---
title: "Marks &amp; Spencer: The £300m Cyber Lesson | Firevault"
description: "A ransomware attack on M&amp;S paused online orders from late April into July, hit profits by an estimated £300 million and exposed customer data. The root cause…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/marks-and-spencer-cyberattack-2025#webpage",
      "url": "https://fire-vault.com/news/marks-and-spencer-cyberattack-2025",
      "name": "Marks & Spencer: The £300m Cyber Lesson",
      "description": "A ransomware attack on M&S paused online orders from late April into July, hit profits by an estimated £300 million and exposed customer data. The root cause…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-news-article.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/marks-and-spencer-cyberattack-2025#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/marks-and-spencer-cyberattack-2025#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Marks & Spencer: The £300m Cyber Lesson",
          "item": "https://fire-vault.com/news/marks-and-spencer-cyberattack-2025"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Marks & Spencer: The £300m Cyber Lesson",
      "description": "A ransomware attack on M&S paused online orders from late April into July, hit profits by an estimated £300 million and exposed customer data. The root cause is a familiar one: too much critical data left connected.",
      "url": "https://fire-vault.com/news/marks-and-spencer-cyberattack-2025",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/og/og-news-article.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/og/og-news-article.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/og/og-news-article.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/images/og/og-news-article.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2025-10-20T09:00:00+00:00",
      "dateModified": "2026-07-04T16:03:24.303926+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/marks-and-spencer-cyberattack-2025"
      },
      "inLanguage": "en-GB",
      "articleSection": "Offline Security",
      "wordCount": 686,
      "keywords": "Marks, Offline Security, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "In late April 2025, Marks & Spencer paused online orders after a ransomware attack tore through its systems. By early June the retailer was only cautiously restarting a limited fashion range for home delivery in England, Wales and Scotland, with click-and-collect still offline and delivery windows stretched to ten days. M&S has said it will be July before operations are fully back to normal. The c",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2025
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedThe Cost, in NumbersWhy Firewalls Were Not EnoughWhat Physical Disconnection Woul…Lessons for Every RetailerConclusionShareMore Resources

[Knowledge Vault](/learn/knowledge)/ Offline Security 

Offline Security · 20 October 2025 

# Marks & Spencer: The £300m Cyber Lesson

A ransomware attack on M&S paused online orders from late April into July, hit profits by an estimated £300 million and exposed customer data. The root cause is a familiar one: too much critical data left connected.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025&text=Marks%20%26%20Spencer%3A%20The%20%C2%A3300m%20Cyber%20Lesson%0A%0AA%20ransomware%20attack%20on%20M%26S%20paused%20online%20orders%20from%20late%20April%20into%20July%2C%20hit%20profits%20by%20an%20estimated%20%C2%A3300%20million%20and%20exposed%20customer%20data.%20The%20root%20cause%20is%20a%20familiar%20one%3A%20too%20much%20critical%20data%20left%20connected.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025)[](mailto:?subject=Marks%20%26%20Spencer%3A%20The%20%C2%A3300m%20Cyber%20Lesson&body=A%20ransomware%20attack%20on%20M%26S%20paused%20online%20orders%20from%20late%20April%20into%20July%2C%20hit%20profits%20by%20an%20estimated%20%C2%A3300%20million%20and%20exposed%20customer%20data.%20The%20root%20cause%20is%20a%20familiar%20one%3A%20too%20much%20critical%20data%20left%20connected.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025)

Offline Security #OSSOffline Secure Storage® 

Article record

**Offline Security**Category 

**20 October 2025**Published 

**4 min read**Reading time 

**Mark Fermor**Written by 

Why it matters

## What this means for organisations holding critical data

A ransomware attack on M&S paused online orders from late April into July, hit profits by an estimated £300 million and exposed customer data. The root cause is a familiar one: too much critical data left connected.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [The Cost, in Numbers](#section-1)
3.  03 [Why Firewalls Were Not Enough](#section-2)
4.  04 [What Physical Disconnection Woul…](#section-3)
5.  05 [Lessons for Every Retailer](#section-4)
6.  06 [Conclusion](#section-5)

**On this page**[What Happened](#section-0)[The Cost, in Numbers](#section-1)[Why Firewalls Were Not Enough](#section-2)[What Physical Disconnection Woul…](#section-3)[Lessons for Every Retailer](#section-4)[Conclusion](#section-5)

In late April 2025, Marks & Spencer paused online orders after a [ransomware attack](/threats/ransomware) tore through its systems. By early June the retailer was only cautiously restarting a limited fashion range for home delivery in England, Wales and Scotland, with click-and-collect still offline and delivery windows stretched to ten days. M&S has said it will be July before operations are fully back to normal.

The company estimates the incident will reduce this year's profits by around £300 million, equivalent to a roughly 30 per cent hit, some of which it hopes to recover through insurance.

## What Happened

M&S confirmed the incident as a ransomware attack. The BBC has reported that detectives are focusing on Scattered Spider, a group of English-speaking teenagers and young adults, using an affiliate service called DragonForce to run the extortion. The same criminals told the BBC they were also behind the Co-op ransomware attack and the attempted hack of Harrods.

