Skip to Content

M&S: £300M Hit and 46 Days With No Online Sales

The 2025 cyberattack on Marks & Spencer showed how an IT incident becomes a financial-results event. See the vectors such attacks typically exploit and how to protect your operation in layers.
August 12, 2026 by
M&S: £300M Hit and 46 Days With No Online Sales

Seven weeks without online sales: the case that became a line item on the balance sheet

In April 2025, British retailer Marks & Spencer was the target of a cyberattack that drew widespread international attention. The company suspended orders through its website and app for roughly seven weeks, approximately 46 days, and faced contactless payment failures and stock shortages in physical stores, according to BleepingComputer's coverage. For a retail operation, that means the digital channel ceased to exist for more than an entire month.

M&S publicly confirmed that customers' personal data had been accessed, although it stated that full card data and passwords were not part of the affected set. Reports from specialized outlets attributed the incident to the group known as Scattered Spider, using the DragonForce ransomware. It is worth separating official statements from journalistic attribution: the company confirmed the data access, while the perpetrators and the ransomware family circulated in the press.

The figure that captured the market's attention came later. In a statement to investors, the company estimated an impact of roughly £300 million on operating profit for the fiscal year, close to US$ 400 million, partially offset by insurance and other mitigation measures. It is one of the best-documented records of how a cyber incident stops being an IT problem and becomes an earnings event, with effects on revenue, reputation, and market value.

None of this is exclusive to corporate giants. The global average cost of a data breach was US$ 4.88 million in 2024, according to IBM's Cost of a Data Breach Report. Midsize companies don't have £300 million in operating profit to absorb the shock, nor a robust insurance policy, nor a dedicated legal department. The headline is smaller, and the chance of not surviving the interruption is greater.


Vectors that incidents like this one typically exploit

The internal details of the incident are not public, and no external analysis can state what failed inside the organization. What can be done, with real value for decision-makers, is to look at the vectors that attacks of this nature against large operations generally exploit, and use them as a mirror for your own structure.

Engenharia social contra pessoas, não contra firewalls. Grupos que atuam nesse perfil são conhecidos por ligar para centrais de suporte se passando por funcionários e solicitar redefinição de senha ou cadastro de um novo dispositivo de autenticação. Imagine o cenário na sua empresa: alguém liga para o suporte às 19h de uma sexta-feira, cita o nome do gestor da área, informa matrícula e data de nascimento obtidos em redes sociais e alega ter perdido o celular corporativo. Se a verificação de identidade depender do bom senso do atendente, o invasor não precisa de nenhuma vulnerabilidade técnica. Segundo o Data Breach Investigations Report da Verizon de 2024, 68% das violações envolveram um elemento humano não malicioso.

Valid credentials and forgotten third-party access. A good share of initial access isn't a break-in, it's a login. Accounts belonging to system vendors, integrators, and contractors tend to retain permanent administrative privileges, with no expiration and no multifactor authentication. The practical scenario is a familiar one: a VPN user created for a migration project that ended two years earlier, with a password reused on a personal service that was leaked. From the system's point of view, whoever logs in is a legitimate user at a legitimate time.

Flat networks and excessive privileges. The difference between a single-machine incident and a weeks-long shutdown almost always lies in what happens after the first access. When the ERP, file server, inventory system, point of sale, and backup environment all coexist on the same network without segmentation, and the same local administrative account exists on all of them, the attacker moves through the entire operation in a matter of hours. Segmentation doesn't prevent entry, it limits the scale of the damage.


Layered protection: what can be done in your environment

Behavioral detection with response. Traditional antivirus compares files against known signatures. EDR (Endpoint Detection and Response) watches behavior, and for that reason it can spot a service account that starts deleting shadow copies in the middle of the night even when no cataloged malware is involved. Combined with proactive 24/7 monitoring with human triage, the alert turns into containment. Without on-call coverage, the alert simply waits for business hours to start, and IBM's 2024 Cost of a Data Breach Report points to an average of 258 days to identify and contain a breach.

