Marks & Spencer UK Click & Collect: Hack Recovery Update
The Marks & Spencer Cyberattack of 2024/2025: A Retail Resilience Guide
Table of Contents
As of August 12, 2025, the retail sector continues to grapple with the escalating threat of cyberattacks. the recent resumption of click-and-collect services by Marks & Spencer (M&S) following a meaningful four-month disruption serves as a stark reminder of the vulnerabilities faced by even established brands and the complex recovery process involved. This incident isn’t isolated; it’s part of a broader trend of ransomware attacks targeting critical infrastructure and consumer-facing businesses. This article provides a extensive analysis of the M&S cyberattack, its impact, the recovery strategy, and crucial lessons for retailers navigating the modern threat landscape.
Understanding the Marks & Spencer Cyberattack
In April 2024, Marks & Spencer disclosed a “cyber incident” that severely impacted its operations.The attack, later attributed to the ransomware group DragonForce by M&S Chairman Archie Norman, led to the temporary suspension of online orders for clothing and home goods, including both deliveries and the popular click-and-collect service. This wasn’t a simple website outage; it represented a significant disruption to a core component of M&S’s omnichannel retail strategy.
The Timeline of the Incident
April 25,2024: M&S halts online orders for clothing and home deliveries and click-and-collect following the discovery of the cyber incident.
June 10, 2024: Online orders for delivery are gradually reinstated.
August 12, 2025 (Present): Click-and-collect services are fully restored in the UK, though services remain paused in Ireland.
May 2024: M&S forecasts a £300 million loss in operating profit for the 2025/26 financial year due to the attack.
* July 2024: UK police arrest four individuals in connection with the M&S hack, alongside investigations into attacks on the Co-op and Harrods.
The Nature of the Attack: Ransomware and Data Theft
The attack involved ransomware, a type of malicious software that encrypts a victim’s data and demands a ransom payment for its release. While M&S has not publicly disclosed weather a ransom was paid, the significant financial impact suggests ample data compromise. Beyond the immediate disruption,the incident involved data theft,raising concerns about the potential exposure of customer data. The specific data compromised remains undisclosed, but typical targets in retail breaches include names, addresses, email addresses, and payment details.
Impact on marks & Spencer and the Wider Retail landscape
the M&S cyberattack had a multifaceted impact, extending beyond the immediate operational disruptions.
Financial Repercussions
M&S initially estimated the attack would cost approximately £300 million in lost operating profit for the 2025/26 financial year. The company hopes to mitigate this loss through insurance claims and cost control measures. Despite the significant financial hit, market reaction has been relatively muted, with shares experiencing a temporary dip but ultimately paring 2025 losses to 11% as of august 12, 2025, suggesting investor confidence in the company’s long-term prospects. analyst Kate Calvert of Investec believes the reinstatement of click-and-collect is a key signal of a return to normalcy and doesn’t anticipate a lasting impact on M&S’s valuation.
Operational Disruptions and Competitive Landscape
The forced offline taking of systems extended beyond the website, impacting in-store availability of both clothing and food products. This created an chance for competitors like Next (in clothing) and Sainsbury’s (in food) to gain market share.The disruption highlighted the interconnectedness of retail operations and the vulnerability of relying heavily on integrated systems.
Reputational Damage and Customer Trust
Cyberattacks erode customer trust. While M&S has taken steps to address the incident, the breach raises questions about the security of customer data and the company’s ability to protect sensitive information. Rebuilding trust requires transparency, proactive interaction, and demonstrable improvements in cybersecurity measures.
The Recovery Strategy and lessons Learned
M&S’s recovery strategy involved a phased approach, prioritizing the restoration of critical services while together investigating the attack and strengthening its cybersecurity defenses.
Phased Restoration of Services
The gradual reinstatement of online ordering, starting with deliveries in June 2024 and culminating in the full restoration of click-and-collect in the UK by August 2025, demonstrates a cautious and
