Marks & Spencer suspends online orders following a cyberattack
Marks & Spencer ceased accepting online orders in the UK and Ireland as part of the response to a cyber incident.

News summary
Marks & Spencer ceased accepting online orders in the UK and Ireland as part of the response to a cyber incident. Its physical stores remained open, but e-commerce and other digital processes were affected for weeks.
A security incident quickly turns into a sales and reputation issue. Recovery priorities, alternative channels and communication are as important as the technical response.
Source: Reuters — 25 April 2025
What happened
Marks & Spencer's cyber incident began around Easter 2025. The company suspended online orders in the UK and Ireland and only restored them gradually from June. Stores stayed open, though some products were out of stock.
The company said initial access was gained through social engineering targeting a third party, and estimated an impact of around £300 million on its operating profit for the year.
What it teaches any business selling online
The attack didn't need a sophisticated technical flaw: convincing someone able to reset access was enough. That puts the spotlight on support desks, internal or outsourced, and how they verify callers.
The second lesson is commercial: weeks without an online channel cost far more than the technical recovery.
What to review
Controls that directly affect this type of attack:
- Identity verification before resetting passwords or multi-factor authentication.
- Supplier and support access with least privilege and logging.
- A continuity plan for the sales channel: what can still be sold and how.
- Recoverable backups of the online shop, ERP and catalogue.
Frequently Asked Questions
- How did the attackers get in?
- According to the company, through social engineering aimed at a third party with access to its systems.
- Is a small online shop a target?
- Yes. Tricking the support desk into granting access works just as well against small organisations.
- Which measure has the most effect?
- Tightening identity checks at the support desk and requiring phishing-resistant MFA for administrative access.
This type of news demonstrates that cybersecurity, cloud and business continuity must be planned together. Seintec can help you do this in your organisation; contact us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.