Marks & Spencer (M&S) has confirmed that a cyberattack that took place three weeks ago led to a breach of some customers' data. The attack, which appears to be related to ransomware, has caused disruption to online ordersand has also affected the availability of some products in stores.

In a statement, the company clarified that the stolen information did not include payment details or passwords, but rather was limited to names, mailing addresses and order history.
See also: Hackers are now testing ClickFix attacks against Linux
Marks & Spencer said no immediate action was required from customers. However, as a precaution, users can change their password the next time they log into their M&S. The company declined to say how many customers were affected.
The giant's website and app have been down since April 25. The incident is reportedly related to the notorious hacker group "Scattered Spider".
In an effort to mitigate the impact, M&S has strengthened its systems, working with specialist cybersecurity consultants, and has reported the incident to the relevant government authorities and law enforcement agencies.
See also: Asus DriverHub flaws lead to RCE attacks
In response to recent cyber threats (attacks on Marks & Spencer, Co-op and Harrods) the UK's National Cyber Security Centre (NCSC) has published a guide with key measures that companies should take to reduce the risk of digital intrusion and strengthen the protection of their infrastructure.
See also: New phishing attack abuses Blob URIs to bypass SEG

The organization's proposals are summarized in the following key points:
- Adopting multi-factor authentication (MFA) across all systems, without exceptions, to increase the difficulty of access by unauthorized users.
- Continuous monitoring for suspicious activity, such as unrecognized logins or account breaches, especially those detected through Microsoft Entra ID Protection.
- Regular auditing of administrative accounts (Domain, Enterprise and Cloud Admin), with the aim of confirming that they are only used by authorized personnel.
- Review support procedures regarding password resets, ensuring strong authentication protocols are in place before access is granted.
- Strengthen connection monitoring with an emphasis on suspicious sources, such as home VPNs or unidentified endpoints, to detect and isolate potential threats.
The NCSC emphasizes that all businesses, regardless of size or sector, must operate with the logic of "early preparation" and assume that they may be targeted by cybercriminals in the near future.
Source: www.theguardian.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
