Domain: Digital - Digital / Technology Entity scope: Marks & Spencer Group plc (LSE: MKS), London. M&S-corporate’s OWN technology procurement is in scope; Ocado-JV platform technology is flagged as JV-partner (Ocado Group-owned). Vendor-domicile rule applies: only genuinely Israeli-domiciled vendors counted in scope. Compiled: 2026-06-21; human-reviewed and updated 2026-08-30 Method: Live web search only
Enterprise Technology Stack & Vendor Relationships
Core cloud and data infrastructure - Microsoft Azure (M&S-own). M&S operates a substantial Microsoft Azure estate. Published Microsoft customer-story documentation confirms deployment of Azure Data Lake Storage, Azure Databricks, Azure Synapse Analytics, and Power BI for analytics and data-science workloads.1 A separate Microsoft case study confirms Azure Machine Learning is used to scale and train hundreds of customer-loyalty (Sparks) models in parallel.2 In March 2026 M&S announced the rollout of 11,000 Microsoft 365 Copilot licences to store managers and Store Support Centre colleagues.3 No Israeli nexus: Microsoft Azure is US-domiciled.
Syte - Israeli-domiciled visual-AI vendor (M&S-own; current status unconfirmed). M&S deployed Syte’s visual-search product (“Style Finder”) on its mobile site in January 2019, allowing shoppers to photograph an item and surface visually similar M&S products.4 Syte was founded in Tel Aviv in 2015 and its principal R&D and corporate operations remain Israel-domiciled.5 M&S was the customer procuring a retail-facing SaaS product; no evidence identifies M&S supplying technology or data to Syte for any Israeli governmental or military purpose. The public evidence establishes the 2019 deployment but does not establish that the contract remains active.
Global-e - current international fulfilment and data-processing partner. M&S’s relationship with Global-e (Nasdaq: GLBE) for cross-border e-commerce localisation was extended in 2019.6 M&S’s current Israel-site privacy policy now independently confirms Global-e U.K. Limited as its international sales and fulfilment partner and states that Global-e collects and uses customer personal data to fulfil and deliver orders.7 Global-e’s current consumer privacy policy identifies the collected data as including names, email and delivery addresses, payment details and, where required for customs, identity or passport numbers. It says Global-e service data is stored and processed in Ireland, but may be transferred to Israel and shared within the Global-e group.8 Global-e is an Israeli-founded group headquartered in Petah Tikva.9 The current relationship therefore involves sensitive customer and transaction data stored in the EEA but legally and operationally transferable or accessible within an Israeli-controlled group; no Israeli state, defence, or surveillance customer relationship is alleged.
Namogoo - Israeli-domiciled client-journey protection vendor (M&S-own). M&S selected Namogoo (Herzliya, Israel) in January 2021 to protect M&S.com visitors from unauthorised third-party injected advertisements.10, 11 Namogoo was founded in 2014 and raised $40 million in Series C funding; the company was subsequently acquired by French firm AB Tasty in November 2025, at which point Namogoo’s Israeli operation became a subsidiary rather than an independent vendor.12 M&S’s continued post-acquisition status with AB Tasty/Namogoo is not confirmed in public sources.
Data routing, access, and retention finding. Syte’s current services privacy policy says uploaded personal images are retained on secured servers for up to 24 hours, IP addresses are encrypted and stored in de-identified form, interaction data is pseudonymised, and the storage servers are AWS-hosted in Frankfurt; Syte Visual Conception Ltd remains an Israeli company and limits access to personnel with a business need.13 This establishes EU hosting and short retention, not Israeli data residency, and the M&S deployment is not confirmed current. No public M&S-specific processing-location or current-contract evidence was identified for Namogoo. Global-e is different: M&S’s own current Israel privacy notice confirms the live processing relationship, while Global-e expressly permits transfer of customer identity, address and payment information to Israel within its group.7, 8 This is the only current, source-confirmed Israeli-controlled data-exposure route identified in the audit.
