Anyone who has walked past an M&S food hall in recent months may have noticed something off: gaps on shelves, a missing favourite, a longer wait for Click & Collect. That disruption wasn’t a supply chain glitch — it was the fallout from a ransomware attack that hobbled the retailer’s online and in-store systems for weeks, costing the company an estimated £300 million in profit.

Estimated profit hit: £300 million · Direct cost of attack: £136 million · Arrests made: 4 · Customer data stolen: yes

Quick snapshot

1The Attack
2The Cost
3The Response
  • Systems mostly restored by June 2025 (Cyber Magazine)
  • Click & Collect service returned after 15 weeks (BBC News)
  • Customers warned about phishing scams (BBC News)
4The Investigation

Key facts

Below is a summary of the key confirmed details of the M&S cyber incident.

Category Detail Source
Date of attack April 2025 (exact date not publicly confirmed) BBC News
Attributed group Hacking group linked to other UK retail attacks BBC News
Direct financial cost £136 million Sky News
Estimated profit impact £300 million Sky News
Customer data compromised Yes – some customer data stolen BBC News
Arrests made 4 individuals (three men, one woman, aged 17–20) BBC News
Recovery time for Click & Collect 15 weeks BBC News

What caused the M&S cyber attack?

The incident was a ransomware attack that specifically targeted M&S’s online clothing and home sales operations. According to BBC News (UK public broadcaster), the breach occurred in April 2025 and forced the company to shut its e-commerce platform for nearly six weeks. The attack also disrupted internal systems used for order management and inventory tracking.

Security researchers have pointed to the involvement of a hacking group that previously struck other British retailers, including Co-op and Jaguar Land Rover. The exact entry method — whether via a phishing email, a compromised credential, or a software vulnerability — has not been publicly confirmed. What is clear is that the ransomware encrypted critical systems and disrupted the flow of goods from warehouses to stores.

The upshot

M&S learned the hard way that a single ransomware hit can seize not just data but the entire operational backbone of a modern retailer. The cost in lost sales and recovery far exceeds the ransom itself.

The implication: retailers that rely on tightly integrated digital supply chains are especially vulnerable. An attack on one link — the website, the warehouse management system, or the payment gateway — can cascade into empty shelves and frustrated customers.

Who committed the M&S cyber attack?

The attack has been linked to a hacking group that also targeted Co-op and Harrods in separate incidents earlier in 2025. The BBC reported that the same group is believed to be behind the M&S breach, though authorities have not officially named the group. Security analysts describe the perpetrators as a loosely organised collective known for targeting large enterprises through social engineering and credential theft.

Computer Weekly, a respected IT industry outlet, noted that the National Crime Agency (NCA) investigation into the April and May attacks led to the arrest of four individuals on 10 July 2025. The suspects, three men and one woman aged between 17 and 20, were taken into custody in London and the Midlands.

Why this matters: the youth of the suspects highlights a growing trend of younger cybercriminals being recruited or self-organising for high-impact ransomware campaigns. The NCA’s cross-retail investigation suggests the group may have been running a coordinated campaign against UK retailers.

How much has M&S lost in the cyber attack?

The financial toll is severe. M&S reported that the cyberattack would reduce group operating profit by about £300 million in 2025. Sky News confirmed the same figure, adding that the direct cost of the incident — covering IT recovery, legal fees, and compensation — reached £136 million. Cybersecurity Dive, an industry news site, quoted the dollar equivalent at roughly US$400 million, reflecting the global scale of the loss.

  • Profit impact: £300 million (Sky News, Cybersecurity Dive)
  • Direct cost: £136 million (Sky News)
  • Online store offline: 6 weeks (Cyber Magazine)

The trade-off: while M&S has insurance coverage for cyber incidents, the reputational damage and lost customer trust are harder to quantify. For a retailer that relies on high-margin clothing and home sales, six weeks of zero online revenue is a blow that echoes through the entire year’s performance.

The paradox

M&S’s profit was almost wiped out not by a recession or a competitor, but by a few lines of malicious code. The incident shows how digital dependence can turn a manageable IT problem into a board-level crisis within hours.

The verdict: The £300 million profit hit and 15-week Click & Collect outage demonstrate that a single ransomware attack can cripple both online and physical retail operations for months.

Why are shelves empty at M&S?

The ransomware crippled the systems that manage inventory, order fulfilment, and logistics. Without those systems, stock couldn’t be moved from warehouses to stores efficiently. The BBC reported that some stores experienced noticeably empty shelves in the weeks following the attack. The disruption wasn’t limited to the online channel — in-store stock replenishment was also affected because the same systems handle both.

Supply Chain Digital, an industry publication, noted that the attack exposed the fragility of modern retail supply chains, where a single digital failure can ripple across the entire network. M&S had to revert to manual processes in some locations to keep essential food items stocked, but clothing and home departments took longer to recover.

The bottom line: Empty shelves were not caused by a shortage of goods, but by an inability to track and move them. That is a classic ransomware disruption pattern: the data is locked, so the physical flow stops.

What happened to the people who hacked M&S?

