Shoppers across Scotland and the UK have faced days of disruption as Marks & Spencer (M&S) battles the fallout from a major cyber attack, with online orders suspended and payment issues continuing in stores.
Since the weekend of April 20th, M&S customers have reported widespread issues:
Online orders suspended: As of Friday, April 25th, M&S halted all online orders through its website and apps, affecting both food and clothing deliveries. Customers who placed orders on Friday are being refunded.
Click & Collect and delivery delays: Many shoppers have been unable to collect pre-ordered items, with some reporting that staff in Scottish stores could not access their orders despite “Ready to Collect.” notifications
Payment disruptions: Contactless payments and the use of gift cards-both physical and electronic-were suspended in-store and online, causing confusion and frustration at checkouts in Glasgow and Edinburgh.
Communication gaps: Customers have taken to social media to voice their frustration, with some complaining about inconsistent updates and being turned away multiple times when attempting to use gift cards.
A Scottish customer shared on social media:
“Appreciate this is difficult for you but orders placed on [10/04] dispatched a few days later still showing as on route to store! You should be offering customers the option to cancel and get a refund. I need to source items elsewhere meanwhile you have my money, not acceptable.”
M&S has confirmed it is dealing with a “cyber incident,” widely believed by cybersecurity experts and reported in the media to be a ransomware attack.
The company has not disclosed full details, but it has taken several systems offline as a precaution to prevent further spread and to protect customer and business data.
Rob Pritchard, a cybersecurity expert, told ITV News:
“The extent of the attack meant they were probably busy trying to get to a root cause, work out exactly what the attackers have access to and ensure they rescinded said access across each system.”
Industry analysts warn that such attacks can have a “ripple effect” on both digital and physical retail operations, with nearly a quarter of M&S’s sales coming from online channels. The timing, just as consumers begin summer shopping, could be particularly damaging to the brand’s reputation and finances.
M&S says contactless payments have now been restored in stores, and some reports indicate that gift card functionality is returning.
All M&S stores, including those in Scotland, continue to operate as normal for in-person shopping.
The National Cyber Security Centre and National Crime Agency are working with M&S to investigate and resolve the incident.
A spokesperson for M&S said:
“We are incredibly grateful for the understanding and support that our customers, colleagues, partners and suppliers have shown. We are working hard to restore our services and minimise disruption and are being supported by industry-leading experts.”