CEO Stuart Machin confirmed the attackers got in via social engineering through a third party with access to M&S systems. The BBC has seen a gloating email sent to Machin apparently from the account of an employee at Tata Consultancy Services, which has provided IT services to M&S for over a decade.

## The Cost, in Numbers

-   **~£300m** estimated hit to this year's operating profit, before insurance recovery.
-   **~£3.8m** of clothing and home is spent on the M&S website and apps every day on average.
-   **From late April to July** of disruption to online orders, with click-and-collect offline for much of that window.
-   **Customer data stolen**: names, home addresses, phone numbers, email addresses, dates of birth and online order history. No usable payment or card details, and no account passwords.
-   **Share price fall** since the attack, alongside supplier disruption reaching Greencore (which resorted to pen and paper) and small brands such as Nails Inc.

> Source: [What can I buy online at M&S since the hack? — BBC News](https://www.bbc.co.uk/news/articles/c0el31nqnpvo)

## Why Firewalls Were Not Enough

M&S is a FTSE 100 retailer with mature IT and significant investment in cyber programmes. The incident did not happen because defensive tooling was absent. It happened because a valid login, obtained by impersonating IT support through a trusted third party, gave attackers the run of a connected estate. The National Cyber Security Centre has warned that criminals attacking UK retailers are actively impersonating help desks to break in.

Once inside, the difference between reading a shared drive and encrypting production systems is measured in hours, not weeks.

## What Physical Disconnection Would Have Changed

Firevault does not claim it could have stopped the initial credential compromise. What it changes is what happens next.

-   **Customer records held in offline Storage** cannot be exfiltrated by an intruder on the corporate network. There is no route to reach them.
-   **Immutable, physically disconnected backups** cannot be encrypted or deleted by ransomware. Restore times drop from weeks to days.
-   **Governed access windows** mean bulk reads of historical data raise flags long before an attacker can complete an extraction.

The connected estate can still be attacked. The question is what the attacker actually finds when they get there.

## Lessons for Every Retailer

-   Assume credentials will be compromised, including those of trusted third parties. Design the environment so that a single account cannot reach every system of record.
-   Treat customer data as an asset to be protected, not a resource to be perpetually available. Not every historical record needs to sit on always-on infrastructure.
-   Rehearse recovery from a genuinely offline copy. If your backups sit on the same fabric as production, they are hostages in waiting.

## Conclusion

The £300 million figure will be studied in boardrooms for years. The more useful takeaway is architectural: connected systems will keep being breached, and defence-in-depth alone will not change that arithmetic. The organisations that recover fastest are those that already decided which data does not belong online in the first place.

Firevault exists to make that decision practical. [Explore Vault](/vault) for board-level records, or [Storage](/storage) for customer and operational data at scale.

About the author

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

Firevault 

Offline Security 

### Co-op: £80m Profit Hit, 6.5 Million Members Exposed

A malicious cyber-attack on the Co-op in April 2025 lost £206m in revenue, hit half-year profits by £80m and exposed data on all 6.5 million members. Here is what happened, and why offline storage matters.

15 Oct 2025 4 min 







](/news/co-op-cyberattack-2025)[

Firevault 

Offline Security 

### Jaguar Land Rover: Production Severely Hit by Cyber-Attack

A cyber-attack severely disrupted JLR's UK vehicle production, forcing plants at Halewood and Solihull offline just as the new September registration plates came in. Here is why physical disconnection matters for OT.

10 Oct 2025 4 min 







](/news/jaguar-land-rover-ransomware-2025)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)[

![When Access Fails: Continuity Needs Offline Secure Storage](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg)

Industry Insight 

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min 







](/news/when-the-grid-fails-offline-secure-storage-business-continuity)

Share this article

Offline Security 20 October 2025 4 min read 

## Marks & Spencer: The £300m Cyber Lesson

A ransomware attack on M&S paused online orders from late April into July, hit profits by an estimated £300 million and exposed customer data. The root cause is a familiar one: too much critical data left connected.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Published by Mark Fermor , Director & Co-Founder 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025&text=Marks%20%26%20Spencer%3A%20The%20%C2%A3300m%20Cyber%20Lesson%0A%0AA%20ransomware%20attack%20on%20M%26S%20paused%20online%20orders%20from%20late%20April%20into%20July%2C%20hit%20profits%20by%20an%20estimated%20%C2%A3300%20million%20and%20exposed%20customer%20data.%20The%20root%20cause%20is%20a%20familiar%20one%3A%20too%20much%20critical%20data%20left%20connected.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025)[](mailto:?subject=Marks%20%26%20Spencer%3A%20The%20%C2%A3300m%20Cyber%20Lesson&body=A%20ransomware%20attack%20on%20M%26S%20paused%20online%20orders%20from%20late%20April%20into%20July%2C%20hit%20profits%20by%20an%20estimated%20%C2%A3300%20million%20and%20exposed%20customer%20data.%20The%20root%20cause%20is%20a%20familiar%20one%3A%20too%20much%20critical%20data%20left%20connected.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fmarks-and-spencer-cyberattack-2025)

[Read full article](https://fire-vault.com/news/marks-and-spencer-cyberattack-2025)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/offline-secure-storage/what-is-oss)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)