logo

M&S says customer data stolen in cyberattack, forces password resets

ID: c927820b-664e-5694-8d0d-4a33c361de34

STIX ID: report--c927820b-664e-5694-8d0d-4a33c361de34

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-05-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Marks & Spencer confirmed a ransomware attack on April 22, 2025 attributed to DragonForce affiliates using Scattered Spider social engineering; attackers encrypted VMware ESXi virtual machines and stole customer personal information (full names, emails, home addresses, phone numbers, dates of birth, order history, household information, Sparks Pay reference numbers and masked card details). The breach disrupted operations across 1,400 stores, caused a pause to online ordering and prompted mandatory password resets for active accounts; M&S says there is no evidence of usable card/payment data or passwords being exposed and is notifying affected customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.