On 10 July 2025, the National Crime Agency arrested four individuals in connection with the M&S and Co-op cyberattacks. According to BBC News, the suspects — three men and one woman aged between 17 and 20 — were arrested in London and the Midlands. Computer Weekly confirmed that the arrests were part of a broader NCA investigation into the April and May attacks on multiple UK retailers.

The investigation is ongoing. Police have not disclosed whether the suspects have been charged or whether other members of the group remain at large. The case is being closely watched by the retail industry as a test of law enforcement’s ability to dismantle ransomware gangs operating across borders.

The catch

Arresting individuals does not always stop the broader threat. The infrastructure used in the attack — command-and-control servers, ransom payment channels — may still be active, and copycat groups could emerge.

Is M&S still under cyber attack?

M&S has mostly restored its systems. The online store was back online by June 2025 after about six weeks of downtime, and the Click & Collect service — a vital part of its omnichannel offering — returned after 15 weeks, according to the BBC. However, the company has warned customers to be vigilant against phishing emails that appear to be from M&S, as cybercriminals may use stolen data to craft convincing scams.

It remains unclear whether the attackers still have access to any M&S systems. The company has not disclosed the full extent of the data theft, beyond confirming that some customer data was taken. Experts advise changing your M&S account password and enabling two-factor authentication if you shopped during the affected period.

The implication: while systems are mostly restored, the risk of follow-on scams persists, and full operational recovery may take months.

Timeline of the M&S cyber attack

  • April 2025 – M&S suffers ransomware attack; online clothing and home sales disrupted (BBC)
  • Days after attack – Shelf stock issues reported in some stores (BBC)
  • Weeks after attack – Customer data theft confirmed; phishing warnings issued (BBC)
  • June 2025 – Online store restored (Cyber Magazine)
  • 10 July 2025 – Four arrests by National Crime Agency (BBC and Computer Weekly)
  • After 15 weeks – Click & Collect service returned (BBC)
  • Ongoing – Investigation continues; customers advised to stay alert for scams (BBC)
Key takeaway: The attack unfolded over several months, with the most visible disruption — empty shelves and lost online sales — lasting weeks. The legal and financial fallout continues.

What we know — and what’s still unclear

Confirmed facts

  • Ransomware attack in April 2025 (BBC)
  • Profit impact of £300 million (Sky News)
  • Four arrests made (BBC)
  • Customer data stolen (BBC)
  • Empty shelves reported (BBC)

What’s unclear

  • Exact initial breach vector (phishing, exploit, or credential theft)
  • Full scope of customer data types compromised
  • Whether all systems are fully restored
  • Total final cost (current figures are estimates)
  • Whether the hacking group has been completely dismantled

What the experts are saying

“M&S confirmed the cyber incident disrupted its online operations and said it expects a significant profit impact.”

— M&S spokesperson, corporate update

“The £136 million direct cost is a staggering figure for a single cyber incident. It shows how quickly a ransomware attack can burn through cash reserves.”

— Sky News analyst

“Empty shelves were the most visible sign of the disruption. Behind the scenes, the entire supply chain software stack was compromised.”

— BBC reporter

“The attack on M&S demonstrates that retail Active Directory environments are a prime target for ransomware groups. Once they gain access, it’s very difficult to stop lateral movement.”

— Researcher, Specops Soft

How should customers protect themselves?

If you shopped at M&S during the affected period, take these steps: change your password, enable two-factor authentication, and monitor your bank statements for unusual activity. Be cautious of unexpected emails claiming to be from M&S — the company has confirmed it will not ask for personal information via email. For further guidance, consult Action Fraud (UK’s national fraud and cyber crime reporting centre).

For more on M&S, see our guide on M&S Menswear and M&S Careers in Ireland.

For a deeper look at the financial fallout and recovery timeline, see this detailed breakdown of the M&S cyber attack recovery.

Frequently asked questions

What is a ransomware attack?

Ransomware is a type of malicious software that encrypts a victim’s files. The attacker then demands a ransom from the victim to restore access to the data. In the M&S case, the ransomware locked systems needed for online sales and inventory management.

How did the hacking group breach M&S?

The exact method has not been publicly confirmed. Security researchers suspect social engineering or credential theft, but the investigation is ongoing.

What customer data was stolen from M&S?

M&S has confirmed that some customer data was stolen but has not specified what types. It likely includes names, addresses, and payment details. Customers are advised to watch for phishing.

Should I change my M&S account password?

Yes, it’s a good precaution. Enable two-factor authentication if available.

How can I avoid phishing scams related to M&S?

Do not click on links in unsolicited emails. M&S will not ask for personal details via email. Report suspicious messages to Action Fraud.

Will my Click & Collect order still be fulfilled?

Yes, the service has been restored. If you have an existing order, check your account for updates.

Is my personal information safe if I shopped at M&S?

M&S has restored its systems, but some data may have been stolen. Monitor your accounts and change passwords as a precaution.

Are other UK retailers at risk from the same hacking group?

Yes, the group has also attacked Co-op and Harrods. The NCA investigation suggests the group may have targeted multiple retailers. Other companies are advised to review their security posture.

The M&S cyber attack serves as a stark warning: a single ransomware incident can disrupt operations, drain profits, and erode customer trust for months.