Cyber incident

As we continue to manage the current cyber incident, we have written to customers to let them know that unfortunately the sophisticated and targeted nature of the incident has meant that some personal customer information has been accessed.

Importantly, there is no evidence that this data has been shared and it does not include card payment details or account passwords, so there is no need for customers to take any action.

To give customers extra peace of mind, they will be prompted to reset their password the next time they visit or log onto their M&S account and we have shared information on how to stay safe online.

What if I want more information or have questions?

Please visit www.corporate.marksandspencer.com/cyber-update where we have more information to help you.

Cyber incident - FAQ's

Cyber incident

What does this mean for me?

You do not need to take any action, but because this has been in the news, you might receive phishing emails, calls or texts claiming to be from M&S when they are not, so be cautious.

We will never contact you and ask you to provide us with personal account information, like usernames, and we will never ask you to give us your password.

Here are some hints and tips on how to stay safe online:

  • Be careful if you receive an email or text message asking you to click on a link – check it goes to where you expect it to.

  • Use a strong and unique password for your email account and use different passwords for each account you have.

  • Always do your software updates on your phones and devices as they often contain important security updates to protect you.

  • If you need more help, there is some good advice on the government’s National Cyber Security Centre website www.ncsc.gov.uk

What do I need to do?

You do not need to take any action and, to give you extra peace of mind, next time you visit or login to your M&S.com account on our website or app, you will also be prompted to reset your password.

How will I be prompted to change my password?

When you next go to login on your M&S account, you will enter your account details and click sign in.

You will then see a message in red which asks you to click the ‘reset your password’ link.

Please click the link and you will be taken to a new webpage on M&S.com.

Once there, enter your email address and click the ‘send password reset’ link.

You will then receive an email to your registered account from Marks and Spencer Service asking you to reset your password.

Please click the ‘reset your password’ button in the email.

You will then be taken to a new webpage on M&S.com to enter your new password.

Enter and confirm your new password and then click the ‘reset my password’ button.

When this has been done, you will see a message to confirm your password has been changed.

Remember to use a strong and unique password.

Can I still use my physical and/or digital Sparks card?

You can still use your physical Sparks card. Your digital card can be accessed via your mobile phone’s digital wallet. To access your Sparks card on the M&S App you will be prompted to reset your password.

Will I still receive offers and emails from M&S?

You will continue to receive emails from M&S. At the moment, Sparks offers are paused but they will be back shortly and shared in the normal way.

Cyber incident new

Cyber incident new

Get in touch

Contact customer service

Select a topic to start a conversation.