...
Skip to content

M&S TCS Cyber Attack: Explained

M&S TCS Cyber Attack: Explained
Photo credit: Canva

REPORTED BY:

Marks & Spencer has ended its long-running technology helpdesk partnership with Tata Consultancy Services (TCS) after a major cyberattack earlier this year. The attack hit M&S in April 2025, shutting down its online business and causing an estimated £300 million loss. Both companies claim the decision to end the contract was made before the hack and is unrelated.

The breach, carried out by hacker group Scattered Spider, exposed customer data and disrupted payments, deliveries, and stock management. While M&S faced massive losses, TCS denied any fault, saying its systems were never breached. The incident has sparked questions about outsourcing, cybersecurity, and vendor responsibility in global IT partnerships.

FAQ

When did the cyberattack happen?

The cyberattack took place in late April 2025. Marks & Spencer confirmed that its systems were hit by hackers, forcing the company to suspend online orders and parts of its click-and-collect operations. In-store payments and stock supplies were also affected, causing days of disruption across the UK.

Who was behind the attack?

A hacker group called Scattered Spider, also known as Octo Tempest, carried out the attack. The group used phishing and social engineering to gain access to M&S systems through a third-party contractor. They later deployed ransomware called DragonForce to lock company data and demand payment.

How did hackers gain access to M&S systems?

Hackers tricked helpdesk staff into revealing passwords and login credentials by pretending to be M&S employees. Once they gained access, they used ransomware to steal and encrypt company data. M&S’s CEO Stuart Machin said the breach occurred “via sophisticated impersonation involving a third-party vendor.”

Was TCS responsible for the breach?

TCS has denied any direct responsibility. The company said the attack happened “in the client’s own environment.” However, reports suggested that login credentials belonging to TCS staff were used in the infiltration. M&S has not blamed TCS publicly but confirmed the breach came through an external vendor.

What was the financial impact on Marks & Spencer?

The cyberattack caused heavy financial damage. M&S estimated losses of around £300 million in profit for the year and more than £1 billion in market value. Online orders, payments, and store operations were disrupted for weeks, affecting both customer trust and sales.

Did M&S fire TCS because of the cyberattack?

Both M&S and TCS say the contract decision was made earlier and not linked to the hack. M&S said the helpdesk renewal process began in January 2025, before the attack. The contract officially ended in July 2025. TCS continues to work with M&S on other IT projects.

How much was the TCS contract worth?

The total value of M&S’s technology contracts with TCS is estimated at around $1 billion. However, the helpdesk portion that ended this year represented only a small part of the overall deal, according to TCS’s statement to investors.

What are people saying about the decision?

A TCS spokesperson said, “The report linking the contract change to the cyberattack is misleading. TCS continues to support M&S in many strategic areas.”
M&S CEO Stuart Machin said, “We are working to strengthen our systems and rebuild customer confidence. Our focus is on recovery and security.”

How did the attack affect customers?

Customers faced issues placing orders online and using contactless payments in stores. Some also reported delays in deliveries. M&S warned shoppers to watch for phishing emails or scams after customer data was stolen during the breach.

Has TCS faced other cybersecurity issues recently?

Yes. In September 2025, another TCS client, Jaguar Land Rover, faced a major cyberattack that halted factory operations in the UK. TCS said its own systems were not affected and that client projects disrupted by the incident would resume soon.

What does this mean for Indian IT firms?

Experts say repeated attacks on major clients like M&S and JLR have raised pressure on Indian IT firms. Cybersecurity is now seen as a major risk factor in outsourcing deals. Analysts say companies must strengthen vendor oversight and train staff to avoid social-engineering traps.

What happens next for M&S?

M&S is rebuilding its digital infrastructure and reviewing all vendor partnerships. The company expects full recovery of operations and online services. It has also started investing more in cybersecurity to prevent future breaches.

How did M&S respond after the attack?

M&S hired cybersecurity firm CrowdStrike to investigate and strengthen its digital defences. The company also launched an internal audit of all third-party vendor systems.

Are customers still at risk?

While M&S says the breach is contained, cybersecurity experts warn that leaked data could still be used in phishing or identity theft attempts. Customers have been advised to change passwords and be cautious of suspicious emails.

Support us to keep independent environmental journalism alive in India.


Keep Reading

Highway Halt Puts Kashmir’s Fruit Economy at Risk

MP brings back Bhavantar as farmers lose soybean harvests

Author

Support Ground Report to keep independent environmental journalism alive in India

We do deep on-ground reports on environmental, and related issues from the margins of India, with a particular focus on Madhya Pradesh, to inspire relevant interventions and solutions. 

We believe climate change should be the basis of current discourse, and our stories attempt to reflect the same.

Connect With Us

Send your feedback at greport2018@gmail.com

Newsletter

Subscribe our weekly free newsletter on Substack to get tailored content directly to your inbox.

When you pay, you ensure that we are able to produce on-ground underreported environmental stories and keep them free-to-read for those who can’t pay. In exchange, you get exclusive benefits.

Your support amplifies voices too often overlooked, thank you for being part of the movement.

EXPLORE MORE

LATEST

mORE GROUND REPORTS

Environment stories from the margins