A cybersecurity expert has issued important guidance for Marks and Spencer and Co-op shoppers in the wake of the retail duo’s recent data breaches.
M&S had to halt online orders on April 22 due to an incident, but assured customers that no immediate action was required on their part. The disruption also led to a markdown of certain food items in stores, and it was later confirmed by the company that scammers had pilfered customer personal information during the breach, potentially including contact details.
On May 2, meanwhile, a Co-op spokesperson disclosed that the company was facing “sustained malicious attempts by hackers to access” their systems. “This is a highly complex situation, which we continue to investigate in conjunction with the NCSC and the NCA,” they stated, following revelations that the same cybercriminals had taken responsibility.
In response to the trouble, TikTok’s MyCyberTips has posted a video detailing steps consumers should take if they suspect their data may have been compromised – and what actions to take thereafter. “If you’ve been receiving a lot of spam emails recently, you can see if your email address was involved in the M&S or Co-op data breach,” he began in a video.
He went on to instruct viewers to check HaveIBeenPwned.com, a website where one can input their email address to check if it has been compromised. “If you have been hacked, hold down on the [spam] email [on your phone] and do ‘Block Sender’, and this will stop the person sending emails to you,” he recommended.
MyCyberTips continued: “Also, if your data has been stolen, make sure you change your password and set up multifactor authentication. You can even go one step further and set up spam filtering links on your email.”
To tackle unwanted emails, meanwhile, they suggest utilising the ‘Blocking and Filtering’ feature to automatically relegate future spam to the Spam folder by entering the sender’s email address.
And in a final piece of guidance, MyCyberTips warned: “The final thing is do not click on ‘Unsubscribe’ links with these emails. What it shows them is your email address is active and so they’re likely to spam you even more because they know that this is a legitimate email address.”
What to do if your information is stolen
- Change your passwords immediately
- Set up two-factor authentication when possible
- Be mindful of spam emails that come into your inbox
- Introduce spam and scam filters where needed
M&S Chief Executive Stuart Machin recently addressed his company’s incident, reporting: “As we continue to manage the current cyber incident, we have written to customers today to let them know that unfortunately, some personal customer information has been taken. Importantly, there is no evidence that the information has been shared and it does not include useable card or payment details, or account passwords, so there is no need for customers to take any action.”
He also reassured: “To give customers extra peace of mind, they will be prompted to reset their password the next time they visit or log on to their MandS account and we have shared information on how to stay safe online.
“Everyone at M&S is working around the clock to get things back to normal for our customers as quickly as possible, and we are very sorry for any inconvenience they have experienced. Our stores remain open as they have throughout. Thank you for shopping with us and for your continued support, we are incredibly grateful.”
Co-op released their own update on the situation in a press release last week, which stated: “Following the malicious third-party cyber-attack, we took early and decisive action to restrict access to our systems in order to protect our Co-op. We are now in the recovery phase and are taking steps to bring our systems gradually back online in a safe and controlled manner.”
In a further update on May 14th, Co-op shared some positive news: “Following the malicious third-party cyber-attack, we took early and decisive action to restrict access to our systems in order to protect our Co-op.”
It added: “We are now in the recovery phase and are taking steps to bring our systems gradually back online in a safe and controlled manner.
“In our Food business:
“There will be improved stock availability in our Food stores and online from this weekend and we are working closely with our suppliers to restock our stores.
“Our stock ordering system is now fully online, and we have switched all our orders back to the normal supply processes and systems.
“All forms of payments including contactless, and chip and pin are working across our entire store estate.
“We’d like to thank all our colleagues, members, partners and suppliers for their support so far. We will provide further updates to our members as we continue to make progress from this cyber-attack.”


