Customer Data Stolen in Cyberattack, Confirms Marks & Spencer

Customer Data Stolen in Cyberattack, Confirms Marks & Spencer

Marks & Spencer Hit by Cyberattack: Customer Data Breached in Major Security Incident

Marks & Spencer (M&S), one of the UK’s most iconic retailers, has disclosed a major cybersecurity breach that exposed sensitive customer data and severely disrupted its operations for over three weeks.

The breach, which began during the Easter bank holiday, has paralyzed key digital functions. Online shopping has been offline since the attack began, while some in-store services have also suffered setbacks due to protective system shutdowns.

What Was Stolen?

According to M&S, attackers infiltrated their systems and exfiltrated personal data belonging to millions of customers. Exposed details may include:

  • Full names
  • Email and home addresses
  • Phone numbers
  • Dates of birth
  • Online purchase history

CEO Stuart Machin stressed that there’s currently no evidence of the stolen information being circulated or sold. However, cybersecurity analysts caution that this status could shift at any moment.

Notably, payment card details and account passwords were not part of the breach. M&S explained that their systems do not store full payment data, rendering any partial records unusable. As a precaution, all online customers will be asked to reset their passwords on their next login attempt.

Who’s Behind the Attack?

Investigations point to DragonForce, a ransomware syndicate known for aggressive double-extortion tactics—locking up data while simultaneously stealing it to pressure victims into paying. DragonForce reportedly operates as a Ransomware-as-a-Service (RaaS) operation, selling its tools to affiliated cybercriminal groups.

Security experts believe the attack began through social engineering, likely involving fake support requests or password reset scams targeting M&S IT helpdesk employees. Evidence also links the breach to Scattered Spider (UNC3944), a notorious cyber crew made up of young hackers based in the US and UK.

Alarmingly, the attackers may have extracted NTDS.dit, a critical file containing credentials and password hashes for the company’s entire Active Directory system—giving them broad access across M&S’s internal infrastructure.

Financial and Operational Fallout

The consequences have been significant. M&S’s share price tumbled by around 11%, wiping over £1 billion from its market capitalization. Online services remain nonfunctional, and there’s still no clear timeline for when they’ll return. In-store inventory has also been affected as some systems were shut down to prevent further spread of the attack.

The company has reached out to 9.4 million online customers, notifying them of the breach and encouraging vigilance. While M&S says no immediate customer action is required, security professionals advise being on alert for phishing emails or messages impersonating M&S.

Authorities and Response

The retailer is now working closely with the National Crime Agency (NCA), National Cyber Security Centre (NCSC), and Metropolitan Police to identify the perpetrators and prevent further damage.

This incident underscores the escalating threat of ransomware campaigns—and the urgent need for businesses to bolster their cybersecurity defences, especially when handling personal data at scale.

More Articles & Posts