Skip to content

Marks & Spencer

Disclosed Apr 22, 20251 year agoUnverified

Scattered Spider cyberattack on M&S steals customer data, halts online sales

Marks & Spencer disclosed a cyber incident in April 2025 that disrupted stores and halted online orders, later confirming customer names, birth dates, contact details and order histories were stolen and forcing password resets. The attack was attributed to Scattered Spider and began with social engineering.

What is known

People affectedNot stated in the sources we have
DisclosedApr 22, 2025
AttackRansomware
Data exposedNames, Dates of birth, Addresses, Emails, Phone numbers, Other
SectorRetail · GB
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalApr 22, 2025
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Marks & Spencer

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.