Marks and Spencer Group Plc (M&S), the UK-based major retailer, has published its full year results to the end of March 2025, using the announcement to highlight that a cyber incident that started in April is expected to have a £300m financial impact on the 2025/26 operating profit.
The company says that it has tried to turn the incident into an opportunity by using the recovery process as a means to transform the technology infrastructure and to identify improved ways of working.
In the full year results media release M&S Chief Executive Stuart Machin stated:
“Over the last few weeks, we have been managing a highly sophisticated and targeted cyber-attack, which has led to a limited period of disruption. We have tackled this head on with incredible spirit, teamwork and deep sense of responsibility as we prioritised serving our customers.
“It has been challenging, but it is a moment in time, and we are now focused on recovery, with the aim of exiting this period a much stronger business. There is no change to our strategy and our longer-term plans to reshape M&S for growth and, if anything, the incident allows us to accelerate the pace of change as we draw a line and move on.
“Over the last 140 years, M&S has overcome many challenges – testament to the longevity of this brand. This incident is a bump in the road, and we will come out of this in better shape, and continue our plan to reshape M&S for customers, colleagues and shareholders.
“I would like to thank all of our colleagues and supplier partners for their hard work and dedication and, importantly thank our customers. They have been unwavering in their support, and we are incredibly grateful for their patience and trust in M&S.”
Further points given in the media release include:
- The M&S team has worked around the clock with suppliers and partners to contain the incident and stabilise operations, taking proactive measures to minimise the disruption for customers.
- M&S is seeking to make the most of the opportunity to accelerate the pace of improvement of its technology transformation and has found new and innovative ways of working.
- M&S is focused on recovery, restoring its systems, operations, and customer proposition over the rest of the first half, with the aim of exiting this period a much stronger business.
Industry comments
Jason Gerrard, Senior Director of Systems Engineering at cyber resilience company, Commvault:
“This morning’s news that M&S may not fully recover from its cyber attack until July is a stark reminder of the importance of true cyber resilience. Organizations can no longer afford to simply rely on their defences to keep attackers out, they must be able to recover fast. Behind the scenes, teams are scrambling to rebuild systems, trace breach origins, and restore customer data with forensic precision – all while execs are juggling regulators, insurers, auditors and shareholders. The longer it takes to return to ‘normal’, the more that ‘normal’ drifts further away, both in business operations and public perception. While recovery takes 24 days on average, some organizations don’t achieve business-as-usual for over 200 days, with M&S falling at the higher end of this scale.
“This headline-grabbing downtime should be a warning to others that preparation for such a scenario is vital. Having a tried and tested recovery plan in place and identifying your minimum viable company (MVC) ahead of time can help to reduce some of the damage that can very quickly spiral out of control. Understanding your MVC – the essential systems needed to stay operational – is central to achieving cyber resilience and maintaining continuous business, even amidst a cyber attack.
“The true power of the MVC model is not simply about responding to threats – it builds future-ready organizations that can adapt, recover, and lead, even in the most hostile conditions. In doing so, they are safeguarding their data and systems, as well as their reputation and long-term viability. If a brand as established as M&S can be brought to its knees by a cyber incident, what does that say about the average business? This is a market-wide wake-up call.”






