Marks & Spencer has apologised to customers following revelations that the British high-street stalwart has been impacted by a ‘cyber incident’ in recent days.
In a note issued to the London Stock Exchange, M&S said that it had been forced to make ‘minor, temporary changes’ to its store operations in order to protect customers while it managed the event, but stressed that stores would remain open, and that both the M&S website and app would operate as normal.
The company said it had already reported the incident to data protection authorities and the National Cyber Security Centre, as well as engaging the services of external cybersecurity experts to assist with investigating the incident, with plans to take whatever action is needed to further protect its network.
In a message posted to social media following the disclosure of the M&S cyber incident, chief executive Stuart Machin reassured customers that, apart from some limited delays to certain orders, the impact would be minimal.
“To protect you and the business, it was necessary to temporarily make some small changes to our store operations, and I am sincerely sorry if you experienced any inconvenience,” wrote Machin.
“I know how much our customers trust M&S, and that trust is incredibly precious to us.
“We have been working hard with the best experts to manage this, and I want to thank them and my colleagues for their hard work.”
Reports from customers on social media over the weekend suggested that certain outlets had been hit with IT issues, with contactless payments suspended and long queues to collect orders, however the retailer has since said the payment issues have been fixed and it is working to resolve other issues.
Recommended reading
- 60% of Businesses Anticipating a Cyber-breach in 2025
- VPN Security Fears Pushing Firms To ‘Zero Trust Everywhere’
- Growing Adoption of Zero-trust and Multi-cloud Environments
Marks and Spencer’s cyber incident follows only a few months behind the hack of Blue Yonder, a provider of supply chain software used by some of the UK’s major supermarkets.
In that incident, Blue Yonder admitted to the Grocer that it had suffered a ransomware attack impacting its private cloud, with Morrisons supermarket forced to revert to a backup system and Sainsbury’s reportedly resorting to contingency plans to keep operations moving.





