M&S data stolen in Epsilon breach
The Epsilon breach may have mainly affected US companies, but Marks & Spencer customers have been hit too.


Marks & Spencer has warned customers their email addresses have been leaked, thanks to a huge breach at US marketing firm Epsilon.
The retail giant emailed customers saying they could expect more spam messages, after addresses were leaked after the hack on Epsilon on 30 March.
Customer email lists from a wide range of major corporations were taken, including hotel chains Marriot and Hilton. It was thought most affected businesses were US based.
M&S confirmed no other personal information, outside names and email addresses, were stolen.
"We have been informed by Epsilon, a company we use to send emails to our customers, that some M&S customer email addresses have been accessed without authorisation," the firm said in its email.
Although spam could be an issue for customers hit by the breach, targeted malware attacks are another worry.
"Today, data theft accounts for 33 per cent of all attacks and although an increase in spam is an obvious outcome, not so obvious is the increased risk of targeted malware attacks seeking to infiltrate company systems," said Paul Davis, director of European operations at FireEye.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"The loss of personal data is the initial step in a series of potential exploits from mass spam through to advanced targeted malware, which seeks to establish a beachhead within corporate systems for subsequent exploit and data exfiltration."
Frank Coggrave, Guidance Software's general manager for EMEA, said the Epsilon hack highlighted a wider trend in the industry.
"The significant knock-on effect to big name Epsilon customers, including Marks & Spencer and hotel chains Mariott and Hilton, highlights that no one is safe from these increasingly sophisticated and targeted attacks," Coggrave said.
"Since attacks consistently break through even the toughest of security systems, organisations need to focus on deploying incident response plans to mitigate the effects."
A number of high profile attacks have hit major corporations over the past month, including an Advanced Persistent Threat strike on security firm RSA.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Tories fined £10,000 after sending unwanted campaign emails
News ICO said the breach of data protection laws was “serious”
By Rene Millman
-
Mine: The startup that can track down your data
Case Studies The search for your digital footprint starts with your email inbox and some machine learning
By Bobby Hellard
-
Nine top GDPR tips for email marketing strategies
In-depth It's not all doom and gloom – here's how you can make GDPR work for you
By Zach Cooper
-
Why GDPR creates a "vicious circle" for marketers
News Customers will control the forthcoming trust economy, predicts Aprimo
By Rene Millman
-
Forget about GDPR fines, says Dotmailer
News Email marketing firm says failing customers should be a bigger worry than official penalties
By Adam Shepherd
-
Google dumps disaster recovery product amidst clean out
News The internet giant dumps the Google Message Continuity product to focus on its Apps lineup.
By Tom Brewster