A Major Cyberattack

On April 25, 2025, the British retail giant Marks & Spencer (M&S) was hit by a significant cyberattack that paralyzed its online operations for several weeks. The chain, which has about 22 million Sparks loyalty card holders, confirmed on May 13, 2025, that customer data had been stolen during the attack.

According to information gathered by the BBC, the attackers demanded a ransom of $4 million and accessed M&S systems through a third-party provider. The UK’s National Crime Agency (NCA) indicated that the suspected hackers were likely young and from the United States and the United Kingdom.

An Operational Paralysis for Weeks

The operational impact was considerable:

  • April 25, 2025: halt of online orders on the M&S website and app
  • May 22, 2025: website returned in consultation mode, without order taking
  • June 10, 2025: gradual resumption of online orders
  • August 11, 2025: return of the “click and collect” service, 15 weeks after the start of the attack

The cost of the attack is estimated at £300 million in losses for M&S, as reported by the company's management in July 2025.

The Co-op Also Hit

The attack on M&S is part of a wave of coordinated attacks targeting several British retailers in the spring of 2025. The Co-operative Group (Co-op), one of the UK's major supermarket chains, was also targeted in May 2025, causing stock shortages in several stores.

On July 16, 2025, the CEO of Co-op confirmed that data from all 6.5 million members of the cooperative had been stolen. She apologized to customers, expressing that she was “incredibly sorry.”

The luxury department store Harrods was also targeted during this period, reinforcing the hypothesis of a coordinated campaign against major British retailers.

Potentially Exposed Data on the Dark Web

In ransomware attacks, cybercriminals frequently use the technique of double extortion: data is first exfiltrated, then victims are threatened with publication or sale on the dark web if the ransom is not paid. Groups like DragonForce, a ransomware gang operating on an affiliate model, have been mentioned in connection with these attacks.

Compromised data may include:

  • Names, postal addresses, and email addresses
  • Phone numbers
  • Purchase histories and consumer preferences
  • Loyalty card data
  • Contact information potentially exploitable for targeted phishing

The sale of such data on dark web forums exposes victims to risks of identity theft, personalized phishing, and financial fraud.

Lessons from an Unprecedented Crisis

In October 2025, the BBC published an analysis titled “The true cost of cyber attacks”, highlighting that these major attacks resulted from a form of “cumulative inaction on cybersecurity” by the government and large British companies.

Several key lessons emerge:

  1. Supply Chain Security: the initial access via a third-party provider underscores the importance of securing the entire IT ecosystem, not just one’s own systems.
  2. Offline Continuity Plans: British authorities have recommended that companies prepare for switch-over plans to offline systems in the event of a cyberattack.
  3. Transparent Notification: the delay between the attack (April 25) and the confirmation of data theft (May 13) – nearly three weeks – raised questions about the transparency of communication.
  4. Human Factor: the presumed involvement of young, Western hackers reminds us that cybercriminal groups are not exclusively based in rogue states.

What Should Affected Customers Do?

If you are a customer of M&S, the Co-op, or another retailer affected by a data breach:

  • Monitor your emails and be wary of messages seeming to come from known brands (phishing)
  • Enable two-factor authentication (2FA) on all your online accounts
  • Check your bank statements regularly for any suspicious transactions
  • Do not reuse the same password across multiple services
  • In France, you can report a data breach to the CNIL (www.cnil.fr)

A Warning Signal for the Entire Retail Sector

The attacks against M&S, the Co-op, and Harrods in 2025 mark a turning point in the targeting of the retail sector. With millions of customers and vast amounts of data, these retailers are prime targets for cybercriminals. The incident serves as a reminder that cybersecurity is no longer an option for retailers but a strategic necessity on which customer trust and the very survival of the business depend.