logo
M&S hackers 'got into system due to colossal blunder - and sat in system for 52 hours before alarm was raised'

M&S hackers 'got into system due to colossal blunder - and sat in system for 52 hours before alarm was raised'

Daily Mail​17-05-2025

Hackers went undetected in Marks and Spencer 's systems for up to 52 hours before the alarm was raised in what insiders are describing as a 'colossal mistake'.
Believed to have been from the Scattered Spider group, the attackers got into the retailer's IT systems via a contractor.
The hackers were then able to work undetected in the systems for just over two days before finally being uncovered, a source said.
Once discovered, emergency response teams battled tirelessly to protect the beloved British store, frequented by up to 9.4million active customers, throughout a five-day 'attack phase'.
'What went wrong was human error. Human error is a polite word for somebody making a colossal mistake,' a source told The Times.
Three weeks on and teams are still working around the clock to get the online shop back up and running.
'There's people who haven't slept for three nights,' an insider said. 'Getting back to where we really want to be is going to be weeks, not days, but we'll have an online presence quite soon.'
In a statement to MailOnline, a spokesperson for M&S said: 'We are working closely with government and law enforcement agencies and as you would expect we cannot share any detail or comment on speculation around the incident itself, since we first reported it, and we have been advised not to.'
It is understood that the M&S website could take weeks to go back online while stock availability across stores is expected to return to normal next week.
Since the attack, the British high street retailer is understood to have hemorrhaged £1billion of value on the stock exchange.
The retailer also admitted criminals have taken information including 'masked' payment card details used for online purchases - typically the last four digits of a card.
But M&S chief executive Stuart Machin clarified that although the hackers had taken personal data, this 'does not include useable card of payment details'.
While it is unknown how many shoppers have been affected by the attack, several customers have reported an 'exponential' increase in the number of scam messages and emails received, pretending to be M&S.
In a letter to customers, M&S operations director Jayne Wall urged people to be cautious and avoid giving out any personal details to unknown callers.
She wrote: 'Unfortunately, the nature of the incident means that some personal customer data has been taken, but there is no evidence that it has been shared.
'The personal data could include contact details, date of birth and online order history. However, importantly, the data does not include useable card or payment details, and it also does not include any account passwords.'
Ms Wall added: 'You do not need to take any action, but you might receive emails, calls or texts claiming to be from M&S when they are not, so do be cautious.
'Remember that we will never contact you and ask you to provide us with personal account information, like usernames, and we will never ask you to give us your password.'
While customer data has not yet appeared on leak sites, experts have not ruled out that it could be a possibility, with Rafe Pilling, director of intelligence at Sophos, an IT security company stressing that hackers could be 'leveraging data' from the breach.
Comprising of predominantly British and American online hackers, the Scattered Spider group are believed to have been responsible due to the attack's pattern, alongside their use of DragonForce software to help the hackers break into the shop's system.
The devastating attack comes as M&S await their annual financial results announcement on May 21.
A world away from the overwhelming success of their previous financial year, where they made a profit of £840million, M&S chief executive Stuart Machin, alongside chairman Archie Norman, are both set to face an abundance of questions about the company's preparation for the attack.
Indeed, Dan Coatsworth, investment analyst at AJ Bell, warned that 2025 'is going down in history as one of the retailer's worst ever years'.
Speaking to MailOnline, he added: 'M&S has a duty to inform customers as soon as possible if their personal information has been illegally accessed, so it's worrying that the retailer took so long to go public.'
While stock is expected to return to Co-op stores this weekend, it is understood that it quickly pulled the plug on its computer system not long after receiving advice from M&S
While M&S shareholder Danny Wallace told The Times he felt 'disappointed' for the two businessmen, he accepted that 'somebody has to have the blame'.
Meanwhile, Alan Woodward, University of Surrey cyber security professor, said that he believed the fact the store has still failed to reinstate their online sales, with customers having been unable to take any orders through the website or app since April 25, 'suggests they were a little less prepared than maybe they should have been'.
Describing the attack as 'embarrassing, retail expert Richard Hyman believed that the retailer, which first opened for business in 1884, would no doubt 'survive' the financial implications of the attack, alongside any damage caused to its reputation.
On May 2, the Information Commissioner's Office said it was also looking into the attack, as well as a similar major incident involving M&S' competitor, the Co-op.
The business was forced to issue an apology to customers after hackers accessed and extracted members' personal data, such as names and contact details, with it continuing to suffer availability problems as a result of the attack.
While stock is expected to return to Co-op stores this weekend, it is understood that it quickly pulled the plug on its computer system not long after receiving advice from M&S.
The National Crime Agency said: 'We are working closely with our law enforcement partners to investigate. We are considering the incidents individually. However, we are mindful they may be linked and therefore this will remain under review.'

