Marks & Spencer has mentioned for the primary time that some non-public buyer knowledge was once taken within the cyber-attack that has crippled its on-line operation for greater than 3 weeks.
Since the store’s IT methods have been hit by means of a ransomware assault, it has now not been taking on-line orders, and the provision of a few merchandise in its shops has been affected after it took a few of its methods offline in reaction.
The corporate mentioned the information accessed does now not come with usable cost or card main points, nor any account passwords. The Guardian understands the main points taken are names, addresses and order histories.
M&S mentioned it had instructed consumers there was once no want to take any motion, even supposing “for extra peace of mind” they’d be precipitated to reset their password the following time they log into their M&S account. It didn’t say what number of consumers were affected.
“Today, we are writing to customers informing them that due to the sophisticated nature of the incident, some of their personal customer data has been taken,” the corporate mentioned.
“Importantly, the data does not include usable payment or card details, which we do not hold on our systems, and it does not include any account passwords. There is no evidence that this data has been shared.”
The crew has now not been ready to take any orders thru its site or app since 25 April because it tries to get to the bottom of the issues led to by means of the assault, which has been related to the hacking crew Scattered Spider.
The store mentioned it had taken steps to offer protection to its methods and engaged main cybersecurity mavens. It has reported the incident to related executive government and legislation enforcement.
after publication promotion
The Information Commissioner’s Office showed on 2 May that it had won reviews from M&S and the Co-op Group, which has additionally suffered a cyber-attack. The ICO mentioned it was once running carefully with the National Cyber Security Centre.
Stephen Bonner, the ICO deputy commissioner, mentioned on the time: “We recognise that seeing cyber-attacks in the news can be concerning, especially if you are a customer.” He mentioned the ICO site had recommendation for people who find themselves anxious about their non-public knowledge.