M&S cyber-attack expected to wipe put £300 million from profits – London Business News | Londonlovesbusiness.com

Date:

Share:


M&S has revealed the fallout from last month’s cyber-attack will drag on until July- with losses now expected to wipe £300m from profits.

Investigators are pointing to the notorious hacking community, Scattered Spider, as the likely culprit.

The breach has crippled M&S’s operations, with online clothing and home orders being suspended since the attack.

It’s part of a wider wave of cyber threats hitting UK retailers – Co-op and Harrods among the latest victims.

Cyber attacks have cost UK businesses £44 billion over the past five years, with over half suffering at least one breach.

M&S is reportedly claiming up to £100 million from its cyber insurance — potentially one of the largest ever payouts in the UK retail sector.

While cyber insurance premiums had recently eased, a rise in claims is expected to push prices back up.

Marks & Spencer said, “We expect online disruption to continue throughout June and into July as we restart, then ramp up operations.”

M&S chief executive Stuart Machin said, “Over the last few weeks, we have been managing a highly sophisticated and targeted cyber-attack, which has led to a limited period of disruption.”

He added, “This incident is a bump in the road, and we will come out of this in better shape, and continue our plan to reshape M&S for customers, colleagues and shareholders.”

Machin said that during the ank holiday weekend his team identified “suspicious activity,” but just last year they simulated a cyber-attack, so we “was ready.”

He added, “We were able to respond quickly and take the right actions immediately.

“We knew who to call and how to put the business continuity plan into action.”

Camellia Chan, CEO and founder at X-PHY said, “The attack on M&S is another stark reminder that ransomware gangs are evolving faster than traditional defences can cope.

“Groups like Scattered Spider aren’t just locking companies out of their systems – they’re embedding themselves deep inside critical infrastructure, moving quietly, and striking at the worst possible moment.

“Encryption attacks expose the fatal weaknesses of reactive, software-only security. Once systems are compromised, the damage is already done.

“Prevention must be built in from the ground up. Businesses need a multi-layered approach that combines hardware-level security to detect and block attacks early. This should be combined with an AI-driven threat detection layer that automate detection and enforce policies in real time. With human-error contributing to 95% of data breaches, this removes the burden of constant vigilance from employees and constant resilience testing.

“By shifting to proactive, embedded defence strategies where hardware and software work in tandem, businesses can limit the blast radius before they escalate and recover faster. In today’s threat landscape, resilience isn’t a luxury. It’s a survival necessity.”



Source link

━ more like this

From Microsoft to “microslop”: The AI backlash that forced a reset

At some point in 2025, Windows stopped feeling like an operating system and started feeling like a demo for AI. Open Notepad to...

Apple smart glasses might avoid the creepy reputation of Meta Ray-Bans with a light trick

Apple’s upcoming smart glasses could sidestep one of the biggest issues facing the category – privacy concerns – by rethinking something as simple...

The MacBook Neo is moonlighting as a Windows gaming machine, and it’s doing it well

Apple didn’t position its most affordable MacBook as a gaming machine. The MacBook Neo, a budget-leaning laptop that runs on Apple’s A18 Pro...

Apple glasses won’t go brand shopping like Meta did with Ray-Ban and Oakley

When it comes to smart glasses, Apple seems to be taking the road less traveled. While others have leaned on big-name eyewear brands...

I tried this Pokémon-inspired weather app, and checking the weather now feels like a Pokédex hunt

Weather apps are usually one of the most boring things on your phone. You open one, glance at the temperature, maybe check if...
spot_img