Urbanrreporter Daily Briefing Go
UrbanrReporter.co.uk Urbanrreporter Daily Briefing Guides
Blog Business Local Politics Tech World

M&S Cyberattack Customer Data Breach – What You Need to Know

Freddie Jack Bennett • 2026-05-04 • Reviewed by Hanna Berg


May 13, 2025

Urban Reporter

Marks & Spencer has confirmed that a ransomware attack in April 2025 resulted in the theft of personal customer data, including names, addresses, phone numbers, dates of birth, and online order histories. The retailer, one of the UK’s largest, disclosed the breach publicly on May 13 after notifying affected customers via email.

The attack, attributed to the cybercrime groups Scattered Spider and DragonForce, disrupted in-store services across UK branches during the Easter weekend before the company publicly acknowledged the incident. M&S has stated that no payment card details or passwords were compromised, as this information was not stored on the affected systems.

The breach forms part of a broader pattern targeting major UK retailers, including Harrods and Co-op. M&S has engaged cybersecurity specialists and is cooperating with the National Cyber Security Centre and law enforcement agencies while urging customers to remain vigilant against potential phishing attempts.

What are the details of the M&S cyberattack?

The cyberattack on Marks & Spencer began over the Easter weekend of April 19-21, 2025, when customers first reported disruptions to contactless payments and Click & Collect services across UK stores. M&S issued a formal statement on April 22 acknowledging the incident and reporting it to the UK’s National Cyber Security Centre.

🔒
Incident
Ransomware attack on M&S systems identified in late April 2025
👤
Data Impacted
Personal customer data including names, addresses, dates of birth, and order histories
Status
No evidence that stolen data has been shared publicly
⚠️
Advice
M&S urges password resets and vigilance against phishing attempts

What customer data was affected?

The stolen information includes basic personal details such as names, postal addresses, email addresses, and phone numbers provided during online or in-store transactions. Dates of birth submitted during account registration or loyalty programme sign-ups were also among the compromised data, along with complete online order histories.

In some cases, customers who hold M&S credit cards or use the Sparks loyalty programme may have had their customer reference numbers accessed. The attackers may have obtained these identifiers, though M&S has emphasized that no financial account passwords or full payment card details were stored on their systems in a usable format.

The operational impact extended beyond data theft. Automated ordering and stock management systems were shut down, forcing staff to implement manual tracking processes. In-store disruptions included non-functional gift-card terminals, disabled returns kiosks, and an inaccessible Sparks loyalty programme, contributing to stock shortages and customer complaints during the recovery period.

M&S data breach customer information timeline

The following timeline reconstructs key events based on M&S corporate statements and cybersecurity reporting:

  • February 2025: Security researchers indicate a possible earlier infiltration involving theft of the NTDS.dit file containing password hashes from M&S systems
  • April 19-21: Easter weekend disruptions begin with contactless payment failures and Click & Collect service glitches across UK stores
  • April 22: M&S publicly acknowledges the cyber incident, notifies the National Cyber Security Centre, and engages cybersecurity experts; stores remain open with modified processes
  • Late April: Attack confirmed as ransomware; operational impact projected to extend through June or July; estimated £300 million reduction in annual profit expected
  • May 13: M&S publicly confirms data theft, begins notifying affected customers via email from operations director Jayne Wall, and proactively resets passwords for online accounts

What should customers do after the M&S data breach?

M&S CEO Stuart Machin has stated that customers do not need to take immediate action beyond resetting their passwords when prompted upon next login. The company has implemented automatic password resets for all online accounts as a precautionary measure. Systems do not store financial data, according to M&S, meaning payment cards and banking details remain secure.

The retailer is advising customers to remain alert for phishing communications. Stolen personal information enables attackers to craft convincing emails, phone calls, or text messages that appear to originate from M&S. These communications may request additional sensitive information or direct recipients to fraudulent websites designed to harvest credentials.

Protecting yourself from scam attempts

Customers should verify the authenticity of any communication claiming to be from M&S by contacting the retailer directly through official channels rather than using contact details provided in suspicious messages. M&S has published frequently asked questions detailing the incident and warning against sharing sensitive information via unsolicited contacts.

