Skip to main content

Marks & Spencer suspends online orders following a cyberattack

Marks & Spencer ceased accepting online orders in the UK and Ireland as part of the response to a cyber incident.

CybersecuritySeintec Team2-3 min read
Marks & Spencer suspends online orders following a cyberattack

News summary

Marks & Spencer ceased accepting online orders in the UK and Ireland as part of the response to a cyber incident. Its physical stores remained open, but e-commerce and other digital processes were affected for weeks.

A security incident quickly turns into a sales and reputation issue. Recovery priorities, alternative channels and communication are as important as the technical response.

Source: Reuters — 25 April 2025

What happened

Marks & Spencer's cyber incident began around Easter 2025. The company suspended online orders in the UK and Ireland and only restored them gradually from June. Stores stayed open, though some products were out of stock.

The company said initial access was gained through social engineering targeting a third party, and estimated an impact of around £300 million on its operating profit for the year.

What it teaches any business selling online

The attack didn't need a sophisticated technical flaw: convincing someone able to reset access was enough. That puts the spotlight on support desks, internal or outsourced, and how they verify callers.

The second lesson is commercial: weeks without an online channel cost far more than the technical recovery.

What to review

Controls that directly affect this type of attack:

  • Identity verification before resetting passwords or multi-factor authentication.
  • Supplier and support access with least privilege and logging.
  • A continuity plan for the sales channel: what can still be sold and how.
  • Recoverable backups of the online shop, ERP and catalogue.

Frequently Asked Questions

How did the attackers get in?
According to the company, through social engineering aimed at a third party with access to its systems.
Is a small online shop a target?
Yes. Tricking the support desk into granting access works just as well against small organisations.
Which measure has the most effect?
Tightening identity checks at the support desk and requiring phishing-resistant MFA for administrative access.

This type of news demonstrates that cybersecurity, cloud and business continuity must be planned together. Seintec can help you do this in your organisation; contact us.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.