Case file · M&S 2025

The M&S cyber attack: how one impersonation stopped online orders for 46 days

Published 2026-09-29 · 4 min read · Missing control: Third-party help desk caller verification

In 2025, one of Britain's best-known retailers stopped taking online orders for 46 days, and its chairman later told lawmakers the attack began with an impersonation involving an outside company.[1][3] This case file covers the timeline, how the attackers got in, what it cost Marks and Spencer, and the one control that was missing.

What happened

Attackers first got into Marks and Spencer's systems on April 17, 2025.[1][2] Over the Easter weekend that followed, customers began reporting problems with contactless payments and click-and-collect orders, and the company said it was dealing with a cyber incident.[2]

The attackers used ransomware, software that scrambles files so they cannot be used until a ransom is paid. To stop it spreading, the company shut down large parts of its own systems, which knocked out a big part of how the business ran.[1] On April 25, it paused online orders through its website and app.[3]

The attackers did not contact the company until about a week after they first got in.[1] Online orders came back on June 10, 2025, 46 days after they stopped, and some services, such as click-and-collect, took months longer.[3][4]

How they got in

On July 8, 2025, M&S chairman Archie Norman gave evidence to a committee of members of Parliament. He described the entry as a sophisticated impersonation attack that involved a third party, meaning the attackers pretended to be someone they were not and used an outside company's role in M&S's IT to get access.[1][5] The company had earlier said the attack was caused by human error rather than a technical flaw.[6]

Reporting at the time connected the entry to IT support provided by an outsourcing partner, with attackers using login details obtained through that relationship.[1][7] In plain terms, the attackers did not break down a wall. They talked their way past people whose job was to help staff get back into their accounts.

Press reports and security researchers linked the attack to a loosely organized English-speaking group known for phone-based impersonation, using ransomware supplied by a criminal service.[1] No government agency has formally attributed the attack.

What it cost

M&S estimated the attack would reduce its operating profit by about 300 million pounds, before insurance and other steps to offset it.[3][6] The lost weeks of online sales, the manual workarounds in stores and warehouses, and the rebuilding of systems all fed into that figure.

Asked by MPs whether the company paid a ransom, Norman declined to say.[1][2] In July 2025, the UK's National Crime Agency arrested 4 people, several of them teenagers, in connection with attacks on M&S and other retailers.[8] They were arrested, not convicted, so they are not named here.

The missing control

The missing control: strict identity checks by any help desk, including an outsourced one, before it resets a password or login method for anyone who calls.

Help desks exist to get people back into their accounts quickly, which makes them a natural target for someone pretending to be a locked-out employee. If a reset required something a caller cannot fake from public information, such as a call back to a number already on file, approval from the employee's manager, or an in-person or video check against a known photo, the impersonation would have hit a wall. The same rules have to apply to every provider that can reset access for you, and you have to check that they follow them.

What to do in your business

Watch the case
How one impersonation froze M&S online salesDrops 2026-12-29
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Infosecurity Magazine: M&S chair details ransomware attack, declines to confirm if payment was made
  2. BleepingComputer: M&S confirms social engineering led to massive ransomware attack
  3. Reuters via StreetInsider: After 46-day cyberattack pause, M&S resumes online orders
  4. Business Insurance: Britain's M&S restores click-and-collect 15 weeks after systems hacked
  5. UK Parliament: Business and Trade Sub-Committee oral evidence, July 8, 2025
  6. Express & Star: Marks & Spencer blames human error as cyber attack set to cost 300 million pounds
  7. Bloomberg: M&S says April cyberattack caused by third-party impersonation
  8. Security Affairs: UK NCA arrested four people over M&S, Co-op cyberattacks