- M&S is facing continuous disturbance after a cyber attack
- The attack has affected contactless payment and clicks and collects systems
- It is still not clear whether any customer data is affected
British retail giant brands and Spencer have had to take some systems and processes offline after suffering a cyberattack that deactivated contactless and clicks and collects services in stores.
The disturbance has now continued for several days, with many stores that are still unable to process contactless payments, and now click and collect the break in all stores. New updates have confirmed that M&S has now stopped online orders as it deals with the attack reports Independent.
The dealer confirmed in a statement that in order to protect colleagues, partners, suppliers and the company, M&S “has made the proactive decision to move some [of our] Processes Offline ”, which would be in line with the response to a ransomware attack – although it is not yet clear whether this is the case.
Retail in danger
Physical stores, the site and the M&S app are still underway, but this disorder can be seriously expensive for a store as large as this – such as operational losses and damage to stores can be expensive.
The retail industry is a common target for cyber criminals, as even a few hours of downtime can cost millions of dollars, making companies more likely to pay a ransom and therefore more vulnerable.
Earlier in 2025, the Walmart membership program ‘Sam’s Club’ was hit by a ransomware attack that reportedly affected thousands of staff -illustrates the vulnerability of the sector.
“The retail industry operates on a very small profit margin, and therefore the amount of attention or budget they can give to tackle their cyber security position, usually button,” explains Pierre Noel, Field Ciso Emea at Expel.
“To tackle this, retailers need to implement a continuous quantification program for cyber risk. One of its results is to generate and prize credible event scenarios, as well as identify mitigating controls and their associated costs. that is acceptable and which is not. ”