What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Marks & Spencer said some personal customer information was taken during a sophisticated cyber incident in 2025. The potentially affected data included names, contact details, dates of birth, order history, household information, masked payment-card details and some customer reference numbers. M&S said usable payment details and account passwords were not included, and that it had no evidence the data had been shared.
The short answer
M&S confirmed in May 2025 that personal customer data had been taken. The company used conditional wording: the listed categories could have been involved, so this does not mean every M&S customer’s information was affected.
The incident created a continuing risk of convincing impersonation emails, texts and calls. Personal details such as an address, date of birth or previous order information can make a scam message appear genuine even when no full card number or password has been exposed.
M&S said it was working with government authorities, law enforcement and cybersecurity specialists. Its customer cyber update and FAQs remain the appropriate source for account-specific guidance.
#1 Best Overall
What customer information may have been taken?
According to M&S, the information potentially involved included:
| Possibly included | M&S said was not included |
|---|---|
| Names | Usable payment-card details |
| Email addresses | Account passwords |
| Postal addresses | |
| Telephone numbers | |
| Dates of birth | |
| Online order history | |
| Household information | |
| Masked payment-card details | |
| Customer reference numbers linked to M&S credit cards or Sparks Pay |
A masked payment-card detail is a partial or obscured identifier, not a complete card number that can normally be used to make a payment. A customer reference number linked to an M&S credit card or Sparks Pay account is also not the same as the card number itself.
These exclusions are M&S’s statements about the information held on its systems. They reduce the risk of direct card misuse, but they do not eliminate the possibility of phishing or identity-based impersonation.
Who may be affected?
M&S has not said that every customer was affected. Potentially relevant groups include current and former M&S.com customers, Sparks members, people with online order histories, and current or former M&S credit-card or Sparks Pay customers.
Being a former customer does not necessarily mean that all historical information had already been removed from every relevant system. Conversely, being an M&S customer does not prove that your records were among those taken. The company’s published notice is the basis for its confirmed customer guidance.
What happened and when?
- April 21, 2025: M&S told Reuters that it had alerted the National Cyber Security Centre, according to contemporaneous reporting.
- April 23: M&S said stores remained open, but contactless payments were unavailable, Click & Collect collection was paused and some online deliveries could be delayed. It was moving processes offline.
- April 25: M&S paused the taking of online orders through its websites and apps.
- May 2: The Information Commissioner’s Office said it had received reports from M&S and the Co-op and was making enquiries with them alongside the NCSC.
- May 13: The customer-data theft admission was reported contemporaneously. M&S’s own customer notice set out the potentially affected data categories and exclusions during May.
The operational outage and the later confirmation that some data had been taken are related parts of the same incident, but an outage by itself is not proof that customer data was stolen. M&S subsequently described taking systems offline, rebuilding some applications and file systems, and using manual processes.
What should M&S customers do now?
- Be alert for impersonation. Treat unexpected emails, texts and calls claiming to be from M&S, a bank or a delivery service with caution.
- Do not share security information. An inbound caller or message should never need your password, one-time verification code, full card details or permission to install software.
- Do not use links in unexpected messages. Open the M&S app yourself or type the official website address manually.
- Use a unique M&S password. If you reused the same password elsewhere, change it on those services too—especially on the email account associated with M&S.
- Monitor accounts normally. Check bank and card statements for unusual activity. M&S said usable card details were not included, so cancelling a card solely because of this incident is not normally necessary unless your bank identifies suspicious activity or you have another reason.
- Report suspicious contact. Use the relevant messaging platform’s reporting tools and the UK’s official fraud-reporting channels where appropriate.
- Use official support if login recovery fails. If you cannot access your account after a reset, start from M&S’s official website or app rather than from a message you received.
M&S initially said customers did not need to take immediate action, while also saying customers would be prompted to reset their M&S password at their next website or app login. Those are different points: there was no stated need for emergency account closure, but changing reused passwords remains sensible security practice.
Was my card or password stolen?
M&S said no usable payment-card details and no account passwords were included. That does not mean customers should ignore suspicious activity. Masked card details, customer references and personal information can still help a fraudster make a message or phone call look authentic.
For example, a scammer who knows a genuine previous order, delivery address or household detail may try to persuade you to “verify” an account or provide a one-time code. A password reset email can also be impersonated. Start the reset process from the official M&S app or website instead of trusting the message’s link.
Was it ransomware, and who was responsible?
Contemporary reports widely described the incident as ransomware-related and mentioned possible groups including Scattered Spider and DragonForce. However, the M&S public statements covered by the company’s cyber update do not confirm a specific criminal group or publicly establish the attack method.
The accurate position is that ransomware and attribution claims were reported or suspected, not confirmed by the primary M&S material cited here. A named group should not be treated as responsible without an official attribution from M&S, law enforcement, the NCSC or a well-supported forensic investigation.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →How badly was M&S affected?
The incident disrupted online retail and parts of store and supply-chain operations. Stores stayed open, but contactless payments, Click & Collect and online deliveries were affected before online ordering was paused on April 25.
Best Value
M&S’s initial 2025 full-year results estimated an approximately £300 million impact on 2025/26 operating profit, before mitigation, insurance and trading actions. That was an early estimate of the profit impact—not a final statement that the incident cost £300 million in direct expenses.
In its results for the 52 weeks ended March 28, 2026, M&S reported £131.3 million in incident-related costs and £100 million in insurance proceeds. Adjusted profit before tax was £671.4 million, compared with £881.1 million the previous year. M&S said the first half was heavily affected, followed by sales and profit growth in the second half.
Fashion, Home & Beauty was particularly affected by the pause in online trading, systems-access problems, stock-flow disruption and the clearance of excess seasonal stock. M&S reported that customer-facing systems had been restored in the summer of 2025 and that practically all operational systems had been recovered by its later reporting.
Free tools Windows power users keep installed
One-click scans. No signup required.
What regulators said
On May 2, 2025, the ICO said it had received reports from M&S and the Co-op and was making enquiries while working with the NCSC. It advised affected customers to follow retailer updates, use strong passwords and avoid reusing passwords.
That statement does not amount to a finding that M&S broke the law, a completed investigation or a fine. The public position in the cited material is that enquiries and cooperation were under way.
What remains unknown?
- The total number of affected customers.
- The precise number of records taken.
- Whether any individual customer’s information was subsequently accessed or misused.
- Whether the information was later shared or published. M&S said it had no evidence it had been shared.
- The confirmed identity of the attackers.
- The final regulatory outcome, if one has not been publicly established.
Official updates
For the latest customer guidance, use M&S’s official cyber update. The ICO’s position is available in its statement on cyber incidents affecting retailers. M&S’s operational and financial follow-up is set out in its 2026 full-year results.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →

