back to article This is not just any 'cyber incident' … this is an M&S 'cyber incident'

UK high street mainstay Marks & Spencer told the London Stock Exchange this afternoon it has been managing a "cyber incident" for "the past few days." Not included in the LSE notification were details about when the incident took place or what kind of incident it is suspected to be, but an email to customers, seen by The …

  1. Ken Moorhouse Silver badge

    Click & Collect

    As in: Click a Link, Collect Malware.

    1. FirstTangoInParis Silver badge

      Re: Click & Collect

      I wonder if Discworld would have a Clack and Collect service.

  2. Anonymous Coward
    Anonymous Coward

    Customer trust is important

    "Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate."

    Or.. we don't give a damn about you suckers (customers) and will give you, maximum, 5 years credit monitoring. And if the situation changes, we will say almost nothing, as our lawyers told us to do so.

  3. abend0c4 Silver badge

    Orders being in store, but staff were unable to hand them over

    This is not a technical issue, it's an M&S lack of preparedness issue.

  4. Anonymous Coward
    Anonymous Coward

    I've heard that contactless is offline in some stores too.

    1. -

      +1 for this since yesterday, a member of staff in my local M&S was posted to advise all shoppers entering that card payments were chip and pin only.

      I bought some goods instore and the chip and pin payment was very slow to authorise, and also hasn't come off my available balance yet, or posted to my account, which probably makes me think they're being posted offline and they yanked the live data connection when they knew there was an issue. Hence the need for C&P and the fact it's very slow. probably some sort of risk management kicking in before allowing an offline auth.

      1. Anonymous Coward
        Anonymous Coward

        That’s not how card payment works in store.

        You’d want it on-line for maximum fraud protection, instead of falling back to the stand-in (Controlled by the chip on your card).

        Sounds like card traffic to the payment host and the HHT’s scanning the click and collect orders as customer received had a connection issue. Perhaps common routing via HO/DataCentre… or some planned maintenance fuck-up.

        1. Anonymous Coward
          Anonymous Coward

          I wonder if they use AWS...because AWS was wonky late last night in the London region on and off, specifically the dashboard was borked, certain things not loading, token errors etc etc...I couldn't scale RDS for a while for a particular client. Other clients were fine.

          1. Anonymous Coward
            Anonymous Coward

            It's Azure, not AWS.

            Retailers won't touch AWS.

            1. UnknownUnknown Silver badge

              That’s complete rubbish - loads of retailers are in AWS for their EPoS, Sales Audit, Merchandising, Warehouse Management, and CRM etc.

              Many as SaaS.

        2. Anonymous Coward
          Anonymous Coward

          AC poster here from the 2058 comment.

          I don't profess to have any particular expert knowledge on this, however, in my dark and distant days of working in retail, we had the old fashioned imprinters for if anything computerized/telephony went down along with boxes of carbon copy slips. There was also the option latterly, if the card supported it, to authorise a certain amount offline via C+P (card dependent obviously, some are 100% phone home/online cards so these would decline), otherwise you'd have to call the merchant acquirer.

          These days everything's shifted the other way - all online auth for pretty much all transactions.

          Fun fact; back in the day when contactless came out (and the limit was £10/20) the auth was mostly offline. When Apple/Google pay etc came into the view, it switched to being 100% online.

          Naturally with the passing of time, the processing speeds have become better and it's pretty much instantaneous with fixed always on internet being common - e.g. 3/4/5G connection or LAN/WLAN.

          However, for the smaller merchants who still used dialup at the time of this, it would always take ages with online device contactless payments

          Also, for anyone keen to know if there was any delay in being charged, no, none. The transaction posted to my statement yesterday so whatever they have as a backup does work, without unduly impacting the shopper's experience. Unless, of course, you were silly to not carry a card and rely entirely on a device payment, in which case, no Colin the Caterpillars for you.

        3. Anonymous Coward
          Anonymous Coward

          Not a planned maintenance f-up

          Infrastructure has been compromised, the impact internally is significant.

      2. Anonymous Coward
        Anonymous Coward

        They are definitely playing this down. I was in a store on Saturday when it happened, they were unable to process contactless, only chip + pin. A staff member told me that the network was down and they can’t process offline. Either they shut it off to prevent escalation or the attack brought it down.

