Marks & Spencer Confirms Customer Data Theft in Cyber Attack

Marks & Spencer Confirms Customer Data Theft in Cyber Attack

1 minute read
Updated 19 days ago

Nature of the Attack

Marks & Spencer () suffered a cyberattack on April 22, 2025, involving ransomware that encrypted their servers, impacting online services and 1,400 stores.

The attack, attributed to ransomware affiliates using tactics, led to the theft of sensitive customer information but not payment or account password details.

Customer Impact and Response

Affected data includes names, dates of birth, home addresses, telephone numbers, and online order histories, but excludes usable payment details and account passwords.

M&S has advised customers to be cautious of phishing attempts and will prompt all customers with active accounts to reset their passwords for security.
This is a beta feature. We cannot guarantee the accuracy or quality of responses.