Analysis of the 2025 Marks & Spencer Ransomware Attack

Since digital technology is being used more and more, cybersecurity has become a major issue for large businesses. Stores like Marks & Spencer (M&S) make use of digital systems for online shopping, for payments, for managing their stock, for logistics and for providing customer services. As these systems are closely linked, a cyberattack can have an impact not only on the computer systems but also on normal business operations. In April 2025 M&S had a serious cyber incident which disrupted a number of its services. As a precaution the company put some of its systems offline and temporarily halted online orders. The disruption also had an effect on warehouse and ordering procedures, so the company was forced to resort to manual methods in order to carry on with its operations. M&S later stated that some personal customer information had been obtained, even though usable details of payment cards and account passwords were not included. This case study looks at the M&S cyberattack, with emphasis on the nature of the incident, its possible technical features, the effect on business operations and on customers, and the actions taken by the company. It also considers the financial impact of the incident and the kind of cybersecurity measures that can help organisations prepare for similar attacks. M&S first estimated that the incident could reduce its operating profit for the 2025/26 financial year by about £300 million before taking into account mitigation, insurance and trading measures. The purpose of the study is to demonstrate that cybersecurity should be viewed not just as an IT issue but also as an important element of business continuity and organisational risk management.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-08
DOI
https://doi.org/10.5281/zenodo.23242454
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Analysis of the 2025 Marks & Spencer Ransomware Attack

Atifa-alt, Atifa Asim
Zenodo (CERN European Organization for Nuclear Research)
Information and Cyber Security
article

Analysis of the 2025 Marks & Spencer Ransomware Attack

Atifa-alt, Atifa Asim
article en

Abstract

Since digital technology is being used more and more, cybersecurity has become a major issue for large businesses. Stores like Marks & Spencer (M&S) make use of digital systems for online shopping, for payments, for managing their stock, for logistics and for providing customer services. As these systems are closely linked, a cyberattack can have an impact not only on the computer systems but also on normal business operations. In April 2025 M&S had a serious cyber incident which disrupted a number of its services. As a precaution the company put some of its systems offline and temporarily halted online orders. The disruption also had an effect on warehouse and ordering procedures, so the company was forced to resort to manual methods in order to carry on with its operations. M&S later stated that some personal customer information had been obtained, even though usable details of payment cards and account passwords were not included. This case study looks at the M&S cyberattack, with emphasis on the nature of the incident, its possible technical features, the effect on business operations and on customers, and the actions taken by the company. It also considers the financial impact of the incident and the kind of cybersecurity measures that can help organisations prepare for similar attacks. M&S first estimated that the incident could reduce its operating profit for the 2025/26 financial year by about £300 million before taking into account mitigation, insurance and trading measures. The purpose of the study is to demonstrate that cybersecurity should be viewed not just as an IT issue but also as an important element of business continuity and organisational risk management.

Zenodo (CERN European Organization for Nuclear Research)
Narayana Health (IN)
Openalex Percentile: Top 6%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.