M&S Will Claim £100m From Its Cyber Insurers

Marks & Spencer (M&S) is getting ready to make one of the largest cyber insurance claims in the UK after explaining that personal customer information was compromised during a massive cyber attack at Easter 2025 which has taken down its digital infrastructure for weeks. 

M&S admitted for the first time on Tuesday 13th May 2025 that some  customers' personal data was stolen as part of the ransom attack, that has left the retailer unable to accept online orders. 

The retailer has told customers this could include contact details, date of birth and online order history but it does not include usable card or payment details or account passwords.

M&S is due report its full-year results soon and will give an update the market on the effects of the ransom attack. So far, the retailer’s share price has fallen around 16 per cent since it disclosed the attack on April 22, which has knocked £1.3bn off its market capitalisation.

Allianz is the principal insurer liable for M&S’s losses and is expected to pay at least the initial £10million while cyber insurance specialist Beazley is also amongst the insurers exposed to losses. 

The Co-op and Harrods have also been hit by recent cyber attacks and the Co-op has said that is is still in  recovery after taking action to bring its systems back online. These attacks are attributed to a collective of english speaking hackers known as Scattered Spider, who speialise in the use of social engineering techniques. One such  method used by Scattered Spider is an exploit named ‘MFA fatigue’ and explains why they are a uniquely dangerous group. 

In an MFA fatigue attack, an attacker floods a user with MFA authentication requests until they finally authorise either out of confusion or exasperation. At that point, the attacker can then bypass even the strongest defences.

In expert comment, Rex Booth, who is CISO at SailPoint said “Scattered Spider is a loosely affiliated group of cyber criminals based primarily in English speaking countries. They’re responsible for numerous high-profile attacks, including the MGM/Caesars compromise in 2023 which netted them a $15million ransom payment.
  
“They’re uniquely dangerous because much of the West is accustomed to this image of cyber criminals from Eastern Europe and Asia. Because most of Scattered Spider are native English speakers, they’re able to execute social engineering attacks without raising concerns as readily. It makes them very effective at exploiting the human side of cybersecurity." Booth concludes.   
 

Cyber attacks have cost UK businesses an estimated £44m in lost revenue over the past five years with over 50% of UK firms experiencing at least one attack during that period.

Insurance Business   |  FT   |  The Times   |  City AM  |  Prolific North  |   Business Live 

Imagge: Ideogram

You Might Also Read: 

The Growing Ransomware Crisis:


If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« Evolving The CISO Role

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Information Security Media Group (ISMG)

Information Security Media Group (ISMG)

Information Security Media Group is the world’s largest media organization devoted solely to information security and risk management.

Arxan Technologies

Arxan Technologies

Arxan is a leader of application attack-prevention and self-protection products for Internet of Things (IoT), Mobile, Desktop, and other applications.

Greenbone Networks

Greenbone Networks

Greenbone Networks delivers a vulnerability analysis solution for enterprise IT which includes reporting and security change management.

Information & eGovernment Authority (iGA) - Bahrain

Information & eGovernment Authority (iGA) - Bahrain

The Information & eGovernment Authority facilitates many services catering to different parts of the community within the IT sector in Bahrain including information security.

DarkOwl

DarkOwl

DarkOwl provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data.

Phy-Cy.X Security Group

Phy-Cy.X Security Group

Phy-Cy.X specialize in the “Physics” of Information Security through both physical and cyber domains. We are not an IT company, we ARE an Information Security company.

Neptune Cyber

Neptune Cyber

Neptune is a cyber security company that works exclusively in the marine sector. Our team combines experts in shipbuilding, maintenance and operations and cyber security testing and design.

GeoEdge

GeoEdge

GeoEdge is the premier provider of ad security and quality solutions for the online and mobile advertising ecosystem.

Ascent Solutions

Ascent Solutions

Ascent is built to help firms evolve their cybersecurity posture, modernize their Microsoft solutions, and accelerate their journey to the cloud.

Radiance Technologies

Radiance Technologies

Radiance solutions provide technological advantage and operational superiority for our nation in the areas of intelligence, cyber and advanced weapon systems.

North Green Security

North Green Security

North Green Security is a UK-based cyber security training and consultancy company.

Bleach Cyber

Bleach Cyber

Bleach Cyber helps small businesses with an affordable and user-friendly solution for managing cloud security.

Digital.ai

Digital.ai

Digital.ai empowers organizations to scale software development teams, continuously deliver software with greater quality and security.

Aspire Technology Solutions

Aspire Technology Solutions

Aspire is an award-winning IT Managed Service and Cyber Security Provider. We specialise in cyber security, cloud, connectivity, managed services, unified communications and IT support.

Custocy

Custocy

Custocy is a unique collaborative AI technology that identifies sophisticated and unknown (zero-day) attacks.

Corgea

Corgea

Corgea is AI-powered security platform that finds, triages and fixes your insecure code.