Optimove - no verified M&S relationship. Optimove (Tel Aviv-founded Israeli CRM/marketing platform) was investigated as a candidate given M&S’s published CRM investments. No public evidence of a Marks & Spencer–Optimove deployment was identified. M&S’s confirmed Customer Data Platform is mParticle (US-domiciled).14 Claim of Optimove deployment: No public evidence identified.
Other confirmed vendors (non-Israeli). mParticle (US, CDP);14 Google Cloud / Dialogflow contact-centre AI implemented via partner Sabio Group;15 SymphonyAI Retail CPG (US, store-intelligence computer vision in 500+ stores);16 First Insight (US, Pittsburgh, merchandise-intelligence AI since 2015, expanded December 2024);17 Thread IP (UK-founded fashion-personalisation, acquired November 2022);18 Hitachi Data Systems (Japan, storage migration);19 and TCS (India, IT helpdesk - contract terminated late 2025, see below).20 None carry an Israeli nexus.
Ocado Retail JV - M&S Food online (JV-partner technology, NOT M&S-own). M&S holds a 50% share in Ocado Retail Ltd, a joint venture with Ocado Group established in 2019 for £750 million. The JV operates the online M&S Food grocery business on the Ocado Smart Platform (OSP).21 The OSP and its technology are owned and operated by Ocado Group plc (UK-domiciled, LSE: OCDO), not by M&S. Any Israeli technology nexus attributable to Ocado’s platform belongs to Ocado Group’s audit, not M&S’s. Flagged here as JV-partner technology for disclosure completeness; M&S is not the technology owner or controller of OSP.
Surveillance, Biometrics & Retail Technology
M&S partnered with FOUR Security Consultants to obtain the UK Surveillance Camera Commissioner’s certification, becoming the first UK retailer to achieve it, indicating it operates CCTV systems subject to the Surveillance Camera Code of Practice; the vendor is UK-domiciled, with no Israeli nexus identified.22
M&S chairman Archie Norman publicly stated the company has opted against facial recognition in stores, preferring to limit shelf stock as a shrinkage deterrent.23 No public evidence identified of M&S deploying Israeli facial-recognition or biometric-surveillance technology in any retail environment.
M&S Bank (a separate financial-services entity operated in partnership with HSBC) offers optional fingerprint and facial-recognition login via its mobile app - consumer-facing biometric authentication for a banking product, not in-store surveillance; the biometric SDK vendor is not confirmed in public sources, and no Israeli nexus is identified in available evidence.24
SymphonyAI’s AI/computer-vision system on handheld devices in 500+ stores checks shelf compliance against planograms; this is retail operational computer vision, not customer tracking or facial recognition, and SymphonyAI is US-domiciled.16
Cloud Infrastructure, Data Residency & Sovereign Cloud Participation
M&S’s primary cloud infrastructure is Microsoft Azure, used for data lakes, analytics, machine learning, and e-commerce workloads.1, 2 No public evidence of M&S data being routed through or stored in Microsoft’s Israeli data-centre infrastructure. M&S procures cloud rather than providing it, and does not appear on any published list of participants in UK government sovereign-cloud initiatives in a technology-vendor capacity. An earlier infrastructure migration moved M&S on-premises storage to Hitachi VSP systems (Japan-domiciled vendor).19 The April 2025 cyberattack exposed approximately 10 million customer records (names, addresses, email addresses), per M&S’s customer notification; data-residency architecture at the time of the breach was not detailed in public disclosures.25
Defence, Intelligence & Security Sector Technology Relationships
No public evidence was identified of M&S Group plc holding contracts with any Israeli defence prime, intelligence agency, or Unit 8200–affiliated cybersecurity company. No public evidence identified.
