TCS probes role in cyberattack on UK retailer M&S after £300 mn profit hit

TCS is investigating if it was the entry point in a cyberattack on UK retailer M&S, which led to major disruptions and data theft, potentially costing the company £300 million (₹3,318 cr) in profit

TCS, Tata Consultancy Services
Marks & Spencer began working with TCS in the early 2010s. | File Photo
Prateek Shukla New Delhi
3 min read Last Updated : May 23 2025 | 6:01 PM IST
IT services giant Tata Consultancy Services (TCS) is conducting an internal investigation to determine whether it was used as an entry point in a cyberattack on Marks & Spencer (M&S). The breach, which occurred over the busy Easter weekend, led to the theft of customer data and caused major disruptions to the British retailer’s operations. TCS, a long-standing technology partner of M&S, hopes to conclude its probe by the end of the month, according to a report by The Financial Times.
 
The cyberattack has had severe consequences for M&S. The company was forced to shut down its online clothing business for over three weeks. The disruption wiped more than £750 million (about ₹8,295 crore) off its market value and is expected to result in a loss of up to £300 million (about ₹3,318 crore) in operating profit. Online services are likely to remain affected until July. A UK police investigation into the matter is also underway.
 
M&S chief executive Stuart Machin recently broke his silence on the incident, blaming “human error” rather than a flaw in the retailer’s internal systems or cyber defences. “Staff at a third-party contractor were tricked,” Machin said, without confirming whether a ransom was paid or if TCS was indeed the entry point used by the hackers.

M&S and TCS: A deep partnership

Marks & Spencer began working with TCS in the early 2010s. In 2018, the retailer outsourced half of its tech jobs to the Indian firm, naming it its “principal technology partner.” The partnership was expanded again in 2023 to transform M&S’s entire tech stack.
 
A source at M&S told Reuters that TCS was a “means of access” during the cyberattack, with at least two TCS employees’ M\&S login credentials being used as part of the breach.

Not an isolated case

M&S is not the only UK retailer targeted in the recent wave of cyberattacks. The Co-op and luxury department store Harrods have also been victims. The Co-op, which has worked with TCS since 2009, reportedly managed to shut down the cyberattack before it caused significant damage.
 
Despite the link, TCS is not investigating any possible connection to the Co-op breach, as the services it provides to the supermarket chain are not related to its technology infrastructure, according to a person familiar with the matter.

Spotlight on third-party IT risks

The breach at M&S has once again brought attention to the risks associated with third-party IT outsourcing. The sector has seen declining demand from its key markets, including the United States.
 
Earlier this year, Infosys, India’s second-largest IT firm, agreed to pay $17.5 million to settle lawsuits in the US following a cyberattack on one of its subsidiaries in 2023.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :Tata Consultancy ServicesCyberattacksData breachIT services

First Published: May 23 2025 | 5:03 PM IST

Next Story