M&S says customer data stolen in cyberattack, forces password resets
ID: c927820b-664e-5694-8d0d-4a33c361de34
STIX ID: report--c927820b-664e-5694-8d0d-4a33c361de34
Feed Name: Bleeping Computer
Marks & Spencer confirmed a ransomware attack on April 22, 2025 attributed to DragonForce affiliates using Scattered Spider social engineering; attackers encrypted VMware ESXi virtual machines and stole customer personal information (full names, emails, home addresses, phone numbers, dates of birth, order history, household information, Sparks Pay reference numbers and masked card details). The breach disrupted operations across 1,400 stores, caused a pause to online ordering and prompted mandatory password resets for active accounts; M&S says there is no evidence of usable card/payment data or passwords being exposed and is notifying affected customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
