M&S Reports 23.8% Profit Drop After Cyber Incident: A Warning for GCC Boards

Marks and Spencer's adjusted profit fell 23.8% to £671m after a cyber incident disrupted the first half of its financial year, a textbook case for why GCC boards must treat cyber risk as a financial risk.

Layla Haddad
Cyber Policy & Digital Risk Correspondent9 min read
Corporate board meeting with executives reviewing financial impact reports following a cyber security incident

Corporate board meeting with executives reviewing financial impact reports following a cyber security incident

Marks and Spencer has reported one of the most consequential cyber-related earnings impacts in recent retail history, with adjusted profit before tax falling 23.8% to £671.4 million for the year ended 28 March 2026. The cause was a cyber incident during the Easter weekend of 2025 that disrupted operations across the entire business for the better part of a financial half-year. Of the £292.1 million in adjusting items recorded for the full year, £131.3 million was directly attributable to the incident.

The total estimated cost to operating profits stands at £300 million, partially offset by a £100 million insurance payout. The net financial damage after insurance recovery is therefore approximately £200 million from a single cyber event against a single enterprise.

The figures make for uncomfortable reading in any boardroom. For boards and CISOs across the GCC, where enterprise digitisation has accelerated rapidly and cyber investment decisions are frequently still treated as IT budget conversations rather than risk capital decisions, the M&S results provide a concrete, audited case study in what a single cyber incident can do to a listed company's financial performance over a sustained period.

What the attackers did and what it cost

The incident, which M&S confirmed was executed by hackers around the Easter 2025 weekend, forced the retailer to suspend all online clothing orders for approximately six weeks. The disruption extended into logistics systems, creating empty shelves and stock availability failures that persisted through the first half of the financial year. Personal customer data was stolen in the attack, including names, addresses, telephone numbers, email addresses, dates of birth and online order histories. M&S confirmed that no financial data was accessed.

The operational consequences of the online suspension went well beyond the direct revenue loss from seven weeks of halted e-commerce. Stock flow was disrupted across distribution, creating a downstream cascade of availability failures and logistics misalignment that took the remainder of the first half to partially resolve. Surplus seasonal stock that could not be cleared through normal online channels accumulated through the period, requiring deep markdowns concentrated in the second half that further compressed margins even as underlying trading conditions improved.

The disruption fell hardest on M&S's Fashion, Home and Beauty division. Sales in that segment fell 7.7% and adjusted operating profit collapsed from £478 million to £213.4 million, a loss of over £264 million in operating contribution from one division in a single year, attributable primarily to the enforced online trading pause and its downstream effects on stock management and availability.

International operations were also affected. Shipments to the Middle East were delayed in the final month of the financial year, contributing to a 7.2% decline in international sales, even as the division managed to improve its adjusted operating profit to £39.1 million from £35.9 million through cost reductions and restructured franchise arrangements. For GCC distributors and franchise partners operating M&S product lines in the region, the supply chain disruption created by a cyber incident in London translated directly into stock gaps and revenue shortfalls thousands of miles from the point of compromise.

The food division was more resilient. Food sales rose 7% for the year and the division grew market share, confirming that the incident's operational impact was concentrated in the supply chain and logistics systems most dependent on digital connectivity rather than in the physical store estate. Even so, elevated markdowns and waste in the first half of food operations, driven by the logistics disruption, reduced adjusted operating profit to £444.5 million from £491.8 million at a margin of 4.6%.

The financial governance lesson

M&S CEO Stuart Machin described the period as an extraordinary year and noted that the company emerged stronger, pointing to customer loyalty through the disruption and to the structural improvements made during recovery. That framing reflects genuine operational resilience. But the audited numbers tell a precise story about the financial scale of operational disruption from a single cyber event: £131.3 million in direct incident costs, £300 million in estimated lost operating profit before insurance recovery, a 28.8% fall in statutory profit before tax to £364.6 million, and a full year of management attention diverted from growth to recovery operations.

Machin also signalled what the external environment looks like from a retail CEO's perspective in 2026, describing a triple whammy of headwinds including increased taxation, a greater regulatory burden, higher fuel and freight costs, and ongoing global conflict affecting supply chains. Cyber resilience is now operating alongside these structural pressures rather than separately from them, meaning that an enterprise absorbing a cyber incident in the current environment has less financial buffer to absorb the secondary effects than it would have had in a more benign cost environment.

For GCC enterprises, particularly those in retail, financial services and logistics where operational continuity is directly linked to revenue, the M&S results provide the kind of financial evidence that boards and audit committees respond to. Cyber risk quantification is increasingly being discussed at a regional level, including by the UAE Cyber Security Council and the Saudi National Cybersecurity Authority, as regulators push enterprises toward demonstrable financial resilience rather than checkbox compliance.

