Were you affected by the M&S data breach? You may be entitled to compensation.
KP Law is now taking on claims from individuals whose data was compromised in the M&S cyber attack. Under UK data protection laws, organisations that fail to adequately protect your information can be held legally responsible.
KP Law is a specialist data breach law firm with a proven track record in securing compensation for victims of corporate cyber negligence.
In April 2025, Marks & Spencer (M&S) was the target of a significant cyber attack. The breach disrupted online orders, impacted in-store contactless payments, and led to the unauthorised access of sensitive customer information.
While M&S has stated that no payment card details or passwords were stolen, other personal information—including names, addresses, contact details, and order history—was compromised.
The following customer data may have been affected:
M&S reported the breach to the Information Commissioner’s Office and continues to work with the National Cyber Security Centre to investigate.
Make sure your M&S and other accounts use strong, unique passwords.
Be cautious of phishing emails or suspicious texts.
Look out for any unexpected activity on your accounts.
KP Law, a leading UK data breach law firm, is investigating the M&S data breach and is preparing a group action on behalf of affected customers. If you believe your personal data was compromised, you may be entitled to compensation. KP Law has extensive experience in handling data breach cases and is committed to holding companies accountable for failing to protect customer information.
If eligible, provide your details to register your interest.
Our team will guide you through the process and represent you on a no-win, no-fee basis.
If you believe your data was compromised in the M&S breach, don’t wait. Join the group claim to seek the compensation you deserve.
While each case is judged on its own merits, there are some things we would typically look for when it comes to when claiming compensation following a data breach, cybercrime or other GDPR violation:
With stolen data, cybercriminals can make purchases using your bank and credit cards, apply for credit in your name, set up fraudulent bank accounts and access your existing online accounts.
GDPR failures, cybercrime and data breaches can have a significant impact on you, both mentally and physically. They can cause or exacerbate anxiety, stress and other psychological conditions.
See our answers to the FAQs we get asked about the M&S Data Breach.
In April 2025 M&S was victim to a cyber incident that caused severe disruption to its operations, and included a substantial amount of sensitive customer data falling into the hands of cyber criminals.
M&S confirmed that the information accessed included customers names, dates of birth and online order history. The breach did not include passwords or usable payment information.
M&S Operations Director Jayne Wall released the following message to customers in the wake of the cyber attack:
“Dear customer,
I’m Jayne Wall, and I look after Customer Service here at M&S. I am sure that you will have seen in the news that we have been dealing with a cyber incident and I wanted to write to you about what this means for you.
What has happened?
To proactively manage the incident, we immediately took steps to protect our systems and engaged leading cyber security experts. We also reported the incident to relevant government authorities and law enforcement, who we continue to work closely with.
Unfortunately, the nature of the incident means that some personal customer data has been taken, but there is no evidence that it has been shared. The personal data could include contact details, date of birth and online order history. However, importantly, the data does not include useable card or payment details, and it also does not include any account passwords. For more detail, see our FAQs.
How does this affect me and what should I do?
You do not need to take any action, but you might receive emails, calls or texts claiming to be from M&S when they are not, so do be cautious. Remember that we will never contact you and ask you to provide us with personal account information, like usernames, and we will never ask you to give us your password.“
“We sincerely apologise for any inconvenience caused to you and all of our customers.“
M&S should be in touch to notify affected individuals.
Anyone who thinks they might be involved should take immediate steps to protect themselves. Find out how to do this here.
If you receive notification that you are affected by the M&S data breach, register to receive updates on our investigation. We’ll let you know what’s happening, and if and when you can make a data breach compensation claim.
A group action claim is where a group of people – sometimes even thousands of people – have been affected by the same issue. Group action cases are also known as class actions, multi-claimant, or multi-party actions.
There are no costs to join our claim. However, if your claim is successful, you may have to pay a ‘success fee’. This fee is taken from the compensation awarded to you. At KP Law, our success fee is competitive, and we make sure you are fully informed about any potential costs before you officially join our action. If you lose, you won’t have to pay a penny.