Marks & Spencer has revealed that the ongoing disruption from a ransomware attack is expected to wipe £300 million off the company’s profits this year.
The company revealed it had been the victim of a ransomware attack on 22 April and its online orders remain “paused” to this day, as the company struggles to recover affected systems. Stores have also been hit by reduced availability, while the company last week admitted that customer data had been stolen in the attack.
Marks & Spencer is only one of a number of British retailers that have been attacked in recent weeks, with the Co-op and Harrods also targeted, although both seem to have recovered more robustly than Marks & Spencer. Yesterday, it was revealed that supermarket supplier Peter Green Chilled had also suffered a ransomware attack, raising further concern about the vulnerability of the UK’s critical food infrastructure.
Marks & Spencer impact
Giving an update on the attack alongside the publication of the company’s full-year results, Marks & Spencer chief executive Stuart Machin said the company expected disruption of its online sales to continue into July.
The company made a pre-tax profit of £876 million in the year to 29 March, before the attack, meaning the estimated costs of dealing with the ransomware will wipe out around a third of the company’s annual income next year, if profits remain consistent.
The incident has also wiped around £750 million off the company’s market capitalisation, meaning the overall cost could end up exceeding £1 billion.
The company is expected to recoup some of those losses through cybersecurity insurance, with the Financial Times estimating it could claim for around £100 million, which is only a fraction of the total damage to the company.
The reported figures highlight the importance of safeguarding critical systems against ransomware attacks. Earlier this month, the National Cyber Security Centre (NCSC) issued fresh guidance to British companies on how to guard against ransomware.
The attackers – believed to be hacking group Scattered Spider – are reported to have used AI-assisted social engineering attacks to convince IT help desks to reset the credentials of key employees, allowing the hackers to penetrate deep into the companies’ networks.
Companies have been advised to urgently review their password-reset procedures and to deploy two-factor authentication “comprehensively” across their organisations, among other measures.