UK retailer M&S begins accepting online orders again, seven weeks after disclosing a sustained cyberattack that cost it up to £300M in this financial year
Laura Onita / Financial Times :
Context & Ripple Effects
The restoration of online ordering is the first visible recovery milestone after an attack that had already forced M&S to warn of a £300M operating-profit impact and prolonged disruption. The incident had moved beyond a technical outage: M&S said customer data was taken, while other UK retailers also reported attacks in the same period.
The reported access route—social engineering through a third-party supplier—makes the recovery relevant to retail’s wider dependence on connected vendors, not just to M&S’s own systems.
First-order effects
- M&S can again serve online customers and begin recapturing digital sales that were unavailable during the outage, though the disclosed financial-year cost remains substantial.
- The restart shifts the company from emergency continuity measures toward restoring customer confidence, after a breach that included stolen customer data.
Second-order effects
- M&S’s suppliers, delivery partners and customer-service operations must absorb the return of online demand while controls are rebuilt around the supplier-linked access path.
- Rival retailers retain an opportunity to hold customers who moved their spending during the disruption; M&S’s speed and reliability of recovery will shape how much demand returns.
Third-order effects
- If supplier-mediated social engineering continues to be a common entry point, retailers will have to treat third-party identity controls and incident recovery as core operational resilience, rather than a back-office security function.
- The episode suggests cyber incidents can impair retail trading for weeks, making resilience planning increasingly consequential for profit guidance, insurance recovery and investor assessments.
The trend: Retail cyber risk is becoming an operational-resilience issue, with attacks on interconnected supplier and identity systems capable of interrupting customer-facing commerce for extended periods.