Clothing and food retailer Marks and Spencer has today issued a message to its 9million-plus online customers, confirming that they may have had some personal data stolen in the latest malicious hack attack and advising them to be “cautious” over future communications claiming to be from the company.
Marks and Spencer is advising customers that they will need to reset passwords once business returns to something like normal.
M&S is the latest target for a ransom attack, where hackers access confidential computer data and use it as leverage against the victim. In the past year, the NHS in London and Transport for London have taken months to untangle the damage caused by hacks into their systems, while the Co-op was also hacked recently, causing havoc with their supermarkets’ supply lines.
There are fears that the hackers could yet share or sell on the stolen data as part of their attempts to extort M&S, with a continuing risk of identity fraud.
The data stolen in the Marks and Spencer attack is reported to include telephone numbers, home addresses and dates of birth, as well as online order histories, but not bank or card details, or any account passwords.
M&S was hit by the cyber attack three weeks ago. Online orders remain suspended.
It is estimated that the ongoing problems are costing the retailer £43million a week in lost sales.
The retailer has not revealed how many of its customers have had their data stolen, but has emailed all website users, and says that it is working with cyber security experts to monitor any developments.
In the Marks and Spencer email, sent from customer service chief Jayne Wall, she says, “Unfortunately, the nature of the incident means that some personal customer data has been taken, but there is no evidence that it has been shared. The personal data could include contact details, date of birth and online order history. However, importantly, the data does not include useable card or payment details, and it also does not include any account passwords…
“You do not need to take any action, but you might receive emails, calls or texts claiming to be from M&S when they are not, so do be cautious. Remember that we will never contact you and ask you to provide us with personal account information, like usernames, and we will never ask you to give us your password.”
“To give you extra peace of mind, next time you visit or login to your M&S.com account on our website or app, you will also be prompted to reset your password.
“We sincerely apologise for any inconvenience caused to you and all of our customers.”
A D V E R T I S E M E N T
PAID ADS: To advertise your services or products to our 10,000 weekday visitors to the site, as featured on Google News Showcase, email us inside.croydon@btinternet.com for our unbeatable ad rates
- If you have a news story about life in or around Croydon, or want to publicise your residents’ association or business, or if you have a local event to promote, please email us with full details at inside.croydon@btinternet.com
As featured on Google News Showcase
- Our comments section on every report provides all readers with an immediate “right of reply” on all our content. Our comments policy can be read by clicking here
Inside Croydon is a member of the Independent Community News Network