2025 ransomware cyberattack - Scattered Spider / DragonForce (not Israeli). In April 2025 M&S suffered a major ransomware attack:
- Threat actor: Scattered Spider (also tracked as UNC3944), a loosely affiliated English-speaking cybercrime collective - not an Israeli group.26
- Ransomware strain: DragonForce, deployed on M&S VMware ESXi servers, encrypting virtual machines powering e-commerce, payment processing, and logistics.27
- Attack vector: Social engineering via M&S’s IT helpdesk (operated by TCS); attackers impersonated an M&S employee to obtain a password reset, then exfiltrated the Windows domain controller’s NTDS.dit file and cracked credentials offline.28
- Arrests: Four individuals (three UK citizens and one Latvian national, aged 17–20) were arrested on 10 July 2025; total estimated losses across M&S, Co-op, and Harrods reached approximately £440 million.29
- Financial impact on M&S: Approximately £300 million reduction in annual profit; multi-day suspension of online clothing sales; a substantial drop in market capitalisation.30
- ICO regulatory status: The ICO stated in May 2025 that it had received M&S’s incident report and was making enquiries. The cited legal commentary described potential exposure of up to £17.5 million or 4% of worldwide turnover; no £20 million ICO fine against M&S was identified.31, 32
- TCS contract termination: M&S terminated its long-running IT helpdesk contract with TCS in late 2025 following the breach.20
No Israeli cybersecurity firm has been identified in public sources as involved in either the attack or the remediation.
AI, Algorithmic & Autonomous Systems
M&S’s AI footprint is predominantly US-vendor and in-house: Microsoft 365 Copilot (11,000 licences, March 2026);3 Thread IP personalisation algorithms generating recommendations across 40+ million fashion combinations (UK-founded, in-house since the 2022 acquisition);18 Azure Machine Learning for the Sparks loyalty programme;2 SymphonyAI computer vision (US);16 and First Insight Voice-of-the-Customer AI (US).17 M&S is also investing £340 million in an automated National Distribution Centre in Northamptonshire using AI and advanced robotics; the robotics/AI technology partner is not confirmed in public sources, and no Israeli nexus is identified in available evidence.33 M&S has additionally announced an internal data-science and AI academy to build in-house capability.34 No public evidence identifies an Israeli-domiciled AI vendor in M&S’s AI stack.
Technology Ecosystem & R&D Footprint
M&S operates a retail-tech startup engagement programme; a 2019 corporate blog post confirmed Syte as one of several startups selected for digital-innovation pilots - the documented channel through which the Syte visual-search deployment originated.35 Following the Thread acquisition, M&S established a “personalised discovery team” within its data-and-digital function, employing former Thread engineers and data scientists.18 No public evidence was identified of M&S maintaining any R&D facility, innovation hub, or formal research partnership with an Israeli university, government body, or technology incubator. No public evidence identified.
Civil Society Scrutiny & Regulatory History
M&S has documented historical leadership links to Zionist advocacy: former chairman Israel Sieff was honorary president of the Zionist Federation of Great Britain and Ireland and vice-president of the World Jewish Congress.36 These are matters of corporate history and political affiliation, not digital-technology complicity; they are noted for completeness but belong in Political.
