M&S cyber attack: Personal customer data stolen by hackers

Marks & Spencer said data had been accessed by the cyber criminals but said there was “no need for customers to take any action". <i>(Image: Jonathan Brady/PA Wire)</i>
Marks & Spencer said data had been accessed by the cyber criminals but said there was “no need for customers to take any action". (Image: Jonathan Brady/PA Wire)
This article is brought to you by our exclusive subscriber partnership with our sister title USA Today, and has been written by our American colleagues. It does not necessarily reflect the view of The Herald.

Marks & Spencer has revealed that customer personal data was stolen by hackers during a cyber-attack which began last month.

The retail giant said data had been accessed by the cyber criminals but said there was “no need for customers to take any action".

Chief executive Stuart Machin said the data had been accessed due to the “sophisticated nature of the incident” but stressed that this does not include payment or card details, or account passwords.

“To give customers extra peace of mind, they will be prompted to reset their password the next time they visit or log on to their M&S account and we have shared information on how to stay safe online,” he said.

In a full statement posted on the Marks and Spencer Facebook page, Mr Machin said: “As we continue to manage the current cyber incident, we have written to customers today to let them know that unfortunately some personal customer information has been taken.


Recommended reading:


“Importantly, there is no evidence that the information has been shared and it does not include useable card or payment details, or account passwords, so there is no need for customers to take any action.

“To give customers extra peace of mind, they will be prompted to reset their password the next time they visit or log on to their M&S account and we have shared information on how to stay safe online.

“Everyone at M&S is working around the clock to get things back to normal for our customers as quickly as possible, and we are very sorry for any inconvenience they have experienced. Our stores remain open as they have throughout.

“Thank you for shopping with us and for your continued support, we are incredibly grateful.”

The group has not been able to take any orders through its website or app since April 25 as it tries to resolve the problem.

The incident first caused problems for the retailer’s contactless payments and click and collect orders, while it has also impacted some availability in stores.

A hacking group operating under the name Scattered Spider has been linked to the attack, according to reports.

Get involved
with the news

Send your news & photos