Marks & Spencer Customers Warned of Scams Following Cyber Attack

Marks & Spencer customers have been urged to be on high alert for phishing attempts and scams after the retailer confirmed a cyber attack had resulted in some personal data being stolen. The stolen data includes names, email addresses, postal addresses, and dates of birth, but M&S stressed that payment or card details, or account passwords were not compromised. Cyber security experts are warning customers to be cautious of targeted social engineering attacks, where threat actors use the stolen information to craft convincing scams.

Key Takeaways:

  • Cyber security experts are urging Marks & Spencer customers to be wary of phishing attempts and targeted social engineering attacks.
  • The stolen data includes names, email addresses, postal addresses, and dates of birth, but M&S confirms that payment or card details, or account passwords were not compromised.
  • Cyber criminals are likely to sell the stolen data on the dark web, putting customers at even more risk.
  • Customers are advised to monitor their credit scores and remain alert to scams that may leverage this information.
  • Experts recommend being highly cautious of all email correspondence related to the attack and not sending personal information over email.
  • Customers are encouraged to change their passwords, enable multi-factor authentication (MFA), and avoid saving payment methods with retailers.
  • Personal details being harvested from a compromised source can lead to impersonation and an increase in spam calls.

Statistics:

  • The stolen data includes names, email addresses, postal addresses, and dates of birth.
  • Cyber criminals are likely to sell the stolen data on the dark web.
  • M&S has confirmed that payment or card details, or account passwords were not compromised.
  • Customers are advised to monitor their credit scores for potential identity fraud.
  • Cyber security experts recommend changing passwords and enabling multi-factor authentication (MFA) to protect online security.

Sources:

  • Marks & Spencer (Exact quote)
  • NCC Group (Exact quote)- Matt Hull
  • NetSPI (Exact quote) - Sam Kirkman
  • Closed Door Security (Exact quote) - William Wright
  • Pentest People (Exact quote) - Chris Burton