M&S Cyberattack to Slash Nearly One-Third of Annual Profits

Marks & Spencer (M&S), one of the UK’s leading retailers known for its clothing, homeware, and food products, has been hit hard by a recent cyberattack. The attack, which occurred during the Easter holiday, caused significant disruption to its operations, including empty food shelves in stores and a complete halt to online sales. The company has now revealed that the breach will wipe out almost a third of its expected annual operating profit.

In a statement released alongside its annual results, M&S estimated that the cyberattack would cost the company £300 million ($403 million) in operating profit for the fiscal year 2025/26. This represents a significant portion of the company’s projected profits, equating to 30.5% of the £984.5 million operating profit the company reported for the year ending March 29, 2025. However, the company noted that the financial impact would be mitigated to some extent through cost management, insurance, and other trading actions. Costs associated with the cyberattack will be reported separately as an adjusting item in its financial statements.

The timing of the cyberattack couldn’t have been worse. With M&S already facing the pressures of operating in a competitive retail environment, the attack led to severe operational disruptions. The cyberattack wiped out over £1 billion from the company’s stock market value, as the retailer struggled to regain control of its systems and resume normal operations. While M&S has indicated that some disruptions could continue until July, it is working swiftly to resolve the issues and restore online retail functions.

Describing the incident as a “highly sophisticated and targeted cyber-attack,” M&S acknowledged the limited period of disruption it caused but emphasized the broader, long-term implications. Despite the short-term losses, the company views the incident as an opportunity to accelerate its ongoing technology transformation. Last year, M&S announced plans to revamp its technology infrastructure, and this cyberattack has pushed the company to accelerate these efforts in a bid to prevent similar attacks in the future.

The company remains focused on strengthening its digital operations to ensure that it is better prepared for potential future cyber threats. While the financial impact of the attack is significant, M&S is determined to use the setback as a catalyst for positive change, accelerating its shift towards more robust and secure technological systems.

In the meantime, customers can expect continued disruptions in M&S’ online retail services. The company is working tirelessly to restore its systems to full functionality, and management has reassured investors and consumers alike that these efforts are a top priority. However, the retailer has acknowledged that full recovery may take some time, with the expected timeline stretching into the summer months.

This cyberattack has not only impacted M&S’ financial results but also raised awareness across the retail sector about the growing risks of cyber threats. As online shopping continues to dominate the retail landscape, the need for robust cybersecurity measures has never been more critical. For M&S, the path forward will likely include increased investment in technology, bolstered security measures, and a renewed focus on digital innovation to protect against future disruptions.

While the short-term financial setback is significant, M&S is determined to navigate this challenge and emerge stronger, having learned valuable lessons from the experience.

Share this article
Shareable URL
Prev Post

JPMorgan CEO Jamie Dimon Warns Markets Are Underestimating Economic Risks, Expects S&P 500 Earnings to Drop

Next Post

Target Cuts Sales Outlook: Tariff Uncertainty and DEI Backlash to Blame

Leave a Reply

Your email address will not be published. Required fields are marked *

Read next