October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

M&S cyber attack: what the retailer’s £131.3m bill means after the original £300m warning

M&S’s 2025 cyber attack led to £131.3m of incident-related costs, £100m of insurance proceeds and a 23.8% fall in adjusted annual profit. The original £300m figure was a pre-mitigation forecast, not the final direct-cost bill.
From TheFinanceBase Team5 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Marks & Spencer’s 2025 cyber attack produced £131.3 million of incident-related costs in the year ended 28 March 2026. The retailer also recognised £100 million of insurance proceeds. Adjusted profit before tax fell 23.8% to £671.4 million, while statutory profit before tax fell 28.8% to £364.6 million.

Those figures are different from the approximately £300 million warning issued in May 2025. That was an early estimate of the incident’s potential effect on operating profit before mitigation, not a confirmed final bill or a direct-cost total.

How the financial impact changed

M&S’s disclosures answer different questions, so the figures should not be treated as interchangeable.

Date or period Disclosure What it means
22 April 2025 Cyber incident disclosed M&S began containing the incident and taking systems offline.
21 May 2025 Approximately £300 million Estimated reduction in 2025/26 operating profit before insurance, cost reductions and trading actions.
26 weeks ended 27 September 2025 £101.6 million incident-related costs; £100 million insurance income Adjusted profit before tax was £184.1 million, compared with £413.1 million a year earlier.
52 weeks ended 28 March 2026 £131.3 million incident-related costs; £100 million insurance proceeds Adjusted profit before tax was £671.4 million, down from £881.1 million.

The full-year accounts also reported £292.1 million of total adjusting items, of which the cyber incident was one component. The £131.3 million is therefore the amount M&S classified as directly associated incident costs in adjusting items, not a complete measure of lost sales, disruption or longer-term economic damage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: M&S full-year results, full-year results PDF and half-year results.

Why £300 million is not the final bill

The May 2025 estimate covered the expected effect on Group operating profit before mitigation. M&S said mitigation included insurance recovery, cost control and trading measures. The later £131.3 million figure records direct incident-related costs in the accounts, while the £100 million represents insurance income recognised centrally in adjusted profit. M&S has not presented the insurance proceeds as proof that every loss was reimbursed, nor has it stated that the direct-cost figure captures all lost profit.

The company described the year as one of two halves: severe operational disruption in the first half, followed by recovery and growth in the second. Second-half adjusted profit before tax rose 4.1%, but the full-year comparison still reflected the earlier shock.

What the attack disrupted

M&S took systems offline to contain and manage the incident. Warehouse-management systems were disconnected, and online orders, Click & Collect and in-store ordering were paused. Stores remained open, but the retail operation continued with significant constraints.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Food operations

Food teams relied on manual forecasting, ordering and replenishment. Reduced availability affected sales, while manual handling increased waste and logistics costs. Food sales still rose 7.8% in the first half and 7.0% for the full year, but availability and supply-chain disruption limited performance.

Fashion, Home & Beauty

The online offer and fulfilment disruption hit this division hardest. First-half sales fell 16.4%, with adjusted operating profit of £46.1 million. Full-year sales were down 7.7%. The annual decline also reflects wider trading and strategic factors, so it should not be attributed entirely to the cyber incident.

International

International sales fell 11.6% in the first half, with adjusted operating profit of £13.3 million, and fell 7.2% for the full year. Again, M&S’s accounts include factors beyond the cyber disruption.

The operational chain was: systems taken offline, followed by warehouse and ordering disruption; paused digital and collection services; lower availability and sales; and additional manual-processing, waste, logistics and stock-management costs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

M&S said the online offer was restored in August 2025. At the half-year stage, practically all operational systems had been recovered, although resilience and recovery work continued. Sources: April and May 2025 disclosures, operational update and half-year results.

What customer data was taken?

M&S says some personal customer data was taken, but it said there was no evidence that the data had been shared. Potentially affected information included:

  • names, email addresses, postal addresses and telephone numbers;
  • dates of birth;
  • online order history and household information; and
  • masked payment-card details used for online purchases.

The company said the data did not include usable card or payment details and did not include account passwords. “Payment information stolen” and “passwords compromised” are therefore inaccurate descriptions of the company’s notice.

M&S advised customers to be alert to fraudulent emails, calls and texts, and said customers would be prompted to reset their passwords at their next website or app login. Read the company’s customer notice at M&S’s cyber update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Did M&S pay a ransom?

M&S has not publicly confirmed whether a ransom was paid. At its 2025 annual general meeting, the company said it could not comment on whether funds had been paid to attackers, following advice from specialist advisers, government agencies and law enforcement. The AGM answers are available in M&S’s 2025 Q&A document.

Which authorities were notified?

M&S said it reported the incident to relevant authorities and law enforcement. Its 2026 annual report says the company reported it to the National Cyber Security Centre and the Information Commissioner’s Office. As of 19 May 2026, M&S said it was still cooperating with investigations by the ICO and other relevant regulators. See the 2026 annual report.

Has the crisis ended?

By the half-year reporting stage, M&S said customer-facing systems had been restored and practically all operational systems had recovered. The full-year results reported stronger sales and profit in the second half, alongside a plan for 2026/27 focused on availability, service levels and technology resilience. Recovery does not mean every consequence has been closed: regulatory cooperation and resilience work were continuing in May 2026.

What this shows about retail cyber risk

The M&S case demonstrates why a retailer’s cyber cost extends beyond website downtime. A serious incident can interrupt warehouse systems, replenishment, inventory visibility, delivery planning, customer collection and digital conversion. Those interruptions can create lost sales, waste, emergency manual work, logistics expense and rebuilding costs. Insurance may offset part of the accounting impact, but it does not make the operational disruption disappear.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bottom line

M&S did not ultimately report a £300 million direct loss to hackers. It initially estimated an approximately £300 million pre-mitigation impact on operating profit, then reported £131.3 million of directly associated incident costs and £100 million of insurance proceeds. The wider damage was visible in lower profit, disrupted sales and months of operational workarounds. Customer data was taken, according to M&S, but usable payment details and passwords were not included; the final regulatory and investigative picture remained incomplete as of May 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.