profit before insurance, cost reductions and trading actions. |
| 26 weeks ended 27 September 2025 | £101.6 million incident-related costs; £100 million insurance income | Adjusted profit before tax was £184.1 million, compared with £413.1 million a year earlier. |
| 52 weeks ended 28 March 2026 | £131.3 million incident-related costs; £100 million insurance proceeds | Adjusted profit before tax was £671.4 million, down from £881.1 million. |
The full-year accounts also reported £292.1 million of total adjusting items, of which the cyber incident was one component. The £131.3 million is therefore the amount M&S classified as directly associated incident costs in adjusting items, not a complete measure of lost sales, disruption or longer-term economic damage.
Recommended Free Tools
#1 Best Overall
Sources: M&S full-year results, full-year results PDF and half-year results.
Why £300 million is not the final bill
The May 2025 estimate covered the expected effect on Group operating profit before mitigation. M&S said mitigation included insurance recovery, cost control and trading measures. The later £131.3 million figure records direct incident-related costs in the accounts, while the £100 million represents insurance income recognised centrally in adjusted profit. M&S has not presented the insurance proceeds as proof that every loss was reimbursed, nor has it stated that the direct-cost figure captures all lost profit.
The company described the year as one of two halves: severe operational disruption in the first half, followed by recovery and growth in the second. Second-half adjusted profit before tax rose 4.1%, but the full-year comparison still reflected the earlier shock.
What the attack disrupted
M&S took systems offline to contain and manage the incident. Warehouse-management systems were disconnected, and online orders, Click & Collect and in-store ordering were paused. Stores remained open, but the retail operation continued with significant constraints.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Food operations
Food teams relied on manual forecasting, ordering and replenishment. Reduced availability affected sales, while manual handling increased waste and logistics costs. Food sales still rose 7.8% in the first half and 7.0% for the full year, but availability and supply-chain disruption limited performance.
Fashion, Home & Beauty
The online offer and fulfilment disruption hit this division hardest. First-half sales fell 16.4%, with adjusted operating profit of £46.1 million. Full-year sales were down 7.7%. The annual decline also reflects wider trading and strategic factors, so it should not be attributed entirely to the cyber incident.
Rank #3
International
International sales fell 11.6% in the first half, with adjusted operating profit of £13.3 million, and fell 7.2% for the full year. Again, M&S’s accounts include factors beyond the cyber disruption.
The operational chain was: systems taken offline, followed by warehouse and ordering disruption; paused digital and collection services; lower availability and sales; and additional manual-processing, waste, logistics and stock-management costs.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsM&S said the online offer was restored in August 2025. At the half-year stage, practically all operational systems had been recovered, although resilience and recovery work continued. Sources: April and May 2025 disclosures, operational update and half-year results.
Rank #4
What customer data was taken?
M&S says some personal customer data was taken, but it said there was no evidence that the data had been shared. Potentially affected information included:
- names, email addresses, postal addresses and telephone numbers;
- dates of birth;
- online order history and household information; and
- masked payment-card details used for online purchases.
The company said the data did not include usable card or payment details and did not include account passwords. “Payment information stolen” and “passwords compromised” are therefore inaccurate descriptions of the company’s notice.
M&S advised customers to be alert to fraudulent emails, calls and texts, and said customers would be prompted to reset their passwords at their next website or app login. Read the company’s customer notice at M&S’s cyber update.
Best Value
Did M&S pay a ransom?
M&S has not publicly confirmed whether a ransom was paid. At its 2025 annual general meeting, the company said it could not comment on whether funds had been paid to attackers, following advice from specialist advisers, government agencies and law enforcement. The AGM answers are available in M&S’s 2025 Q&A document.
Which authorities were notified?
M&S said it reported the incident to relevant authorities and law enforcement. Its 2026 annual report says the company reported it to the National Cyber Security Centre and the Information Commissioner’s Office. As of 19 May 2026, M&S said it was still cooperating with investigations by the ICO and other relevant regulators. See the 2026 annual report.
Has the crisis ended?
By the half-year reporting stage, M&S said customer-facing systems had been restored and practically all operational systems had recovered. The full-year results reported stronger sales and profit in the second half, alongside a plan for 2026/27 focused on availability, service levels and technology resilience. Recovery does not mean every consequence has been closed: regulatory cooperation and resilience work were continuing in May 2026.
What this shows about retail cyber risk
The M&S case demonstrates why a retailer’s cyber cost extends beyond website downtime. A serious incident can interrupt warehouse systems, replenishment, inventory visibility, delivery planning, customer collection and digital conversion. Those interruptions can create lost sales, waste, emergency manual work, logistics expense and rebuilding costs. Insurance may offset part of the accounting impact, but it does not make the operational disruption disappear.
Bottom line
M&S did not ultimately report a £300 million direct loss to hackers. It initially estimated an approximately £300 million pre-mitigation impact on operating profit, then reported £131.3 million of directly associated incident costs and £100 million of insurance proceeds. The wider damage was visible in lower profit, disrupted sales and months of operational workarounds. Customer data was taken, according to M&S, but usable payment details and passwords were not included; the final regulatory and investigative picture remained incomplete as of May 2026.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




