M&S says cyber hackers broke in through third-party contractor


Pedestrians walk past the Marble Arch branch of British retailer Marks & Spencer Plc in central London, Britain, May 18, 2025. REUTERS/Carlos Jasso/File Photo

LONDON (Reuters) -Marks & Spencer said hackers broke into its systems by tricking employees at a third-party contractor, skirting its digital defences to launch a cyberattack that will disrupt the British retailer for months.

Giving the first details since disclosing the breach on April 22, Chief Executive Stuart Machin said all companies were vulnerable, and M&S had boosted its defences by trebling tech spending in the last three years.

M&S has an IT contract with Tata Consulting Services. One source familiar with the matter told Reuters it was a means of access. TCS has declined to comment.

Machin declined to comment on TCS specifically when asked if it was the weak link.

"Unable to get into our systems by breaking through our digital defences, the attackers did try another route resorting to social engineering and entering through a third party rather than a system weakness," he told reporters.

"Once access was gained, they used highly sophisticated techniques as part of the attack."

Machin declined to comment on any ransom demand, citing advice from government agencies and law enforcement.

M&S stopped online sales. It said on Wednesday they were unlikely to be fully restored until July.

Machin said M&S became aware of the breach when it spotted suspicious activity during the Easter weekend of April 19-20.

He said the time between the hackers gaining access and detection was "short". Experts told the company that the average was 10 days and in some cases many months.

Britain's National Crime Agency told the BBC the attack investigation was focused on a cluster of young, English-speaking hackers.

M&S, which has sales of nearly 14 billion pounds ($19 billion) a year, immediately called in experts, partners and authorities, Machin said.

Some 600 systems had been scanned for damage, he said, and they were gradually being brought back online.

($1 = 0.7459 pounds)

(Reporting by Paul Sandle and James Davey. Editing by Mark Potter)

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Tech News

First Robot: Melania Trump brings droid to White House event
Why AI means animal testing is not always needed to trial new medicines
Day of reckoning arrives for social media after US court loss
Teens get probation after using AI to create fake nudes of classmates
Revolut to base 40% of its global workforce in India by 2026
Apple rolls out age checks for UK users
Munich Re: AI making cyber attacks costlier and more effective
Nanya Technology shares surge 10% after $2.5 billion fundraising
Nvidia-backed Reflection AI eyes $25 billion valuation, WSJ reports
Hundreds of teens to trial social media bans in UK pilot project

Others Also Read