News: 1747819194

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

M&S warns of £300M dent in profits from cyberattack

(2025/05/21)


Marks & Spencer says the disruption related to its ongoing cyberattack is likely to knock around £300 million ($402 million) off its operating profits for the next financial year (2025/26).

The beleaguered high street retailer made the admission in its [1]fiscal 2025 profit and loss accounts for the year ended March 29 , published on Wednesday, following [2]reports that it could be gearing up to make a maximum claim on its cyber insurance policy to the tune of £100 million ($134 million).

Unending ransomware attacks are a symptom, not the sickness [3]READ MORE

The £300 million figure will be reduced through cost mitigations, insurance, and trading actions, M&S said, and it's expected that the total costs related to the attack itself and technical recovery will be communicated at a later date as an adjustment item.

CEO Stuart Machin said in the results [4]release : "Over the last few weeks, we have been managing a highly sophisticated and targeted cyberattack, which has led to a limited period of disruption. We have tackled this head-on with incredible spirit, teamwork, and a deep sense of responsibility as we prioritised serving our customers.

"It has been challenging, but it is a moment in time, and we are now focused on recovery, with the aim of exiting this period a much stronger business. There is no change to our strategy and our longer-term plans to reshape M&S for growth and, if anything, the incident allows us to accelerate the pace of change as we draw a line and move on."

[5]

The retailer said it wanted to make the most of the crisis "the opportunity" provided by the attack to accelerate a technical transformation, without detailing exactly what that transformation entailed.

[6]

[7]

"We are focused on recovery, restoring our systems, operations, and customer proposition over the rest of the first half, with the aim of exiting this period a much stronger business," it added.

Various divisions suffered an overall decline in operating profits. M&S said that early on into the attack, which has been [8]ongoing for about a month now, that some franchise stores, such as those inside train stations, were experiencing shortages of certain foods, such as "meal deal" sandwiches.

[9]

This reduced availability has affected food sales, and M&S also incurred additional waste and logistics costs owing to the shift toward manual processes.

After briefly managing to keep online and app sales running post-breach, these were [10]eventually taken offline along with other systems, and the company said online sales and trading profit was "heavily impacted" as a result.

Online sales in its fashion, home, and beauty divisions remain unavailable and are not expected to return until July, M&S revealed today.

[11]

"Overall, our strategy remains the same and there is no change to our longer-term plans to reshape M&S for growth. We are confident that we will enter the second half with a strong customer proposition, returning to the performance we were delivering immediately prior to the incident and throughout 2024/25, which is outlined in the following sections."

After posting its results this morning, M&S's share price was down 3 percent at the time of writing, and about 12 percent down since the start of the attack, representing a more than £1 billion ($1.3 billion) loss to its market valuation.

However, there are green shoots for the retailer, whose pre-tax and pre-adjusted profits were up 22.2 percent on the previous year at £875.5 million ($1.17 billion), which is the company's best performance in more than 15 years.

[12]Cyber fiends battering UK retailers now turn to US stores

[13]Here's what we know about the DragonForce ransomware that hit Marks & Spencer

[14]Marks & Spencer admits cybercrooks made off with customer info

[15]British govt agents step in as Harrods becomes third mega retailer under cyberattack

Overall, sales also grew 6.1 percent to £13.9 billion ($18.6 billion), and M&S reaffirmed its commitment to reduce its costs by £500 million ($670 million) in time for the 2027/28 financial year.

"Over the last 140 years, M&S has overcome many challenges – testament to the longevity of this brand," said Machin. "This incident is a bump in the road, and we will come out of this in better shape, and continue our plan to reshape M&S for customers, colleagues, and shareholders.

"I would like to thank all of our colleagues and supplier partners for their hard work and dedication and, importantly thank our customers. They have been unwavering in their support, and we are incredibly grateful for their patience and trust in M&S."

M&S disclosed the attack on April 22, and responsibility was soon ascribed to the English-speaking group known as [16]Scattered Spider , who reportedly used [17]DragonForce ransomware to infect the retailer's systems.

Nothing is officially confirmed on this front, although DragonForce took credit for the attack when [18]speaking to the BBC .

DragonForce said it was also involved in the attacks on [19]Co-op and Harrods , but none of the companies have yet appeared on its leak site, which is unexpected for intrusions that took place nearly a month ago.

M&S [20]confirmed last week that those responsible stole customer data including names, dates of birth, telephone numbers, home addresses, household information, email addresses, and online order histories.

It told the London Stock Exchange that the data did not include full payment card numbers or account credentials. ®

Get our [21]Tech Resources



[1] https://www.londonstockexchange.com/news-article/MKS/final-results/17046629

[2] https://www.ft.com/content/723b6195-1ce7-4b5f-94f5-729e9152c578

[3] https://www.theregister.com/2025/05/12/opinion_column_ransomware/

[4] https://www.londonstockexchange.com/news-article/MKS/final-results/17046629

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aC2kO92VQXiXubhiu0cUEAAAAlM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aC2kO92VQXiXubhiu0cUEAAAAlM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aC2kO92VQXiXubhiu0cUEAAAAlM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2025/04/22/marks_spencer_cyber_incident/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aC2kO92VQXiXubhiu0cUEAAAAlM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2025/04/25/ms_halts_online_orders/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aC2kO92VQXiXubhiu0cUEAAAAlM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2025/05/15/cyber_scum_attacking_uk_retailers/

[13] https://www.theregister.com/2025/05/15/dragonforce_ransomware_uk_retail_attacks/

[14] https://www.theregister.com/2025/05/13/ms_confirms_customer_data_stolen/

[15] https://www.theregister.com/2025/05/02/ncsc_steps_in_as_harrods/

[16] https://www.theregister.com/2025/05/18/ex_nsa_scattered_spider_call/

[17] https://www.theregister.com/2025/05/15/dragonforce_ransomware_uk_retail_attacks/

[18] https://www.bbc.co.uk/news/articles/cgr5nen5gxyo

[19] https://www.theregister.com/2025/05/02/ncsc_steps_in_as_harrods/

[20] https://www.theregister.com/2025/05/13/ms_confirms_customer_data_stolen/

[21] https://whitepapers.theregister.com/



A £300million reduction in profits

A Non e-mouse

How much would the IT upgrades & updates cost had M&S listened to their IT staff?

Re: A £300million reduction in profits

Doctor Syntax

The "accelerate a technical transformation" will mostly amount to doing just that. AKA shutting the stable door after the horse has bolted.

Re: A £300million reduction in profits

KittenHuffer

And will other businesses learn from their mistake?

"It could be that Walter's horse has wings" does not imply that there is
any such animal as Walter's horse, only that there could be; but "Walter's
horse is a thing which could have wings" does imply Walter's horse's
existence. But the conjunction "Walter's horse exists, and it could be
that Walter's horse has wings" still does not imply "Walter's horse is a
thing that could have wings", for perhaps it can only be that Walter's
horse has wings by Walter having a different horse. Nor does "Walter's
horse is a thing which could have wings" conversely imply "It could be that
Walter's horse has wings"; for it might be that Walter's horse could only
have wings by not being Walter's horse.

I would deny, though, that the formula [Necessarily if some x has property P
then some x has property P] expresses a logical law, since P(x) could stand
for, let us say "x is a better logician than I am", and the statement "It is
necessary that if someone is a better logician than I am then someone is a
better logician than I am" is false because there need not have been any me.
-- A. N. Prior, "Time and Modality"