As of late-2025 ethical-retail assessments and the BDS National Committee’s guidance, M&S is not subject to an active BDS technology-specific boycott campaign; historical campaigns related to M&S’s Israeli franchise operations and food sourcing have not extended to a technology-platform boycott.37 Separately, UK pro-Israel advocacy body CUFI published a piece celebrating M&S’s partnerships with Israeli startups Syte and Namogoo as examples of UK–Israel commercial collaboration - a framing from a pro-Israel advocacy source that does not alter the factual vendor relationships described above.38
The ICO stated in May 2025 that it had received M&S’s report of the April cyber incident and was making enquiries; no completed £20 million ICO penalty was identified.32 M&S gave evidence to the UK Parliament Business and Trade Sub-Committee on Economic Security on 8 July 2025 regarding the attack; no Israeli technology nexus arose in the published evidence session.39
Footnotes
-
https://www.microsoft.com/en/customers/story/1620068383237408887-marksandspencer-azuresynapseanalytics-unitedkingdom ↩ ↩2
-
https://www.microsoft.com/en/customers/story/1638626120995556543-marks-and-spencer-retailer-azure-machine-learning ↩ ↩2 ↩3
-
https://corporate.marksandspencer.com/newsroom/press-releases/ms-gives-every-store-manager-and-every-store-support-centre-colleague ↩ ↩2
-
https://fashionunited.uk/news/retail/marks-and-spencer-introduces-visual-search-for-mobile/2019012141126 ↩
-
https://www.marksandspencer.com/he-il/customer-service/privacy-security/privacy-policy.html ↩ ↩2
-
https://www.israelhayom.com/2021/01/12/marks-spencer-partners-with-israeli-startup-namogoo/ ↩
-
https://www.prnewswire.com/news-releases/namogoo-selected-by-marks - spencer-to-help-optimise-the-customer-journey-on-mscom-301204760.html ↩
-
https://en.globes.co.il/en/article-israeli-cybersecurity-co-namogoo-raises-40m-1001305433 ↩
-
https://www.symphonyai.com/news/retail-cpg/marks-spencer-selects-symphonyai-retail-cpg-for-ai-based-store-intelligence-to-transform-customer-experience-and-store-operations-efficiency-2/ ↩ ↩2 ↩3
-
https://www.firstinsight.com/press-releases/first-insight-expands-partnership-with-ms-to-drive-digital-transformation-and-customer-centric-growth-across-all-ms-clothing-home-categories ↩ ↩2
-
https://corporate.marksandspencer.com/newsroom/press-releases/ms-acquires-thread-ip-accelerate-its-personalisation-plans ↩ ↩2 ↩3
-
https://www.itpro.com/cloud/362376/marks-spencer-completes-infrastructure-migration-with-hds ↩ ↩2
-
https://www.theregister.com/2025/10/28/marks_spencer_helpdesk_deal/ ↩ ↩2
-
https://corporate.marksandspencer.com/about-us/our-businesses/ocado-retail ↩
-
https://www.gov.uk/government/news/marks-and-spencer-first-retailer-to-gain-sccs-cctv-certification ↩
-
https://fortune.com/europe/2023/11/21/marks-spencer-self-checkout-shoplifting-middle-class-brits-uk-chairman/ ↩
-
https://bank.marksandspencer.com/digital-banking/banking-app/biometrics/ ↩
-
https://www.blackfog.com/marks-and-spencer-ransomware-attack/ ↩
-
https://www.ampcuscyber.com/shadowopsintel/how-scattered-spider-compromised-marks-spencers-network-key-findings-and-lessons-learned/ ↩
-
https://thehackernews.com/2025/07/four-arrested-in-440m-cyber-attack-on.html ↩
-
https://www.sangfor.com/blog/cybersecurity/marks-spencer-cyberattack-2025-supply-chain-breach ↩
-
https://www.blegalgroup.com/marks-spencer-data-breach-2025-legal-exposure-ico-action-what-it-means-for-uk-businesses/ ↩
-
https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/05/statement-on-cyber-incidents-impacting-retailers/ ↩ ↩2
-
https://aimagazine.com/news/m-s-340m-advanced-automated-food-distribution ↩
-
https://corporate.marksandspencer.com/newsroom/blog/launching-worlds-first-data-science-ai-academy-retail ↩
-
https://corporate.marksandspencer.com/newsroom/blog/new-wave-tech-start-ups-helping-put-digital-innovation-heart-ms ↩
-
https://www.jta.org/archive/lord-sieff-philanthropist-zionist-leading-businessman-dies-at-83 ↩
-
https://www.ethicalconsumer.org/company-profile/marks-spencer-group-plc ↩
-
https://www.cufi.org.uk/news/marks-spencer-partners-with-israeli-startup-bringing-together-another-uk-israel-collaboration/ ↩
-
https://www.iisf.ie/files/UserFiles/Cyber-technical-guides/Scattered-Spider-and-MandS-Incident_.pdf ↩