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

'Stasi-like' Labour council fines stunned resident £1,000 for putting his bins out a few hours early
'Stasi-like' Labour council fines stunned resident £1,000 for putting his bins out a few hours early

Daily Mail​

time22 minutes ago

  • Daily Mail​

'Stasi-like' Labour council fines stunned resident £1,000 for putting his bins out a few hours early

A Labour council who fined a resident £1,000 for putting his bins out a few hours early has been accused of acting like the 'Stasi'. Clyde Strachan, 37, decided to help refuse collectors by placing his rubbish outside his West Kensington home shortly before midday in May. He then went away for a week and when he returned was faced with an 'environmental enforcement notice', which demanded he make contact with Hammersmith and Fulham Council. The engineer then received an £1,000 fixed penalty notice, stating: 'There was one large box, six bags of waste, and one food bin deposited on the pavement and left. 'It isn't collection day so it shouldn't be there. 'There is no formal right to appeal, however the council will accept representations from you within seven days.' Mr Strachan told The Telegraph: 'I spoke on the phone to one of the council officers and said I was willing to receive a warning but felt a £1,000 fine was excessive. 'I said I had put the bins out early as I was not available the next day. It was an honest mistake. I didn't feel as though I needed to grovel, but it felt like that was what he was after.' The fine has sparked criticism towards the council's 'law enforcement team'. Likening it to the 'Stasi' - the secret police who helped maintain communist power in East Germany through spying and violence. Robert Jenrick, the shadow justice secretary said: 'Instead of cracking down on genuine anti-social behaviour, the state tries to reassert itself by punishing well-meaning people for tiny infringements. 'This huge fine for putting the bins out a few hours early veers into Stasi-like control of people's lives. This man was clearly doing the right thing in the circumstances.' The fine has since been retracted. A council spokesman said: 'Mr Strachan asked for a review of the FPN on May 28 when he let us know that the reason he put the rubbish out early was that he had been going on holiday the following day. 'The following day, the council froze the fine pending a review. 'We have since cancelled the FPN as we agree that Mr Strachan made an honest mistake and is not a persistent fly-tipper.'

Woman in her 20s ‘raped' yards from iconic seaside town pier as man, 45, is arrested
Woman in her 20s ‘raped' yards from iconic seaside town pier as man, 45, is arrested

The Sun

time26 minutes ago

  • The Sun

Woman in her 20s ‘raped' yards from iconic seaside town pier as man, 45, is arrested

POLICE are investigating a report of rape that took place yards from an iconic seaside town pier. A man, 45, has been arrested and police are appealing for witnesses and anyone with information to come forward. 1 A member of the public reported the incident in Manchester Street, Brighton, at about 11am on Saturday, June 7. The victim, a woman in her 20s, cannot be identified for legal reasons and is receiving support from specially-trained officers. Officers attended the scene, and a 45-year-old man was arrested on suspicion of rape. He remains in custody at this time. Detective Inspector Kirstie Neal of Sussex Police said: 'Detectives are investigating this incident, and we are appealing for all witnesses and anyone with information who has not already come forward to do so. 'Anyone in the area with relevant CCTV, mobile phone, doorbell or dashcam footage is also asked to come forward. 'It took place in a busy area just off St James's Street, and there will be an increased police presence in the area while this matter is investigated.'

What is a part and part mortgage?
What is a part and part mortgage?

Telegraph

time37 minutes ago

  • Telegraph

What is a part and part mortgage?

