M&S and Co-op Cyber Security Case Study: What Local Businesses Can Learn

2025 was a big year for cyber security headlines in the UK, with two of our biggest stores suffering high profile cyber attacks: Marks and Spencer and The Co-op.
Around a year on, here’s a breakdown of what happened, how Co-op’s cyber security measures helped them come out on top and what local businesses can learn.
M&S and Co-op 2025 cyber attacks: the timeline
Malicious activity reportedly began occurring as early as February 2025 and it wasn’t until August that business returned to normal for M&S. That’s 6 months of business impact, without considering the long-term damage on reputation and customer relationships.
Here’s a top-line look at the timeline of the cyber attacks.
| M&S | Co-op | |
|---|---|---|
| Feb 2025 | Undetected social engineering attack believed to occur Attackers believed to gain access through social engineering. Goes undetected for 2 months. | — |
| 22nd–30th April 2025 | Payment systems fail; M&S servers encrypted; all online orders suspended Customers unable to use contactless payments or click & collect across M&S stores over Easter weekend. Ransomware deployed impacting e-commerce, payment processing and logistics. | Co-op breach caught within an hour Attacker impersonates a colleague & resets account on 25th April. SOC detects unusual behaviour almost immediately and response launched within the hour. Systems shut down & VPN access cut. |
| 13th May 2025 | Customer data theft confirmed M&S confirms personal data stolen (names, email addresses, postal addresses, dates of birth). | Data accessed and supply disruption Co-op confirms data was accessed but ransomware was not successfully deployed. Store supply disruption & Funeral business reverts to paper-based systems in May and June caused by decision to shut down back-office systems to limit attack damage. On 16th July, Co-op CEO confirms that names, addresses and contact details of all 6.5 million Co-op members were taken. |
| 10th June 2025 | Some online orders resume 46 days after suspension Click & collect remains down. | |
| August 2025 | Click & collect restored 15 weeks after attack Competitor Next upgrades profit forecast for fourth time, citing ‘competitor disruption’ (i.e. the M&S cyber attack) in its trading statement. | — |
The Numbers
What Co-op did differently, AND WHAT THIS MEANS FOR YOUR BUSINESS
Expert view: Shirine Khoury-Haq, The Co-op Group
“On April 25th, our Co-op was the victim of a multi-stage cyber attack… Our routine investment in security, the deliberate segregation of systems and frequent testing laid a strong foundation for our response to this cyber attack. It was, however, the extraordinary talent of our in-house teams and partners that made the difference.“
Even with strong preparation, Co-op still took a significant hit. But their investment in security meant the attack was contained in minutes rather than months, and the damage was a fraction of what it could have been.
The right measures won’t make your business invincible. But they’ll help make sure that when something happens, it doesn’t become a crisis you can’t recover from.
According to Hiscox’s 2025 Cyber Readiness Report, 94% of SMEs plan to increase their cyber security investment in the next 12 months. They’re updating employee training (70%), hiring specialist staff (60%), and investing in software to identify and manage threats (54%). Are you with them?
Too often, businesses only take cyber security seriously after they’ve suffered an attack which could’ve cost them considerable amounts of money and significant reputational damage. This is our plea to you to not be one of those businesses. Speak to us today to get your free cyber security review booked in.
Sources:
https://www.hiscox.co.uk/cyberreadiness – September 2025
https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025 – October 2025
https://www.retailgazette.co.uk/blog/2025/04/ms-suspends-online-orders/
https://www.retailgazette.co.uk/blog/2025/06/ms-shares-rise-online-orders
https://www.aol.com/news/britains-m-restores-click-collect-063231661.html
https://therecord.media/next-clothing-retailer-reports-profits-boosted-post-ms-cyberattack
https://www.cnbc.com/2025/05/21/ms-cyberattack-to-wipe-out-nearly-one-third-of-annual-profits.html
https://www.prolificnorth.co.uk/news/co-op-reveals-285m-revenue-hit-from-2025-cyber-attack
https://www.computerweekly.com/news/366634121/MS-profits-tumble-after-cyber-attack
https://www.computerweekly.com/news/366632018/Co-op-declares-cyber-attack-damage-cost-it-206m
https://www.aol.com/news/britains-m-says-cyberattack-cost-060737852.html
Latest Managed IT Support Advice
Check out our latest IT support blog posts.
What to Learn from M&S & Co-op Cyber Attacks
If you’ve recently noticed higher prices for RAM in your quotes, you’re not alone. Read our blog to find out what’s causing RAM cost increases and how it might impact your business.

Why RAM costs are rising & what it means for your business in 2026
If you’ve recently noticed higher prices for RAM in your quotes, you’re not alone. Read our blog to find out what’s causing RAM cost increases and how it might impact your business.

Why Maintaining Strong Microsoft 365 Security is Vital for Your Brighton Business
Discover why achieving and maintaining high Microsoft 365 security is critical for Brighton & Sussex businesses – and how we help.