Experts Advise Caution After M&S Data Breach Exposes Customer Information
Marks & Spencer (M&S) has confirmed that a significant data breach has led to the theft of personal information from its customers. Although the company reassured users that no payment or card details were taken and passwords were not compromised, names, addresses, and phone numbers were among the stolen data. Cybersecurity experts have raised concerns about the increased risk of phishing scams and identity fraud, urging customers to remain cautious.
Experts recommend that customers be vigilant against suspicious emails, messages, and calls that may use personal details to appear legitimate. The attack is attributed to a known group, Scattered Spider, which specializes in exploiting human vulnerabilities rather than technical flaws. M&S emphasized they would never ask for passwords or sensitive account information directly.
Cybersecurity professionals also advise changing passwords and enabling two-factor authentication, even though passwords were not stolen, as attackers often use data from past breaches to gain access. The UK’s Take Five campaign’s advice to ‘stop, challenge, protect’ is recommended for preventing further victimization. Despite M&S stating no further action is necessary, experts stress proactive steps to mitigate risks.
