Marks & Spencer confirmed it was managing a cyber incident after problems with contactless payments and click-and-collect over the Easter weekend. It paused online orders on 25 April, and the Co-op and Harrods disclosed attacks within days.
What happened
- M&S chairman Archie Norman later told MPs that the attackers got in through a sophisticated impersonation of one of its third-party users, and M&S confirmed that some customer personal data had been taken.
- M&S began taking online orders again on 10 June, about seven weeks later, and estimated a hit to operating profit of around £300m.
- The Co-op shut down IT systems, leaving some stores short of stock, and later confirmed that personal data of all 6.5 million of its members had been copied.
- On 10 July 2025 the National Crime Agency arrested four people aged 17 to 20 in connection with the attacks, which were widely linked in reporting to the Scattered Spider collective.
Why it mattered
The attacks brought ransomware and social engineering to the attention of the UK public and boards, and showed how service desk processes can be abused.
Lessons for organisations
Strengthen identity verification for password and MFA resets, including at outsourced help desks. Test incident response and recovery plans so that critical services can continue if core systems are taken offline.
Sources: National Crime Agency, BleepingComputer
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.