Phishing vigilance

Be cautious of emails, calls, or texts requesting personal information, passwords, or payment details. M&S will never ask for your full password or request sensitive data through unsolicited communications. Report suspicious activity to the company through official channels.

Those who have experienced fraud linked to the breach may pursue remedies through their banks, which can monitor accounts for suspicious transactions, or through the Information Commissioner’s Office, which oversees data protection compliance in the UK. The ICO investigates data breaches and can impose fines on organizations that fail to protect personal information adequately.

The M&S data breach notification email

Affected customers began receiving notification emails on May 13, 2025, sent by operations director Jayne Wall on behalf of M&S. The communications outlined what information was involved, confirmed that payment data was not accessible to attackers, and provided guidance on next steps including password resets and fraud awareness.

Customers who believe they may have been affected but have not received notification should check their spam folders and verify that their registered email address with M&S is current. Those with concerns can contact M&S customer services through official channels to confirm whether their data was involved in the breach.

Is compensation available for the M&S cyberattack data breach?

M&S has not announced any compensation programme or payout scheme for affected customers. The company has focused communications on explaining the nature of the breach, confirming that no financial data was compromised, and advising on security precautions rather than offering financial remedies.

Customers who have suffered financial losses due to fraud directly linked to the breach may have grounds to pursue claims through their banks or credit card providers, who can investigate unauthorized transactions and process refunds where appropriate under financial regulations.

Regulatory recourse

Individuals who believe they have been harmed by the breach may file complaints with the Information Commissioner’s Office. The ICO has authority to investigate data protection violations and can take enforcement action against organizations found to have breached UK GDPR obligations.

No information was found linking financial commentator Martin Lewis or his organization to the M&S breach. Claims management firms have begun advertising services related to data breach compensation, though customers should exercise caution when engaging with such services, as fees and success rates vary significantly.

Legal experts note that data breach compensation claims in the UK typically require demonstrating material harm or distress resulting from the incident. The absence of evidence that stolen data has been publicly shared or misused may affect the viability of individual claims, though this remains an evolving area of law.

Who was behind the M&S cyberattack?

Security researchers have identified two cybercrime groups associated with the M&S attack. Scattered Spider, known for sophisticated social engineering operations against large organizations, confirmed their involvement through a ransom note delivered directly to M&S CEO Stuart Machin. The group operates using a Ransomware-as-a-Service model employing the DragonForce encryption toolkit.

The attack employed double extortion tactics, meaning hackers both encrypted data to disrupt operations and threatened to release stolen information unless ransom demands were met. This approach has become standard among major ransomware operations, creating pressure on victims even when data backups exist.

How the attackers gained access

Investigations indicate the breach originated through social engineering targeting Tata Consultancy Services, the third-party IT helpdesk provider contracted by M&S. Attackers posed as internal staff members to obtain legitimate credentials from TCS support personnel, bypassing perimeter security controls to gain entry to M&S corporate systems.

Security researchers from CM Alliance have noted that attackers may have established initial access as early as February 2025 by stealing the NTDS.dit file, which contains password hashes from M&S Active Directory systems. This credential cache could theoretically enable offline password cracking attempts, though M&S reports that no usable passwords were extracted.

The M&S incident was not isolated. Scattered Spider and related groups conducted simultaneous attacks against other UK retailers including Harrods and the Co-operative Group, suggesting a coordinated campaign targeting the retail sector’s security vulnerabilities during a high-traffic trading period.

What we know and what remains unclear

Established information Unconfirmed or pending details
Personal customer data was stolen including names, addresses, phone numbers, dates of birth, and order histories Precise number of customers whose data was affected
No payment card details or passwords were stored in a usable format Whether the February 2025 NTDS.dit file theft is definitively connected to the April attack
Attack attributed to Scattered Spider using DragonForce ransomware Ransom demands and whether any payment was made
Entry point was through third-party supplier TCS via social engineering Full extent of data accessed in initial February infiltration
No evidence exists that stolen data has been shared publicly Whether data has been traded privately on criminal forums
M&S engaged NCSC and law enforcement; cooperation ongoing Timeline for full systems restoration

The broader context: UK retail under cyber threat

The M&S breach reflects a wider pattern of sophisticated attacks against UK retail organizations. The retail sector handles vast quantities of customer data and processes significant payment volumes, making it an attractive target for ransomware operations seeking maximum financial leverage.

