Marks & Spencer (M&S) has resumed its click-and-collect service almost four months after a major cyber-attack caused widespread disruption to its operations.
The retailer’s systems were first hit over the Easter weekend in April, when hackers forced the company to take down part of its IT infrastructure. Online orders for clothing and home deliveries through the website and mobile app were halted, and in-store services including contactless payments and click and collect stopped working.
Contactless payments were later reinstated, and online orders returned in early June, but click-and-collect remained unavailable until now. A notice on the M&S website has confirmed: “Click & Collect is now available for fashion, home and beauty online orders.”
Click and collect, which allows customers to buy products online and pick them up in-store the next day, was the last major service to be restored. The retailer had also fully reinstated its Sparks membership scheme last month.
£300m cost to business
The ‘cyber incident’ is expected to cost M&S around £300 million this year, although the company hopes to recover some losses through insurance. Customer personal data – including names, email addresses, postal addresses and dates of birth – was taken during the attack.
In May, M&S said the breach was the result of “human error” and was caused by hackers gaining access to its systems through a third party. Chief executive Stuart Machin told reporters: “We didn’t leave the door open, this wasn’t to do with under-investment. Everyone is vulnerable. For us, we were unlucky on this particular day through some human error.”
Chair Archie Norman previously described the attack as “traumatic”, telling MPs that for a week the cyber team “had no sleep, or three hours a night” and that the business remained “in rebuild mode”.
Ransomware Group Link
The attack is believed to have been carried out by the DragonForce ransomware-as-a-service operation, likely an affiliate of the Scattered Spider group.
First identified in 2023, DragonForce has been linked to incidents targeting other retailers including the Co-op and Harrods, and listed 58 victims on its leak site between January and March this year.
Last month, four people were arrested as part of a National Crime Agency investigation into the attacks on M&S, Co-op and Harrods. The arrests included two British men aged 17 and 19 in the West Midlands, a 19-year-old Latvian, and a 20-year-old British woman from Staffordshire.
Recommended reading
- How Scattered Spider’s Web Brought UK Retail to its Knees
- M&S Confirms Customer Data Breach After Cyber-attack
- Cyber-attacks A “Wake-up Call” to Retail Sector
They were detained on suspicion of multiple offences under the Computer Misuse Act, including blackmail, money laundering and involvement in organised crime. All four have been bailed, and their electronic devices have been seized for forensic analysis.
The incidents prompted the National Cyber Security Centre in May to issue guidance urging organisations to strengthen their security processes. The NCSC advised reviewing password reset policies, particularly for IT help desks, and tightening authentication for senior accounts with escalated privileges. The agency also recommended implementing multi-factor authentication across all systems.





