Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Twilio denies breach following leak of alleged Steam 2FA codes

    Assisted dying proposal passes first stage in Scotland | Assisted dying

    Iraq frees over 19,000 prisoners under new amnesty, including some ex-ISIL | ISIL/ISIS News

    Facebook X (Twitter) Instagram
    Trending
    • Twilio denies breach following leak of alleged Steam 2FA codes
    • Assisted dying proposal passes first stage in Scotland | Assisted dying
    • Iraq frees over 19,000 prisoners under new amnesty, including some ex-ISIL | ISIL/ISIS News
    • Will the US-China tariff deal avert a possible global trade war? | News
    • Menendez brothers’ resentencing hearing begins after months of delays | Los Angeles
    • Trump offers Iran ‘brighter future’ without the need for nukes during speech to Saudi oligarchs
    • Global Health Overview — Global Issues
    • Commvault Command Center patch incomplete: researcher • The Register
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»M&S says customer data stolen in cyberattack, forces password resets
    Cyber

    M&S says customer data stolen in cyberattack, forces password resets

    mediamillion1000@gmail.comBy [email protected]May 13, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    M&S says customer data stolen in cyberattack, forces password resets
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    M&S says customer data stolen in cyberattack, forces password resets

    Marks and Spencer (M&S) confirms that customer data was stolen in a cyberattack last month, when ransomware was used to encrypt servers.

    The attack occurred on April 22, 2025, significantly impacting business operations on the retailer’s 1,400 stores, forcing it to stop accepting online orders.

    BleepingComputer first revealed that the attacks were conducted by DragonForce ransomware affiliates utilizing Scattered Spider social engineering tactics to breach Marks and Spencer’s network. During the attack, the threat actors encrypted VMware ESXi virtual machines hosted on the company’s servers.

    Since then, M&S has been investigating the attack and confirmed that the intruders stole sensitive personal information belonging to customers.

    This was announced by M&S CEO, Stuart Machin, who posted a letter on the retailer’s official Facebook page.

    “As we continue to manage the current cyber incident, we have written to customers today to let them know that unfortunately, some personal customer information has been taken,” states Machin.

    “Importantly, there is no evidence that the information has been shared and it does not include usable card or payment details, or account passwords, so there is no need for customers to take any action.”

    Despite these assurances, all customers with active M&S accounts will be prompted to reset their password the next time they attempt to log in via the website or app.

    An FAQ page published on the M&S website says the following data types have been exposed:

    • Full name
    • Email address
    • Home address
    • Phone number
    • Date of birth
    • Online order history
    • Household information
    • Sparks Pay reference numbers
    • “Masked” payment card details

    The term “masked” is unclear, but it could mean that only partial numbers are exposed. BleepingComputer contacted M&S to confirm.

    “You do not need to take any action, but you might receive emails, calls or texts claiming to be from M&S when they are not, so do be cautious,” warns M&S.

    “We will never contact you and ask you to provide us with personal account information, like usernames, and we will never ask you to give us your password.”

    Sparks offers will be paused for now, but no specific updates on the status of online order processing or other business disruptions were shared this time.

    M&S said it would notify all impacted customers accordingly and promised to share more details when those become available.

    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

    customer cyberattack Data forces Password resets Stolen
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhy Global “Moratorium” on SRM Deployment Should Get a Chilly Reception
    Next Article India’s ‘new normal’ of perpetual war will damage its democracy | India-Pakistan Tensions
    [email protected]
    • Website

    Related Posts

    Twilio denies breach following leak of alleged Steam 2FA codes

    May 13, 2025

    Commvault Command Center patch incomplete: researcher • The Register

    May 13, 2025

    Google Is Using On-Device AI to Spot Scam Texts and Investment Fraud

    May 13, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Twilio denies breach following leak of alleged Steam 2FA codes

    Assisted dying proposal passes first stage in Scotland | Assisted dying

    Iraq frees over 19,000 prisoners under new amnesty, including some ex-ISIL | ISIL/ISIS News

    Will the US-China tariff deal avert a possible global trade war? | News

    Trending Posts

    Twilio denies breach following leak of alleged Steam 2FA codes

    May 13, 2025

    Assisted dying proposal passes first stage in Scotland | Assisted dying

    May 13, 2025

    Iraq frees over 19,000 prisoners under new amnesty, including some ex-ISIL | ISIL/ISIS News

    May 13, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Twilio denies breach following leak of alleged Steam 2FA codes
    • Assisted dying proposal passes first stage in Scotland | Assisted dying

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.