M&S Customers Warned to Stay Vigilant for Phishing Scams After Cyber Attack

Cyber security experts are urging Marks & Spencer customers to be cautious of potential phishing scams and identity fraud following a data breach, which has seen some personal data stolen. Despite assurances from M&S that no payment information or account passwords were compromised, experts warn that threat actors could use the stolen data to launch targeted social engineering attacks. Customers should be wary of emails pretending to be from M&S or other companies, and should not click on any links if unsure.

Key Takeaways:

  • The stolen data includes names, email addresses, postal addresses, and dates of birth, but not payment information, card details, or account passwords.
  • Experts warn that threat actors could use the stolen information to launch targeted social engineering attacks, including phishing scams.
  • M&S customers should be cautious of emails pretending to be from M&S or other companies, and should not click on any links if unsure.
  • Identity fraud is a significant risk in breaches like this, and customers should monitor their credit scores to ensure financial products are not taken out in their name without consent.
  • Customers should be highly cautious of all email correspondence in relation to the attack, and should not send personal information over email.
  • Experts urge people to change their password at the earliest opportunity, ensure it's complex, and do not password share with any other logins.
  • Multi-factor authentication (MFA) should be enabled, and SMS-based tokens should be avoided in favor of authenticator apps.

Statistics:

  • 1 in 5 UK adults have been a victim of phishing scams (Source: UK Government).
  • 77% of organizations report experiencing phishing attacks (Source: Wombat Security).
  • The average cost of a data breach is £2.8 million (Source: IBM).
  • 64% of hacking-related breaches involve weak or stolen passwords (Source: Verizon Data).

Sources:

  • Martyn Landi article, date not provided.
  • NCC Group website, date not provided.
  • NetSPI website, date not provided.
  • Closed Door Security website, date not provided.
  • Pentest People website, date not provided.
  • UK Government website, date not provided.
  • Wombat Security website, date not provided.
  • IBM website, date not provided.
  • Verizon Data website, date not provided.