M&S says customers’ personal data taken by hackers

Marks & Spencer Confirms Cyberattack Compromised Customer Data but No Payment Details
Photo: Sky News

Marks & Spencer Confirms Cyberattack Compromised Customer Data but No Payment Details

Marks & Spencer (M&S), the British retail giant, has disclosed that personal customer data was compromised following a major cyberattack. The company clarified that no payment information or passwords were accessed. The cyber incident, allegedly orchestrated by the hacking group Scattered Spider, began around Easter Monday and has significantly disrupted operations, including online sales and recruitment. In a statement posted on social media, CEO Stuart Machin assured customers that although their personal data had been accessed, there was no need for immediate action. However, customers will be prompted to reset their passwords for added security. The company has also issued guidance on staying safe online. Internally, the situation appears chaotic. According to anonymous sources within M&S, the company lacked a business continuity plan for such attacks, resulting in staff working under extreme stress, including spending nights at the office. Agency staff at some distribution centers were instructed to stay home, and shelves at stores across the UK have reportedly been left empty. Recovery is expected to take months, highlighting the seriousness of the breach and the challenges of cybersecurity preparedness in large organizations.

Leave a Reply

Your email address will not be published. Required fields are marked *