M&S stops online orders and issues refunds after cyber attack

2 weeks ago 41

Tom Gerken & Graham Fraser

Technology reporters

Alamy The M&S website, showing its elemental  logo. It highlights the antithetic  categories of apparel  that are sold, specified  arsenic  men's, women's and kids clothes.Alamy

Marks & Spencer (M&S) says it has stopped taking online orders arsenic the institution struggles to retrieve from a cyber attack.

Customers began reporting problems past weekend, and connected Tuesday the retailer confirmed it was facing a "cyber incident".

Now, M&S has wholly paused orders connected its website and apps - including for nutrient deliveries and apparel - and says it volition refund orders placed by customers connected Friday.

The firm's shares fell by 5% pursuing the announcement, earlier recovering.

Online orders remained paused connected Saturday morning.

"We are genuinely atrocious for this inconvenience," the retailer wrote in a station connected X.

"Our experienced squad - supported by starring cyber experts - is moving highly hard to restart online and app shopping.

"We are incredibly grateful to our customers, colleagues and partners for their knowing and support."

It said its stores stay unfastened contempt the issues affecting online ordering.

Ongoing issues

Previously, the steadfast was dealing with problems which affected radical utilizing contactless payments, Click & Collect, arsenic good arsenic those paying with acquisition cards.

Since it suspended online ordering, M&S has responded to societal media posts advising customers that these problems persist.

"Gift cards, e-gift cards and recognition receipts can't presently beryllium utilized arsenic a outgo method successful store oregon online," it said successful effect to 1 idiosyncratic connected X.

But it told different that if radical person already received an email telling them an point is acceptable to beryllium collected, they should beryllium capable to spell into the store and prime it up.

"We're holding each parcels successful store until further notice, truthful there's nary hazard of it being sent back," it said.

But immoderate radical person criticised the steadfast for its handling of the outage, peculiarly astir its messaging to customers.

"After being told yesterday successful the evening the occupation with acquisition cards was sorted, went successful store contiguous and was sent distant again," one idiosyncratic told the steadfast successful a station connected X.

They said it was the 4th time successful a enactment they had tried and failed to usage their M&S acquisition card.

Meanwhile, contempt the frustrations, immoderate radical online person praised in-store unit implicit their work amid the problems, and called for customers not to instrumentality their frustrations retired connected workers.

But galore inactive look to person questions implicit however existing purchases, orders and returns volition beryllium impacted by the continued fallout from the cyber attack.

Online grocer Ocado, which sells M&S nutrient connected its platform, is unaffected by the problems arsenic it runs connected an wholly abstracted system.

M&S A screenshot from the M&S website's women's covering  conception  displays a clickable banner informing customers "we person  paused online orders" and that "products stay  disposable  to browse online and stores are open".M&S

The M&S website is present informing customers it has stopped taking online orders.

Online disruption

A spokesperson from the Information Commissioner's Office told the BBC that M&S was "assessing the accusation provided" aft the retailer told it astir the incident.

The steadfast antecedently said connected Tuesday it had reported the incidental to the National Cyber Security Centre (NCSC), and the National Crime Agency told the BBC it was moving with the NCSC to enactment the firm.

In an update to investors connected Friday, M&S said its determination to intermission online orders successful the UK formed portion of its "proactive management" of the incident.

"The M&S squad - supported by starring experts - is moving highly hard to reconstruct online operations and proceed to service customers well," it said.

Amid the continuing fallout of this week's cyber attack, however, experts are speculating astir what whitethorn beryllium down it.

Nathaniel Jones, vice-president of information and AI strategy astatine cyber information steadfast Darktrace, said M&S halting online income shows "the cascading interaction these attacks tin person connected gross streams".

"It demonstrates however rapidly cyber incidents tin cripple retail operations crossed some integer and carnal channels," helium added.

William Wright, from cybersecurity steadfast Closed Door Security, said helium believed it could person a "material impact" connected the firm.

"Data shows astir a 4th of the store's income hap online, truthful nary substance however agelong this intermission is enactment successful place, it volition wounded M&S financially," helium said.

The retailer is the latest large marque to acquisition important disruption to its online services successful caller months.

Morrisons faced immense problems with its Christmas orders past year, with deliveries cancelled and discounts not applied.

This was followed by 2 large banking outages connected what was wage time for galore successful the archetypal 2 months of this year.

In January, superior IT problems astatine Barclays affected the bank's app and online banking. It was aboriginal disclosed Barclays could look compensation payments of £12.5m.

In February, respective banks - notably Lloyds - faced outages, leaving businesses incapable to wage staff.

Additional reporting by Liv McMahon

Read Entire Article