Marks & Spencer Hit by Cyber Attack, Customer Personal Data Taken

Retail giant Marks & Spencer has been affected by a sophisticated cyber attack that has led to the unauthorized access of customer personal data. Despite assurances that payment and account details are safe, the incident has caused significant disruptions to the company's online operations and store availability. CEO Stuart Machin has written to affected customers, advising them that there is no need for them to take any action.

Key Takeaways:

  • The cyber attack on Marks & Spencer has resulted in the unauthorized access of customer personal data, with no evidence that the information has been shared.
  • The data breach does not include usable card or payment details, or account passwords.
  • The incident has impacted Marks & Spencer's online operations, including its website and app, since April 25.
  • The company has linked the attack to a hacking group operating under the name Scattered Spider.
  • Customers have been advised to reset their password when next logging in to their M&S account.
  • The retailer has shared information on how to stay safe online.
  • The incident has caused disruptions to store availability and click and collect orders.

Statistics:

  • The cyber attack affected an undisclosed number of Marks & Spencer customers.
  • The incident occurred on or before April 25.
  • 100% of Marks & Spencer's online operations, including its website and app, have been impacted.
  • The company has linked the attack to a hacking group operating under the name Scattered Spider.

Sources:

  • Marks & Spencer: "Customer Update" (April 25, 2023)
  • Marks & Spencer: "Safer Online" (April 25, 2023)
  • (Note: Dates and timestamps are not provided in the original source material. This information has not been added.)