If you're undertaking the often daunting task of choosing a mortgage, not only will you need to look at the type of mortgage you want – fixed or tracker – you'll need to select the length of the deal you want, as well as the repayment option that suits you. Usually, you'll need to choose between repayment – where you'll pay off both the loan interest and capital amount you've borrowed – or interest-only, where you just pay the interest. But there's a lesser-known hybrid version that could suit you, too. This is often referred to as a 'part and part' mortgage. Here, Telegraph Money explains how these deals work and the pros and cons you should consider before taking one on. What is a part and part mortgage? How does a part and part mortgage work? Advantages of this mortgage deal Disadvantages of part and part mortgage s Part and part mortgage FAQs What is a part and part mortgage? A part and part mortgage – also known as 'part interest-only' – is a combination of repayment and interest-only mortgages. Since part of your home loan will be on interest-only, there will still be an outstanding amount to be repaid in full at the end of your mortgage term. Nicholas Mendes, from broker John Charcol, said: 'Used well, part and part can strike a balance between reducing monthly payments and maintaining some capital repayment. 'But there's a clear trade-off. If the repayment plan doesn't materialise, you're left with a significant balance to clear at the end of the term.' How does a part and part mortgage work? As an example, you could get a part and part mortgage for £350,000, with £200,000 on a repayment basis, while the remaining £150,000 is interest-only. This kind of set-up would make for smaller monthly payments, since you're essentially removing the capital repayment element on a portion of your borrowing. However, at the end of the term, you'll need to pay off the full interest-only amount – in this case, £150,000. To be eligible for even a small element of interest-only, you will need to demonstrate that you have a repayment strategy in place – that is, evidence that you have a means of repaying the debt when the time comes. This could be money saved in a stocks and shares Isa, an endowment policy, the sale of a second home or a pension fund. Lenders will usually have a limit on how much of the mortgage can be allocated as interest-only, and this could also vary depending on your circumstances. Income thresholds are often higher, said Mr Mendes, usually starting from £50,000 to £100,000 for single applicants, and most lenders will cap the amount you can borrow at 50 to 75pc ​for that portion of the mortgage. To reduce the interest-only lump sum that's due when the mortgage term ends, you might be able to apply to increase the portion of your mortgage on repayment in the future to continue chipping away at the original amount you borrowed. Advantages of this mortgage type Your monthly payments will be lower than with a repayment mortgage. These mortgages can be helpful if you're on a strict budget, when property prices are high, or interest rates are rising. A relatively small saving of even a couple of hundred pounds per month could make all the difference to securing the home you want. If you already have an interest-only mortgage, going for 'part and part' can help you start chipping away at the capital, without the shock of going all in. Part and part mortgages are flexible, which means that you can make overpayments if you can afford to. However, this will only be applied to the repayment portion of the mortgage, so the limits before early repayment charges (ERCs) kick in will be lower. It's best to check these details with your lender before you make any overpayments. Disadvantages of part and part mortgages You will pay more interest overall compared to a repayment mortgage. It could take longer to pay off your mortgage. Mortgage lenders may have limits on how much of your mortgage can be interest-only. You will need to have a means of paying off the chunk of interest-only borrowing when the term ends. If you can't, you'll be at risk of losing your home. Part and part mortgage FAQs Can I use a part-and-part mortgage on any type of mortgage deal? A part and part repayment mortgage is available on a fixed rate, discounted rate or tracker loan. The key is whether the lender will approve it according to your affordability and how you intend to repay the remaining debt at the end. Which lenders offer part and part mortgages? Not all lenders offer this choice and have repayment or interest-only as the only options. Halifax, HSBC, Leeds Building Society and Skipton Building Society are among the lenders that do offer part and part options. It's worth checking before you apply if it's offered. How do I get a part and part mortgage? You'll need to apply for your home loan in the same way as any other and pass affordability and credit checks. Since part and part repayments aren't available from all lenders, it might be more straightforward to enlist the help of a mortgage adviser who can help find a home loan to suit you. Beforehand, you could speak to your existing lender to see what they can offer. Can I switch to a repayment mortgage later? When you come to remortgage, you may be able to switch to a full repayment mortgage if you want to. However, note that this will usually mean an increase to your monthly payments, and your lender will want to make sure this is affordable for you. How do I know if a part and part mortgage is right for me? A part and part mortgage might be useful if you're paying interest-only at the moment and want to make a move towards repayment – but not going the whole way. It can help ease into higher repayments. It could also help if you're soon to receive a windfall – perhaps inheritance or a big bonus from work, and need to keep repayments lower until the money lands. If in doubt, a mortgage adviser will be able to help find the best mortgage for you.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store