Nature of the Attack
Marks & Spencer () suffered a cyberattack on April 22, 2025, involving ransomware that encrypted their servers, impacting online services and 1,400 stores.
The attack, attributed to ransomware affiliates using tactics, led to the theft of sensitive customer information but not payment or account password details.
Customer Impact and Response
Affected data includes names, dates of birth, home addresses, telephone numbers, and online order histories, but excludes usable payment details and account passwords.
M&S has advised customers to be cautious of phishing attempts and will prompt all customers with active accounts to reset their passwords for security.