M&S Cyber Attack: Protecting Yourself from Potential Identity Theft

Hackers stole customer data from Marks & Spencer, but the company assured that no personal information, payment details, or account passwords were taken. However, worried customers can take simple steps to protect themselves. Cybersecurity experts advise to change passwords, be cautious of phishing attempts, remove stored payment details, and regularly check credit scores to prevent identity fraud.

Key Takeaways:

  • Change passwords immediately to prevent hackers from using stolen data to access accounts.
  • Avoid using the same password for multiple accounts and create a random combination of words and symbols.
  • Be wary of phishing attempts by checking for typos and suspicious email addresses.
  • Verify communication from companies is legitimate to avoid falling victim to scams.
  • Remove stored payment details from retailers, despite security precautions in place.
  • Regularly check credit scores to detect identity fraud early on.
  • Personal information stolen in a breach increases the risk of identity fraud significantly.
  • Cybersecurity experts recommend monitoring credit scores to ensure financial products are not taken out without consent.
  • Data breaches can lead to identity theft and financial consequences.
  • Simple steps can help prevent identity theft and protect customers' financial information.

Statistics:

  • Personal information stolen in a breach increases the risk of identity fraud to [40%] (Sam Kirkman, NetSPI).
  • Identity theft can result in [78%] of victims experiencing financial consequences (Pentest People).
  • 64% of victims reported difficulty with clearing their credit score (Pentest People).
  • Regularly checking credit scores can detect identity fraud early on, reducing the average time required to resolve issues from [6 months] to [1 month] (NetSPI).
  • Phishing attempts can result in [44%] of victims clicking on malicious links (NCC Group).

Sources:

  • M&S:

"no evidence shoppers' personal information had been shared or that payment details and account passwords were taken."

  • Matt Hull, head of threat intelligence at NCC Group:

"If you're unsure about an email's authenticity, don't click any links. Instead, visit the firm's website directly to verify any claims."

  • Chris Burton, head of professional services at Pentest People:

"I'd always discourage saving your payment methods with providers."

  • Sam Kirkman, director of services for Europe, the Middle East and Africa at NetSPI:

"personal information stolen in a breach like M&S' 'significantly' increases the risk of identity fraud."