UK retailer M&S resumes click and collect services 15 weeks after disclosing a cyberattack, set to cost it ~£300M; M&S resumed online delivery orders on June 10
British retailer Marks & Spencer (MKS.L) has resumed taking click and collect orders for clothing …
Context & Ripple Effects
M&S’s recovery has unfolded in stages: it reopened online ordering in June after the April incident disrupted core digital retail operations. The company had already warned of an estimated £300M operating-profit impact, making the restoration of another fulfilment channel material to its recovery rather than a routine site update.
Earlier coverage also said customer data was taken in the attack, while M&S’s CEO described social engineering through a third-party supplier as the access route. That ties operational resilience, supplier controls and customer trust to the same incident.
First-order effects
- Customers can again use click and collect for clothing, restoring a fulfilment option that had remained unavailable after online delivery orders restarted.
- M&S can begin normalizing digital sales and store collection workflows, though the disclosed disruption and cost estimate remain part of the incident’s financial impact.
Second-order effects
- The staggered return of delivery and collection exposes how an outage in shared retail systems can disable multiple sales channels even after a storefront can accept orders again.
- Retailers and their suppliers face added pressure to test third-party access controls and recovery procedures, given M&S’s account of supplier-linked social engineering.
Third-order effects
- If prolonged, multi-channel outages continue to follow cyber incidents, retail resilience will increasingly be judged by the ability to restore fulfilment operations—not only by preventing data theft.
- The episode points toward cyber risk being treated as an operational and supplier-governance issue alongside an IT-security issue, although the wider pace of that shift cannot be determined from this case alone.
The trend: Cyberattacks are increasingly testing retailers’ end-to-end fulfilment resilience, with recovery measured channel by channel rather than by a single return to online service.