The simultaneous targeting of multiple major retailers by Scattered Spider suggests organized, coordinated efforts rather than opportunistic attacks. Social engineering techniques proved effective against helpdesk operations, exploiting human factors rather than technical vulnerabilities alone.

Industry observers note that third-party suppliers represent a persistent weak point across corporate cybersecurity. The M&S breach via TCS follows similar patterns seen in other major incidents where suppliers provided an indirect path to primary targets with stronger internal security controls.

Supply chain vulnerability

Organizations relying on third-party IT providers should verify that supplier security practices meet equivalent standards to internal policies. The M&S breach demonstrates how attackers exploit trust relationships between companies and their technology partners.

Official statements and sources

“The nature of the incident means that some personal customer data has been taken, but there is no evidence that it has been shared.”

— M&S Corporate Cyber Update, corporate.marksandspencer.com

The official M&S cyber update page remains the primary authoritative source for customer guidance. The company has committed to providing regular updates as investigations progress and systems are restored. Key sources for this report include M&S corporate communications, cybersecurity industry analysis from Blackfog and CM Alliance, and technology news coverage from Cybersecurity Dive.

The National Cyber Security Centre has published general guidance on ransomware prevention and response, applicable to organizations and individuals seeking to understand defensive measures. The Information Commissioner’s Office regulates data protection compliance and handles breach notifications from organizations operating in the UK.

Summary and next steps

The M&S cyberattack represents one of the most significant data breaches affecting a UK retailer in recent years. While no payment data was compromised, the theft of personal information including names, addresses, and order histories creates potential risks for targeted phishing and identity-related fraud. The incident highlights vulnerabilities in supply chain security and the sophisticated tactics employed by established ransomware groups.

Customers should complete any prompted password resets, monitor accounts for unusual activity, and verify all communications claiming to originate from M&S before responding. Those experiencing fraud linked to the breach should contact their financial institutions and consider filing reports with relevant authorities including the ICO. Related network disruptions and administrative challenges affecting UK consumers can be tracked in our coverage of G Network Collapses Administration – What Customers Need to Know.

For customers navigating broader financial and administrative challenges during this period, our guide to Universal Credits Sign In – Official Guide and Troubleshooting Steps provides additional support resources. M&S has stated it will continue updating affected customers as its investigation progresses and systems return to full operation.

Frequently asked questions

What specific customer data was taken in the M&S breach?

The stolen information includes names, postal addresses, email addresses, phone numbers, dates of birth, and online order histories. Some customers’ credit card reference numbers or Sparks loyalty programme identifiers may also have been accessed.

Were my payment card details stolen?

No. M&S has confirmed that payment card details were masked and unusable because the company does not store full card numbers. Similarly, passwords were not stored in a format accessible to the attackers.

Has my stolen data been shared or sold online?

M&S has stated that no evidence exists showing stolen data has been shared publicly. However, the absence of public disclosure does not guarantee the data has not been traded privately.

What should I do if I receive a suspicious email claiming to be from M&S?

Do not click links or provide personal information. Contact M&S directly through official channels to verify the communication. Report suspicious emails to your email provider and to M&S’s dedicated fraud team.

Can I claim compensation from M&S for the data breach?

M&S has not announced any compensation programme. Customers who have suffered direct financial losses may pursue remedies through their banks or file complaints with the Information Commissioner’s Office, though individual claims require demonstrating harm.

How did attackers gain access to M&S systems?

The breach originated through social engineering targeting Tata Consultancy Services, M&S’s IT helpdesk provider. Attackers impersonated internal staff to obtain legitimate credentials from TCS support personnel.

Is Martin Lewis involved with the M&S breach compensation?

No information links financial commentator Martin Lewis or his organization to the M&S breach or any related compensation schemes.

When will M&S fully restore its systems?

M&S initially projected operational impacts extending through June or July 2025. The timeline for complete systems restoration remains subject to the ongoing investigation and security verification processes.

Freddie Jack Bennett

About the author

Freddie Jack Bennett

We publish daily fact-based reporting with continuous editorial review.