Isolated, immutable, and tested backups. In 94% of ransomware attacks, the criminals attempted to compromise the victim's backups, according to Sophos's State of Ransomware 2024. A copy that is reachable over the same network and with the same credentials as the production environment is an asset for the attacker. A mature backup and disaster recovery strategy provides for logical isolation, encryption, immutability, and full restoration tested on a fixed schedule.

Identity and attack surface under control. Phishing-resistant multifactor authentication on all external access, periodic review of privileged accounts, removal of third-party access at the end of a contract, and continuous patch management make up the cheapest layer and the most postponed one. Patching applied within a defined window, with an up-to-date inventory, eliminates most automated opportunities.

Trained people and a rehearsed crisis. Ongoing training with phishing simulations and a formal identity verification script at the help desk measurably reduces the human vector. Alongside that, a documented incident response plan — with defined roles, a communication tree, criteria for shutting systems down and legal contacts — needs to be exercised. Under regimes such as GDPR and LGPD, notification deadlines run while the operation is still putting out the fire.


Questions every decision-maker should be asking right now

Before any budget discussion, three questions separate those who have a strategy from those who have a collection of tools:

  • Would my backups really work in a disaster like this one? How long would it take for my operation to come back online?
  • Does my team have the right tools to identify and block an attack before disaster strikes? How am I investing in their readiness?
  • How long would my company survive without access to its systems and files?

Would my backups really work in a disaster like this one? How long would it take for my operation to come back online?

Having a backup is not the same as having the ability to recover. Copies reachable over the same network and with the same credentials as the production environment are a priority target, which is why a backup that holds up in a disaster is isolated, encrypted, immutable and validated through a full, timed restore. That test is what turns RTO and RPO into numbers you can defend before the board, rather than an intention written into a policy and never exercised.

Does my team have the right tools to identify and block an attack before disaster strikes?

There are two distinct layers here. In terms of tools, the practical difference lies between signature-based detection and behavioral detection with the ability to isolate an endpoint automatically. Detection with no one to respond is just an alert sitting in a queue, which is why continuous monitoring with human triage weighs as much as the agent installed on the machine — something a managed security operation sustains outside business hours. In terms of readiness, it is usually the inexpensive measures that get neglected: formal identity verification at the help desk, phishing simulations with metrics by department and a response plan rehearsed at least once a year.

How long would my company survive without access to its systems and files?

This question translates security into the language of business. Marks & Spencer went roughly 46 days without online sales because it had the cash, the insurance and a century-old brand to carry it through the gap. Few companies have that margin. Calculating revenue per hour of downtime, then adding idle labor, contractual penalties and customer loss, produces a number that tends to surprise the executive team. With that figure in hand, the annual cost of monitoring, patch management, isolated backup and incident response stops being an expense and becomes a direct comparison with a week of interrupted operations.


Frequently asked questions

What does the Marks & Spencer case reveal about cyber risk in operations that depend on systems?

The April 2025 attack kept the retailer's online sales suspended for roughly 46 days and had an impact the company itself estimated at around £300 million in operating profit for the fiscal year. The case shows that the main financial loss does not come from the ransom, but from the prolonged interruption of operations. Companies without cash, insurance and an established brand tend to suffer proportionally more from the same window of downtime.

How do I know whether my backup would withstand a ransomware attack?

A backup is only reliable when it is isolated from the production network, protected by separate credentials, encrypted and stored in an immutable format that prevents modification or deletion within a defined period. The decisive test is a full, timed restore of a critical system, performed on a fixed schedule. A status dashboard showing green does not prove recovery; it only indicates that the copy routine ran.

What is the difference between traditional antivirus and EDR?

Traditional antivirus identifies threats by comparing files against a database of already known signatures, which leaves it blind to new code or to the abuse of legitimate system tools. EDR, short for Endpoint Detection and Response, analyzes process behavior and makes it possible to automatically isolate a compromised endpoint. Its real value depends on having monitoring and human response available outside business hours, when most attacks make their move.


If your company does not yet have an integrated layered protection strategy, consider scheduling a Strategic IT Assessment, with no obligation, to identify vulnerabilities before they become headlines.

M&S: £300M Hit and 46 Days With No Online Sales
August 12, 2026
Share this post
Tags
Archive