Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Blog

M&S admits customer data was taken in 2025 cyberattack: what shoppers need to know

By TheFinanceBase Team6 min read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Marks & Spencer said some personal customer information was taken during a sophisticated cyber incident in 2025. The potentially affected data included names, contact details, dates of birth, order history, household information, masked payment-card details and some customer reference numbers. M&S said usable payment details and account passwords were not included, and that it had no evidence the data had been shared.

The short answer

M&S confirmed in May 2025 that personal customer data had been taken. The company used conditional wording: the listed categories could have been involved, so this does not mean every M&S customer’s information was affected.

The incident created a continuing risk of convincing impersonation emails, texts and calls. Personal details such as an address, date of birth or previous order information can make a scam message appear genuine even when no full card number or password has been exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

M&S said it was working with government authorities, law enforcement and cybersecurity specialists. Its customer cyber update and FAQs remain the appropriate source for account-specific guidance.

What customer information may have been taken?

According to M&S, the information potentially involved included:

Possibly included M&S said was not included
Names Usable payment-card details
Email addresses Account passwords
Postal addresses
Telephone numbers
Dates of birth
Online order history
Household information
Masked payment-card details
Customer reference numbers linked to M&S credit cards or Sparks Pay

A masked payment-card detail is a partial or obscured identifier, not a complete card number that can normally be used to make a payment. A customer reference number linked to an M&S credit card or Sparks Pay account is also not the same as the card number itself.

These exclusions are M&S’s statements about the information held on its systems. They reduce the risk of direct card misuse, but they do not eliminate the possibility of phishing or identity-based impersonation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who may be affected?

M&S has not said that every customer was affected. Potentially relevant groups include current and former M&S.com customers, Sparks members, people with online order histories, and current or former M&S credit-card or Sparks Pay customers.

Being a former customer does not necessarily mean that all historical information had already been removed from every relevant system. Conversely, being an M&S customer does not prove that your records were among those taken. The company’s published notice is the basis for its confirmed customer guidance.

What happened and when?

  • April 21, 2025: M&S told Reuters that it had alerted the National Cyber Security Centre, according to contemporaneous reporting.
  • April 23: M&S said stores remained open, but contactless payments were unavailable, Click & Collect collection was paused and some online deliveries could be delayed. It was moving processes offline.
  • April 25: M&S paused the taking of online orders through its websites and apps.
  • May 2: The Information Commissioner’s Office said it had received reports from M&S and the Co-op and was making enquiries with them alongside the NCSC.
  • May 13: The customer-data theft admission was reported contemporaneously. M&S’s own customer notice set out the potentially affected data categories and exclusions during May.

The operational outage and the later confirmation that some data had been taken are related parts of the same incident, but an outage by itself is not proof that customer data was stolen. M&S subsequently described taking systems offline, rebuilding some applications and file systems, and using manual processes.

What should M&S customers do now?

  1. Be alert for impersonation. Treat unexpected emails, texts and calls claiming to be from M&S, a bank or a delivery service with caution.
  2. Do not share security information. An inbound caller or message should never need your password, one-time verification code, full card details or permission to install software.
  3. Do not use links in unexpected messages. Open the M&S app yourself or type the official website address manually.
  4. Use a unique M&S password. If you reused the same password elsewhere, change it on those services too—especially on the email account associated with M&S.
  5. Monitor accounts normally. Check bank and card statements for unusual activity. M&S said usable card details were not included, so cancelling a card solely because of this incident is not normally necessary unless your bank identifies suspicious activity or you have another reason.
  6. Report suspicious contact. Use the relevant messaging platform’s reporting tools and the UK’s official fraud-reporting channels where appropriate.
  7. Use official support if login recovery fails. If you cannot access your account after a reset, start from M&S’s official website or app rather than from a message you received.

M&S initially said customers did not need to take immediate action, while also saying customers would be prompted to reset their M&S password at their next website or app login. Those are different points: there was no stated need for emergency account closure, but changing reused passwords remains sensible security practice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was my card or password stolen?

M&S said no usable payment-card details and no account passwords were included. That does not mean customers should ignore suspicious activity. Masked card details, customer references and personal information can still help a fraudster make a message or phone call look authentic.

For example, a scammer who knows a genuine previous order, delivery address or household detail may try to persuade you to “verify” an account or provide a one-time code. A password reset email can also be impersonated. Start the reset process from the official M&S app or website instead of trusting the message’s link.

Was it ransomware, and who was responsible?

Contemporary reports widely described the incident as ransomware-related and mentioned possible groups including Scattered Spider and DragonForce. However, the M&S public statements covered by the company’s cyber update do not confirm a specific criminal group or publicly establish the attack method.

The accurate position is that ransomware and attribution claims were reported or suspected, not confirmed by the primary M&S material cited here. A named group should not be treated as responsible without an official attribution from M&S, law enforcement, the NCSC or a well-supported forensic investigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How badly was M&S affected?

The incident disrupted online retail and parts of store and supply-chain operations. Stores stayed open, but contactless payments, Click & Collect and online deliveries were affected before online ordering was paused on April 25.

M&S’s initial 2025 full-year results estimated an approximately £300 million impact on 2025/26 operating profit, before mitigation, insurance and trading actions. That was an early estimate of the profit impact—not a final statement that the incident cost £300 million in direct expenses.

In its results for the 52 weeks ended March 28, 2026, M&S reported £131.3 million in incident-related costs and £100 million in insurance proceeds. Adjusted profit before tax was £671.4 million, compared with £881.1 million the previous year. M&S said the first half was heavily affected, followed by sales and profit growth in the second half.

Fashion, Home & Beauty was particularly affected by the pause in online trading, systems-access problems, stock-flow disruption and the clearance of excess seasonal stock. M&S reported that customer-facing systems had been restored in the summer of 2025 and that practically all operational systems had been recovered by its later reporting.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What regulators said

On May 2, 2025, the ICO said it had received reports from M&S and the Co-op and was making enquiries while working with the NCSC. It advised affected customers to follow retailer updates, use strong passwords and avoid reusing passwords.

That statement does not amount to a finding that M&S broke the law, a completed investigation or a fine. The public position in the cited material is that enquiries and cooperation were under way.

What remains unknown?

  • The total number of affected customers.
  • The precise number of records taken.
  • Whether any individual customer’s information was subsequently accessed or misused.
  • Whether the information was later shared or published. M&S said it had no evidence it had been shared.
  • The confirmed identity of the attackers.
  • The final regulatory outcome, if one has not been publicly established.

Official updates

For the latest customer guidance, use M&S’s official cyber update. The ICO’s position is available in its statement on cyber incidents affecting retailers. M&S’s operational and financial follow-up is set out in its 2026 full-year results.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.