In May 2025, Marks & Spencer (M&S) joined the growing list of high-profile names impacted by cybercrime. The breach — part of a wider attack on delivery partner Snappy Shopper — has exposed personal data of thousands of customers, triggering a wave of phishing attempts, scam messages, and public concern.
As a business, while this breach may not directly impact your operations, it highlights a crucial point: cyber threats don’t stop at the office door. They follow your employees home — and what affects them personally can create ripple effects in the workplace.
This article is designed as a shareable resource you can pass to your team, helping them understand the risks, avoid scams, and stay cyber safe in both their personal and professional lives.
The breach originated from Snappy Shopper, a third-party delivery partner used by M&S and Co-op. The compromised data includes:
With this data now in the hands of criminals, a wave of scams has already begun targeting affected customers, including phishing emails, fake delivery texts, and scam calls posing as support representatives.
For cybercriminals, data like this is gold. Even when it doesn’t include passwords or full card details, it allows them to:
This is what makes the human element the weakest link in cybersecurity — and why attacks like this can easily jump from personal inboxes to workplace threats.
As attackers leverage the exposed data to reach out directly to M&S customers, it’s vital to remind your employees (and their families) how to stay safe. Encourage your team to:
These habits won’t just protect your team in their personal lives — they help build cyber awareness that carries over into the workplace.
While this breach didn’t happen in your organisation, it still poses an indirect risk. Human-targeted attacks like phishing are the top cause of workplace breaches, and attackers are increasingly blurring the lines between personal and professional exploitation.
When your team learns how to spot a scam at home, they’re more likely to do the same at work.
usecure helps businesses like yours reduce human cyber risk with automated training, phishing simulations, and user risk monitoring. But we also believe in empowering people outside of work.
Share this blog with your team as a simple way to help them stay secure in their personal lives — and build safer habits that benefit your business too.