Marks & Spencer (M&S) paused orders on its UK and Ireland websites and mobile apps on April 25, 2025, while responding to a cyber incident. Customers could still browse products online and visit open stores, but checkout was unavailable; earlier disruption had also affected contactless payments, delivery timing and click-and-collect operations. This was a 2025 event, not an ongoing online-sales outage in 2026. M&S later restored customer-facing systems and reported a return to sales and profit growth in the second half of its 2025/26 financial year.
The initial announcement did not establish that the attack was ransomware, identify the perpetrators or prove that the entire ecommerce platform had been destroyed. Subsequent disclosures showed wider operational disruption, some personal data taken and substantial financial costs.
What M&S actually suspended
In its April 25, 2025 update, M&S said it had paused orders through its websites and apps as a precaution while managing the incident. The distinction between browsing and buying mattered:
| Service or operation | Status during the disruption |
|---|---|
| Website and app product browsing | Still available |
| Website and app checkout | Orders paused |
| Physical stores | Open and trading |
| Click and collect | Disrupted; collections and processing were affected |
| Contactless payments | Previously disrupted, according to M&S’s April 23 update |
| Delivery and fulfilment | Delays and operational disruption were reported |
| Geographic scope | UK and Ireland websites and apps, plus some M&S-operated international websites, according to the 2025 financial statements |
The April 23 operational statement is available from M&S. Keeping a catalogue visible did not mean that inventory, warehouse or fulfilment systems were functioning normally.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Timeline: from operational problems to recovery
- April 2025: M&S began taking selected processes offline while responding to a cyber incident.
- April 21–23: Customers reported contactless-payment and click-and-collect problems. M&S acknowledged operational disruption. Contemporary chronology is documented by Al Jazeera.
- April 25: Website and app orders were paused, although browsing and store trading continued. See the company announcement.
- Late April and May: Disruption spread through warehouses, logistics, replenishment, recruitment and other processes. Stores used manual workarounds, and reports described stock shortages and delays.
- Summer 2025: M&S said customer-facing systems were progressively restored and that practically all operational systems had been recovered by its half-year reporting period.
- August 2025: Click and collect was reported as returning as recovery continued.
- November 2025: M&S quantified sales losses, incident costs and insurance proceeds in its half-year results.
- May 2026: M&S reported that sales and profit growth had resumed in the second half of 2025/26 in its full-year results.
Why an online outage affected stores and supply chains
This was not simply a broken checkout page. M&S said it disconnected warehouse-management systems as part of its response. That helped contain the incident but also interrupted the systems that connect online orders, stock visibility, fulfilment, click and collect, store ordering and replenishment.
The operational chain
- Warehouse management: Disconnecting systems reduced the ability to pick, pack and route orders automatically.
- Inventory visibility: Stores and websites could not reliably use normal real-time stock information.
- Replenishment: Ordering and forecasting moved to manual processes, increasing delays and the risk of shortages.
- Customer services: Click-and-collect processing and delivery commitments became harder to manage.
- Financial effects: Extra labour, logistics, waste and markdowns added to lost sales.
M&S described manual methods for trading, forecasting, ordering and replenishment in its half-year results. Stores remaining open therefore did not mean that every backend system was available.
Rank #2
What is known about the attack
Confirmed at the time
M&S publicly called the event a cyber incident. Its April 25 statement did not confirm ransomware, a criminal group, the initial access route or the full extent of data access. Contemporary coverage noted that the breadth of the shutdown prompted expert speculation about ransomware or extortion, but those were interpretations rather than findings established by M&S at that point. See Computer Weekly.
Later attribution reports
Security researchers and later reporting linked the incident to the Scattered Spider/Octo Tempest ecosystem and DragonForce ransomware. Those links should remain attributed: M&S’s public disclosures concentrated on the incident’s consequences rather than publishing a complete, independently verifiable technical attribution. It is not established here that Scattered Spider definitely carried out the attack, that DragonForce was definitively the malware used by M&S, that a help desk was certainly compromised, or that M&S paid a ransom. Claims that the M&S, Co-op and Harrods incidents were one coordinated operation also remain a matter for attributed reporting, not an uncontested fact. Al Jazeera’s account provides the relevant attribution context: https://www.aljazeera.com/news/2025/5/2/harrods-ms-hit-by-cyberattack-what-happened-who-was-behind-it.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
What happened to customer data
The data position changed as the investigation developed. Early April 25 coverage said there was no indication then that personal information had been exposed. M&S later told customers that some personal data had been taken. Its cyber update and customer FAQ listed potentially affected information as:
- Names
- Email and postal addresses
- Telephone numbers
- Dates of birth
- Online order history
- Household information
- Masked payment-card details used for online purchases
M&S said the data did not include usable payment details or account passwords and that it had no evidence the information had been shared. “No usable payment details” is more precise than saying no card information existed: masked card details could be included, but not details usable to make payments. The company said it reported the incident to relevant authorities, including the UK’s National Cyber Security Centre and Information Commissioner’s Office, in its 2025 financial statements.
Rank #4
What customers should do
M&S’s guidance does not require every customer to cancel a card or change every password. The practical steps are narrower:
- Be alert to emails, calls and texts claiming to be from M&S, especially messages about refunds, vouchers, deliveries or password resets.
- Do not provide a username, password or other account information in response to unsolicited contact.
- Handle links and attachments in incident-related messages cautiously; use the official M&S site or verified company channels instead.
- Reset your M&S password when prompted at the next website or app login.
- Monitor bank and other account activity for suspicious transactions or login alerts.
Be particularly wary of reused passwords: an M&S credential reused on another service could create a separate risk even though M&S said its own account passwords were not part of the taken data.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
How serious was the business impact?
M&S first estimated that the incident could reduce 2025/26 operating profit by approximately £300 million, before mitigation, insurance and other trading actions. That was an estimate of operating-profit impact, not a statement that M&S had simply “lost £300 million.” The estimate appeared in its 2024/25 full-year results.
| Measure | Reported result | Qualification |
|---|---|---|
| Adjusted profit before tax, first half 2025/26 | £184.1 million, versus £413.1 million a year earlier | M&S half-year results |
| Fashion, Home & Beauty sales, first half | Down 16.4% | M&S half-year results |
| Incident-related adjusting costs, first half | £101.6 million | M&S half-year results |
| Insurance proceeds | £100 million | Reported in the half-year and full-year disclosures |
| Adjusted profit before tax, full year 2025/26 | £671.4 million, versus £881.1 million | M&S full-year results |
| Incident-related adjusting costs, full year | £131.3 million | M&S full-year results |
| Fashion, Home & Beauty sales, full year | Down 7.7% | M&S full-year results |
Insurance reduced the accounting effect, but it did not restore missed sales, lost customer time, disrupted operations or trust. M&S said second-half sales and profit growth returned after the severe first-half disruption, indicating recovery rather than an absence of damage. The company’s complete figures are in its 2025/26 results.
Quick Recap
What the incident shows about retail cyber resilience
- Containment has a continuity cost: Taking warehouse and ordering systems offline may limit compromise while immediately damaging fulfilment and stock flow.
- Retail is tightly interconnected: Ecommerce, inventory, warehouses, payments and stores depend on shared operational data.
- Manual fallback must work at scale: It can keep stores trading, but usually requires more labour and creates delays, waste and markdowns.
- Public information evolves: Early statements can be necessarily incomplete while forensics and legal notifications proceed; later data findings should supersede assumptions based only on the first update.
- Recovery is progressive: A browseable website or restored checkout does not prove that every backend system has recovered simultaneously.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




