The M&S cyber attack: how one impersonation stopped online orders for 46 days
In 2025, one of Britain's best-known retailers stopped taking online orders for 46 days, and its chairman later told lawmakers the attack began with an impersonation involving an outside company.[1][3] This case file covers the timeline, how the attackers got in, what it cost Marks and Spencer, and the one control that was missing.
What happened
Attackers first got into Marks and Spencer's systems on April 17, 2025.[1][2] Over the Easter weekend that followed, customers began reporting problems with contactless payments and click-and-collect orders, and the company said it was dealing with a cyber incident.[2]
The attackers used ransomware, software that scrambles files so they cannot be used until a ransom is paid. To stop it spreading, the company shut down large parts of its own systems, which knocked out a big part of how the business ran.[1] On April 25, it paused online orders through its website and app.[3]
The attackers did not contact the company until about a week after they first got in.[1] Online orders came back on June 10, 2025, 46 days after they stopped, and some services, such as click-and-collect, took months longer.[3][4]
How they got in
On July 8, 2025, M&S chairman Archie Norman gave evidence to a committee of members of Parliament. He described the entry as a sophisticated impersonation attack that involved a third party, meaning the attackers pretended to be someone they were not and used an outside company's role in M&S's IT to get access.[1][5] The company had earlier said the attack was caused by human error rather than a technical flaw.[6]
Reporting at the time connected the entry to IT support provided by an outsourcing partner, with attackers using login details obtained through that relationship.[1][7] In plain terms, the attackers did not break down a wall. They talked their way past people whose job was to help staff get back into their accounts.
Press reports and security researchers linked the attack to a loosely organized English-speaking group known for phone-based impersonation, using ransomware supplied by a criminal service.[1] No government agency has formally attributed the attack.
What it cost
M&S estimated the attack would reduce its operating profit by about 300 million pounds, before insurance and other steps to offset it.[3][6] The lost weeks of online sales, the manual workarounds in stores and warehouses, and the rebuilding of systems all fed into that figure.
Asked by MPs whether the company paid a ransom, Norman declined to say.[1][2] In July 2025, the UK's National Crime Agency arrested 4 people, several of them teenagers, in connection with attacks on M&S and other retailers.[8] They were arrested, not convicted, so they are not named here.
The missing control
The missing control: strict identity checks by any help desk, including an outsourced one, before it resets a password or login method for anyone who calls.
Help desks exist to get people back into their accounts quickly, which makes them a natural target for someone pretending to be a locked-out employee. If a reset required something a caller cannot fake from public information, such as a call back to a number already on file, approval from the employee's manager, or an in-person or video check against a known photo, the impersonation would have hit a wall. The same rules have to apply to every provider that can reset access for you, and you have to check that they follow them.
What to do in your business
- Write down how a reset is verified. Decide what proof anyone must give before a password or phone number on an account is changed, and share it with staff and IT providers.
- Call back on a known number. Never reset access for a caller on the same call; hang up and call the person back on the number already on file.
- Put it in your IT contract. Ask your managed IT provider to describe its identity checks in writing and to tell you every time it resets an account.
- Protect admin accounts more. Require a second person's approval before resetting any account with admin or finance access.
- Plan to run without systems. Know how you would keep taking orders and paying staff for 2 weeks if your computers were shut down.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the Caesars hack happened: a con at the outsourced IT help desk
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Infosecurity Magazine: M&S chair details ransomware attack, declines to confirm if payment was made
- BleepingComputer: M&S confirms social engineering led to massive ransomware attack
- Reuters via StreetInsider: After 46-day cyberattack pause, M&S resumes online orders
- Business Insurance: Britain's M&S restores click-and-collect 15 weeks after systems hacked
- UK Parliament: Business and Trade Sub-Committee oral evidence, July 8, 2025
- Express & Star: Marks & Spencer blames human error as cyber attack set to cost 300 million pounds
- Bloomberg: M&S says April cyberattack caused by third-party impersonation
- Security Affairs: UK NCA arrested four people over M&S, Co-op cyberattacks