M&S warns customers to be ‘cautious’ after latest hack attack

Clothing and food retailer Marks and Spencer has today issued a message to its 9million-plus online customers, confirming that they may have had some personal data stolen in the latest malicious hack attack and advising them to be “cautious” over future communications claiming to be from the company.

Marks and Spencer is advising customers that they will need to reset passwords once business returns to something like normal.

M&S is the latest target for a ransom attack, where hackers access confidential computer data and use it as leverage against the victim. In the past year, the NHS in London and Transport for London have taken months to untangle the damage caused by hacks into their systems, while the Co-op was also hacked recently, causing havoc with their supermarkets’ supply lines.

There are fears that the hackers could yet share or sell on the stolen data as part of their attempts to extort M&S, with a continuing risk of identity fraud.

The data stolen in the Marks and Spencer attack is reported to include telephone numbers, home addresses and dates of birth, as well as online order histories, but not bank or card details, or any account passwords.

M&S was hit by the cyber attack three weeks ago. Online orders remain suspended.

It is estimated that the ongoing problems are costing the retailer £43million a week in lost sales.

The retailer has not revealed how many of its customers have had their data stolen, but has emailed all website users, and says that it is working with cyber security experts to monitor any developments.

In the Marks and Spencer email, sent from customer service chief Jayne Wall, she says, “Unfortunately, the nature of the incident means that some personal customer data has been taken, but there is no evidence that it has been shared. The personal data could include contact details, date of birth and online order history. However, importantly, the data does not include useable card or payment details, and it also does not include any account passwords…

“You do not need to take any action, but you might receive emails, calls or texts claiming to be from M&S when they are not, so do be cautious. Remember that we will never contact you and ask you to provide us with personal account information, like usernames, and we will never ask you to give us your password.”

The email provides links to the company’s online security advice page and updates on the cyber incident.

“To give you extra peace of mind, next time you visit or login to your M&S.com account on our website or app, you will also be prompted to reset your password.

“We sincerely apologise for any inconvenience caused to you and all of our customers.”


A D V E R T I S E M E N T


Inside Croydon – If you want real journalism, delivering real news, from a publication that is actually based in the borough, please consider paying for it. Sign up today: click here for more details


PAID ADS: To advertise your services or products to our 10,000 weekday visitors to the site, as featured on Google News Showcase, email us inside.croydon@btinternet.com for our unbeatable ad rates



  • If you have a news story about life in or around Croydon, or want to publicise your residents’ association or business, or if you have a local event to promote, please email us with full details at inside.croydon@btinternet.com
  • As featured on Google News Showcase

About insidecroydon

News, views and analysis about the people of Croydon, their lives and political times in the diverse and most-populated borough in London. Based in Croydon and edited by Steven Downes. To contact us, please email inside.croydon@btinternet.com
This entry was posted in Business, Crime and tagged , , , , . Bookmark the permalink.

Join the conversation here