• 3,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

News » TCS under scrutiny as M&S cyberattack triggers $400Mn losses

TCS under scrutiny as M&S cyberattack triggers $400Mn losses

TCS under scrutiny as M&S cyberattack triggers $400Mn losses

LONDON, UNITED KINGDOM — Tata Consultancy Services (TCS), the Indian IT giant and principal technology partner to Marks & Spencer (M&S), is at the center of an internal probe after hackers exploited TCS employee credentials to breach M&S systems, resulting in unprecedented operational disruption and projected losses of up to $400 million.

TCS employee logins targeted in Scattered Spider cyberattack

The sophisticated attack, attributed to the notorious Scattered Spider group, began over the Easter weekend when hackers used the login credentials of at least two TCS employees to infiltrate M&S’s IT infrastructure.

TCS has been M&S’s principal technology partner for over a decade, managing critical IT helpdesk operations and digital transformation projects.

Both companies have declined to comment publicly while TCS conducts an internal investigation, expected to conclude by the end of May, according to Reuters.

M&S chief executive Stuart Machin earlier blamed “human error” rather than a flaw in the retailer’s internal systems or cyber defenses. “Staff at a third-party contractor were tricked,” Machin said.

Security analysts believe the attackers leveraged social engineering tactics—impersonating staff and manipulating IT helpdesks—to bypass multi-factor authentication and gain privileged access, echoing previous Scattered Spider campaigns against major casinos and retailers.

Prolonged disruption reveals global supply chain vulnerabilities

M&S’s online operations have been offline for over a month, with the retailer warning that disruptions may persist until July

The breach forced the shutdown of online ordering, disrupted food supply chains, and exposed sensitive customer data, including names, birth dates, and purchase histories—though payment details remained secure.

The incident has highlighted the systemic risks posed by third-party vendors in globally connected supply chains. TCS, which also serves other major retailers including Co-op and Harrods, is not investigating links to other breaches, but the pattern of attacks has prompted calls for industry-wide reassessment of vendor risk management.

M&S faces financial, reputational fallout as recovery drags

M&S estimates the cyberattack will slash its operating profit by £300 million (US$400 million), with its market value dropping by over £1 billion (US$1.3 billion) since the incident. 

The retailer’s leadership, including CEO Stuart Machin, has attributed the breach to human error at a third-party contractor rather than internal system flaws. 

M&S has reset customer passwords and is working with authorities, insurers, and cybersecurity experts to restore operations and limit further damage.

Experts urge stronger third-party cybersecurity controls

The attack has triggered urgent debate among cybersecurity professionals about the adequacy of current vendor security protocols. 

Experts warn that traditional authentication methods, such as SMS-based multi-factor authentication, are increasingly vulnerable to social engineering and phishing. 

Calls are growing for the adoption of biometric verification and more rigorous employee training to counter evolving threats.

“The major disruption and sales loss M&S has seen following the incident serve as a powerful reminder to all organizations: cybersecurity must be treated as a board-level issue. No business is immune to cyber threats, and those with complex digital ecosystems are particularly vulnerable,” said Robert Cottrill, technology director at digital firm ANS.

As TCS’s internal investigation continues, the M&S breach stands as a stark warning to global retailers about the cascading risks of third-party cyber vulnerabilities—and the urgent need for robust, proactive defense strategies among outsourcing companies.

Start your
journey today

  • Independent
  • Free
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO)

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between Philippines outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4000+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
3,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 3,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 3,000 firms
  • Simple
  • Transparent
Banner Image