Marks and Spencer has revealed that the cyber attack which disrupted its operations earlier this year will cost the retailer around £136 million – a figure covering only the immediate systems response, recovery, and specialist professional support.
The incident, which took down M&S’s online systems from Easter into the summer, severely impacted trading and almost erased the company’s statutory profit before tax for the first half of the year. Profits fell from £391.9 million to just £3.4 million, though the retailer said it still expects full-year profit to be “at least in line with last year.”
The group’s adjusted profit before tax, which strips out certain one-off items, fell by more than half to £184 million, down from £413 million in the same period last year. M&S added that it expects to recover about £100 million through insurance claims related to the cyber attack.
Sales were hit hard as the company’s e-commerce platform remained offline from April to June, with some physical stores also experiencing empty shelves in the days after the breach. Click and collect services were only restored in August.
The attack was carried out by ransomware hackers who infiltrated M&S systems by tricking employees at a third-party contractor. Despite the disruption, M&S chief executive Stuart Machin said the retailer continued to record strong food performance, with “three years of consecutive monthly food volume growth.”
While overall sales volumes rose compared with the previous 12 months, the retailer’s fashion, home and beauty sales fell by 16.4%, and international sales were down 11.6%. Rival retailer Next confirmed it had benefited from M&S’s temporary halt in some sales.
The breach formed part of a wider wave of attacks against major British businesses, with the Co-op, Jaguar Land Rover, and Harrods also suffering operational disruption from cyber incidents this year.
The M&S attack is believed to have been carried out by DragonForce, a ransomware-as-a-service operation linked to the Scattered Spider group. First identified in 2023, DragonForce has been associated with several high-profile retail sector incidents and had listed 58 victims on its leak site between January and March.
Last month, four individuals were arrested in connection with the M&S, Co-op, and Harrods attacks as part of an ongoing National Crime Agency investigation.
Recommended reading
- How Scattered Spider’s Web Brought UK Retail to its Knees
- M&S Confirms Customer Data Breach After Cyber-attack
- Cyber-attacks A “Wake-up Call” to Retail Sector
The suspects – two British men aged 17 and 19, a 19-year-old Latvian man, and a 20-year-old British woman from Staffordshire – were detained on suspicion of offences including blackmail, money laundering, and organised crime under the Computer Misuse Act. All four have been released on bail, and their devices have been seized for forensic examination.
The National Cyber Security Centre (NCSC) responded to the string of attacks in May by issuing guidance to UK organisations, urging them to reinforce password reset policies, strengthen authentication for privileged accounts, and adopt multi-factor authentication across systems.
Despite the significant setback, M&S said it remains confident in its recovery trajectory, forecasting profits for the remainder of the year to reach “at least in line with last year.”





