M&S confirms personal customer data stolen in cyber breach
Marks and Spencer (M&S) has revealed that personal customer data was stolen during the cyber attack that hit the retailer last month.
The retailer today (13 May) released a statement on the London Stock Exchange board, confirming that the data had been taken. However, it told customers that there is “no need to take any action”.
M&S said that the data breached in the cyber incident, which is now entering its fourth week, did not include usable payment or card details, as that information “does not hold on our systems”, and does not include any account passwords.
The FTSE 100-listed business said it had engaged leading cybersecurity experts and reported the incident to relevant government and law enforcement bodies, as investigations continue.
The statement added: “There is no evidence that this data has been shared.
“We have said to customers that there is no need to take any action. For extra peace of mind, they will be prompted to reset their password the next time they visit or log onto their M&S account, and we have shared information on how to stay safe online.”
Subscribe to Grocery Gazette for free
Sign up here to get the latest grocery and food news each morning
The latest update follows M&S attempts to restore its operations to normal following the fallout from the cyber attack last month, first reported by the retailer on 22 April.
The business has faced severe disruption, resulting in work-from-home staff being locked out of internal systems, warehouse employees being turned away, the suspension of click and collect and online sales, and product shortages due to supply delays.
M&S is not the only retailer to fall victim to a cyber attack in recent weeks.
Co-op is also facing ongoing disruptions from its ransomware attack, with essential supplies being rerouted to remote locations, as shoppers complain of empty shelves.
Last week, the convenience giant revealed that the attack had exposed “data relating to a significant number of our current and past members”, as an anonymous group behind the attack claimed they had “customer database, and Co-op member card data”.





1 Comment. Leave new
I wonder why they’re still working from home.