M&S drops TCS IT service desk contract following devastating cyberattack
Another casualty after the M&S cyberattack as IT service desk partner dropped
- Marks and Spencer has dropped its IT service desk provider
- This follows an investigation into the source of a huge cyberattack
- The tech firm says the two are 'clearly unrelated'
Marks and Spencer (M&S) has ended its partnership with Indian IT firm Tata Consultancy Services (TCS)following the devastating cyberattack which halted systems in store and online.
The contract has been ended after TCS was investigated over speculation that it may be the source of the breach- although the source is not yet confirmed.
"Regarding the IT service desk contract specifically, as is usual process, we went to market to test for the most suitable product available, ran a thorough process and instructed a new provider this summer. This process started in January, and this change has no bearing on our wider TCS relationship," a spokesperson told The Register.
Official IdentityForce® | Identity Theft Protection - save up to 68% annually
Many people don’t know how to protect their ID. Get your ID Action Plan here. Get a personalized step-by-step Action Plan & ID Safety Score based on YOUR dark web hits.
Sophisticated impersonation
The M&S attack caused chaos on the high street, which has now been confirmed as a ransomware attack that also affected retail giant Co-op - and had a total financial impact of between £270 million to £440 million.
The hackers are said to have used a ‘sophisticated impersonation’ to gain entry ‘involving a third-party’ - although it hasn’t been confirmed what the exact circumstances were surrounding the incident.
TCS is still in partnership with M&S for a number of other technologies and IT services, and says that the service desk contract termination and cyberattack were ‘clearly unrelated’ and that the process had begun long before the April Incident.
"As both M&S and TCS have clarified, the service desk contract with M&S followed a regular competitive RFP process initiated in January 2025, with M&S opting to proceed with other partners much prior to the cyber incident in April 2025. These matters are hence clearly unrelated. In fact, we continue to work on numerous other areas, in our role as a strategic partner for M&S and are proud of this longstanding partnership," a TCS spokesperson told TechRadarPro.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
"On the cyber incident itself, as previously clarified, TCS conducted a review of our own networks and systems and our conclusion is that the vulnerabilities have not originated from there. TCS does not provide cyber security services to M&S. This is a service that is provided by another partner."
Third party vendors and contractors are increasingly used to gain access to larger, more lucrative targets - which should be a wake up call for cybersecurity teams.
“Modern retail environments are complex, containing hundreds of connected devices integrated within sophisticated online retail supply chains,” says Neil Thacker, Global Privacy & Data Protection Officer at Netskope.
”System integrations are what make retailers agile, and able to find huge efficiencies in their business operations, but they also potentially leave companies exposed because a successful infiltration in one part of the business can quickly spread laterally to other business critical systems.”

➡️ Read our full guide to the best identity theft protection
1. Best overall:
Aura
2. Best for families:
IdentityForce
3. Best for credit beginners:
Experian IdentityWorks

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.
