Marks & Spencer
Disclosed Apr 22, 20251 year agoUnverified
Scattered Spider cyberattack on M&S steals customer data, halts online sales
Marks & Spencer disclosed a cyber incident in April 2025 that disrupted stores and halted online orders, later confirming customer names, birth dates, contact details and order histories were stolen and forcing password resets. The attack was attributed to Scattered Spider and began with social engineering.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Apr 22, 2025 |
| Attack | Ransomware |
| Data exposed | Names, Dates of birth, Addresses, Emails, Phone numbers, Other |
| Sector | Retail · GB |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Marks & Spencer confirms cybersecurity incident amid ongoing disruptiontechcrunch.com · News | News |
| Marks & Spencer confirms customers' personal data was stolen in hacktechcrunch.com · News | News |
| M&S confirms social engineering led to massive ransomware attackbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Apr 22, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.