The M&S incident also illustrates a pattern that security teams across the region are increasingly flagging: that the most damaging operational impacts of a cyber event are not the immediate recovery costs, but the secondary effects on revenue, customer fulfilment and supply chain continuity that take quarters to resolve. The direct incident costs of £131.3 million represent less than half of the estimated £300 million total operating profit impact. The majority of the damage was delivered not by the attack itself but by its downstream operational consequences playing out across months of disrupted logistics, stock management and customer fulfilment.

What the recovery arc looks like in practice

The M&S financial year was divided sharply in performance terms. The first half absorbed the bulk of the disruption. The second half saw adjusted profit recover to grow 4.1% year-on-year, demonstrating that a structured operational response can produce meaningful recovery within a single financial year if executed consistently.

M&S achieved £89 million in structural cost savings during the year, which were reinvested into operational resilience rather than returned as margin. The company expects a return to profit growth in 2026/2027 relative to 2024/2025, and Berenberg analysts responded to the results by raising their price target on M&S shares from 415p to 480p, suggesting that the market views the recovery trajectory as credible.

That trajectory, disruption in the first half, structural response through the year, and gradual normalisation into the following financial year, is the realistic recovery arc for any enterprise that experiences a significant cyber incident with a tested incident response capability. Without that capability, the recovery period extends and the secondary financial damage compounds. M&S entered the incident as a major listed retailer with established crisis management infrastructure, board-level governance and access to insurance coverage. Smaller enterprises and regional operators without those structural advantages face proportionally more severe recovery challenges from equivalent disruption.

For organisations operating managed detection and response programmes across the GCC, the M&S case reinforces the operational argument for continuous threat monitoring over reactive incident response. The seven-week online suspension that drove the bulk of M&S's financial damage resulted from the time required to contain the incident, restore systems and verify the integrity of the e-commerce platform before resuming trading. Earlier detection of the intrusion, before operational systems were compromised at scale, would have materially altered the financial outcome.

The ransomware and data theft dimension

The M&S incident involved both operational disruption and confirmed customer data theft, a combination that increasingly characterises the most financially damaging attacks against retailers and consumer-facing enterprises. The stolen data, comprising names, addresses, contact details, dates of birth and order histories, represents a usable dataset for follow-on phishing campaigns, identity fraud and credential stuffing attacks against M&S customers, creating a long-tail liability that extends beyond the financial year in which the incident occurred.

The combination of operational disruption and data exfiltration is consistent with the tactics used by ransomware-affiliated groups that conduct double extortion operations, encrypting or disrupting systems while simultaneously extracting data to use as additional leverage. The pattern of supply chain and gateway compromise that has characterised major retail incidents in 2025 and 2026 reflects the same underlying dynamic: attackers are targeting the operational dependencies of large enterprises rather than their perimeter defences, because it is the operational disruption, not the data theft alone, that generates the maximum financial and reputational leverage.

What GCC boards should take from the M&S results

For organisations operating across Dubai and the wider GCC, where cross-border e-commerce, omnichannel retail and cloud-dependent operations are standard, the M&S case makes a specific set of arguments that are relevant to board-level cyber risk conversations in 2026.

The financial impact of a cyber incident is not limited to recovery costs and it is not symmetrically distributed across the business. The M&S incident cost more than twice its direct remediation costs in indirect operational damage, concentrated in the divisions and functions most dependent on digital continuity. Boards that understand cyber risk only through the lens of direct costs are systematically underestimating their actual financial exposure.

Insurance coverage is necessary but insufficient. M&S received £100 million in insurance payments against a £300 million estimated operating profit impact, covering roughly one third of the total financial damage. The remaining two thirds was absorbed by the business through reduced profitability, structural cost savings and management resource diversion. Cyber insurance should be understood as a partial financial buffer, not a risk transfer mechanism.

The passkey and authentication hardening investments that GCC regulators and security advisors have been recommending to enterprise teams in 2026 are directly relevant to the class of attack that compromised M&S. Credential-based initial access and the exploitation of authentication weaknesses in enterprise and e-commerce platforms represent the entry point for a significant proportion of the most financially damaging incidents recorded in the past 18 months.

Supply chain and logistics dependencies deserve explicit treatment in cyber risk assessments. The M&S incident demonstrated that operational disruption originating in digital systems propagates rapidly into physical supply chains, creating stock, availability and fulfilment failures that are visible to customers and that generate sustained revenue impact well beyond the period of active system disruption. For GCC enterprises with regional distribution operations, this is a specific risk category that warrants its own scenario planning and resilience testing.

The M&S annual results are audited, publicly filed and financially precise. They represent the clearest available evidence of what cyber risk costs when it materialises at scale in a large enterprise. For GCC CISOs preparing board-level risk presentations in 2026, the numbers from M&S's financial year deserve a place in that conversation.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.

Intelligence Focus Areas

Cyber Risk Governance GCCBoard-Level CybersecurityEnterprise Resilience MENAFinancial Impact of Cyber IncidentsCISO Intelligence 2026