Share.

    23 commenti

    1. AirResistence on

      This whole thing with M&S is a huge reminder that companies should not be recording any data on customers unless its needed like a bank.

    2. bobblebob100 on

      Got to love how companies dont encrypt personal information then tell you that security is their no1 priority

    3. callmejellydog on

      You probably have aliases and postboxes these days but why is this allowed?

      “Someone stole your data lol oops”

      And that’s it? Where’s the compensation to the individual? Will top management be heavily disciplined and receive the order to return stock or have wages arrested?

      Nah. Keep it going lads. Why take information security seriously when there is no punishment for not?

    4. Virtual-_-Insanity on

      Just the details needed for identity fraud then

      Also can’t wait for the eventual text/call/whatsapp and email phishing. 

    5. RaymondBumcheese on

      In the immediate aftermath, the most important part is the scam warning. If you were a customer, be incredibly vigilant for people claiming to be from M&S or your bank.

    6. BritanniaGlory on

      Happens in every attack, don’t worry, the customer data isn’t valuable.

    7. berfunckle_777 on

      Lots of weasel wording in this statement regarding the possibility that payment card data was also compromised albeit likely redacted or encrypted. Nevertheless it’s shocking that they are potentially obfuscating the full extent of the breach to protect their reputation and share price.

    8. Ekokilla on

      This should be a wake up call to any governments trying to erode e2e encryption, just how easily an encrypted network that isn’t e2e is attacked

    9. Apprehensive_Bus_543 on

      Surely my personal data has now been stolen so many times it’s worthless.

    10. Tricky_Peace on

      I mean, I don’t think this should be a major surprise. M&S will have a lot of customer details, and would be a major target of a cyber attack

    11. shxwcr0ss on

      We need a watchdog like HSE to ensure cybersecurity and infrastructure is being maintained and taken seriously. Just like GDPR.

      If huge companies can use outdated systems and refuse to spend on digital infrastructure, then why should the smaller ones strapped for cash bother?

      How do we trust ANY company with our information after this disaster? You can’t trust brand name clearly…

      It’s a joke that our details have likely been leaked in this, and we just get a “oh sorry about that”…

    12. PyroRampage on

      The ICO are doing… uh nothing as usual. Maybe a 10k fine lol.

    13. SmashedWorm64 on

      I think this also reflects badly on how much data is collected for no reason.

      I understand names and addresses for home deliveries and ensuring things get to where they are going… but shops in general nowadays seem to want way too much info just go pass the register.

    14. sharkmaninjamaica on

      This has made me hugely rethink loyalty cards and m and s in general cos I shop there a lot.

      I signed up to the sparks card about three days before this attack funnily enough. My first thoughts were how shit it was. When I swipe a Morrisons more card, a nectar etc I always get a handful of discounts every single shop, I don’t even need to deliberately look for them. But now, after a couple weeks with a sparks, I’ve never got a single offer to date.

      They also don’t collect points.

      And then, few days ago I start getting tons of junk emails (tho they’re all getting past the outlook filters) claiming they’re from m and s (very convincingly btw) telling me about welcome gifts etc and offers and I even almost fell for one (it came thru right after I signed up!).

      I now overwhelmingly feel like I have got a ton of negatives for not a single positive with this card. Even without the leak and spam I been getting I wouldn’t have a single positive to speak of – I gave them all my data for what exactly?

      Nah I’m totally done with this company – won’t shop there again

    15. GhostRiders on

      Just to note, even Rolls Royce use TCS, in fact they use them to such an extent that they have lost considerable knowledge and are completely reliant on them.

    16. ollielite on

      Wouldn’t saved bank card details be stored with m&s for deliveries?

    17. DUTTYSTINKINGPEE on

      this is why they were out of the beef crisps according to my sister

    18. NateShaw92 on

      Alright folks place yer bets on who’s next we have Lidl at 3/1, Tesco 3/1, Nandos Evens.

    19. Vivid-Blacksmith-122 on

      The inability of consumer stores to protect customer data is why I have stopped having store accounts. When PC World was hacked I received very specific phishing emails for several years which included my phone number, email address, physical address etc. The emails were like “to arrange delivery of your parcel” and looked real. If someone had been expecting a delivery it would have been SO easy to fall for it.

      If I can’t order from a company without having an account then I don’t buy from that company. They do not “need” to hold so much information about their customers.

    20. hatnscarf on

      Dear Hatnscarf

      I’m Jayne Wall, and I look after Customer Service here at M&S. I am sure that you will have seen in the news that we have been dealing with a cyber incident and I wanted to write to you about what this means for you.

      What has happened?

      To proactively manage the incident, we immediately took steps to protect our systems and engaged leading cyber security experts. We also reported the incident to relevant government authorities and law enforcement, who we continue to work closely with.

      Unfortunately, the nature of the incident means that some personal customer data has been taken, but there is no evidence that it has been shared. The personal data could include contact details, date of birth and online order history. However, importantly, the data does not include useable card or payment details, and it also does not include any account passwords. For more detail, see our FAQs.

      How does this affect me and what should I do?

      You do not need to take any action, but you might receive emails, calls or texts claiming to be from M&S when they are not, so do be cautious. Remember that we will never contact you and ask you to provide us with personal account information, like usernames, and we will never ask you to give us your password.

      For more information, FAQs and hints and tips on how to stay safe online visit [corporate.marksandspencer.com/cyber-update](http://corporate.marksandspencer.com/cyber-update)

      To give you extra peace of mind, next time you visit or login to your M&S.com account on our website or app, you will also be prompted to reset your password.

      We sincerely apologise for any inconvenience caused to you and all of our customers.

      Thank you so much for shopping with us and for your support, we never take it for granted.

      Jayne Wall
      Operations Director

    21. bobblebob100 on

      In a age where people want all their personal information safe, its weird to think we used to have public phone books in every household with names, addresses and phone numbers stored

    22. Bubbly_Celery4034 on

      This not just a massive PR disaster, it’s a M&S PR disaster.

    Leave A Reply