        1. WookieBill

          Yes, I was in the Chesterfield store on Easter Saturday and they were cash and chip and pin only then. Unless you were also in the Chesterfield store it points in the direction of their payment systems also being either accessed, or at risk of being accessed.

    2. Vaughtex

      Issue with processing cards on Saturday, no wireless transactions, but chip and PIN were OK.

    3. Terry 6 Silver badge
      Flame

      Yes, and they didn't have any kind of sign up at my local to warn us. So I tried my M and S card on my phone and after some wheel spinning it rejected it and told me to try again. And it got rejected again. So I tried with the physical card and it still got rejected. So then I tried with a different card on my phone, which got rejected too.

      At which point I went back to old fashioned chip n pin. Luckily I could remember the pin for one of my cards quite easily, since I seldom need to use the pin with the others,and by then I was too flustered and cross to even think straight, let alone recall the other pins.

  5. Ramis101

    "This is not just any 'cyber incident' … this is an M&S 'cyber incident'"

    M&S Marketing are gonna be pissed at you lot for that!

    Priceless though :)

    1. Roger Kynaston

      Priceless

      You had better keep that comment handy for when a certain credit card processor gets cracked.

      “having your data sold on the dark web. Priceless. For everything else there is …"

      1. Anonymous Coward
        Anonymous Coward

        Re: Priceless

        “having your data sold on the dark web. Priceless. For everything else there is …"

        True. I heard through the news ( in the telly as you blokes say), some folks got all the encryption keys from Gemalto a few years ago.

    2. 43300

      But is it a 'generously filled' cyber incident? Or does that only apply to their sandwiches?

  6. PG2255

    According to the BBC, reports of gift cards not working too. Which is great as I have one to spend.

    1. wolfetone Silver badge

      Gift cards are a con.

      "It's your birthday. So what I did was use this £20 note that you can spend anywhere to buy you a gift card for £20 which you can only use in a very narrow selection of stores. Enjoy your day x"

      1. Anonymous Coward
        Anonymous Coward

        And which might not work when you actually try to use it!

      2. PG2255

        I get the gift card at a discounted price. Circa £44 I think gets a £50 card. So it's better than cash, saves me money.

        But I agree on the not being able to spend them.

  7. b1k3rdude

    The article title is low hanging fruit, but still amusing :-)

  8. Screwed

    Was in M&S yesterday late afternoon - and almost no yellow-labelled reductions. Whilst often of little or no relevance, it is unusual not to see quite a number of items with yellow label reductions at that time.

    I suspect that the computer systems identify which items need attention, based on stock levels and dates, then someone goes round printing the yellows, and sticking them on. But if systems not working properly, that process likely failed to work properly.

    But the one contactless payment I made (debit card via Apple wallet) worked and has appeared on my account this morning.

    1. Anonymous Coward
      Anonymous Coward

      Based on what my mum tells me with regards to yellow sticker items, it's a largely manual process. She worked at M&S for a number of years, retired some years ago now.

      The staff member picks out an item they want to buy at a staff discount...like really nice joints of meat, steaks etc, they will then strategically hide it somewhere (usually in the refrigerated warehouse) until it reaches it's yellow sticker threshold (often half price)...then you yellow sticker it and buy it at that price with your staff discount on top (20%) then freeze it.

      Is this the yellow sticker procedure you speak of?

      I've always wondered why we ate like kings when I was a kid...seems my mum was an M&S Beef Bandit.

  9. TomB

    'twas in the Dublin, Grafton St, M&S on Monday.. went to pay by tap (via my phone), and it didn't work.. assistant popped up (much like the store keeper in Mr Benn ), saying they had had problems since 3am(!) and that it was being worked on... she suggested I paid by card and I said... er now, don't carry them these days... back went the twisty salt and vinegar crisps and discounted hot cross buns!

    1. graemep

      Avoid single points of failure with payment methods. I always have cards and cash.

  10. Anonymous Coward
    Anonymous Coward

    "Importantly, our stores remain open, and our website and app are operating as normal,"

    No - it was very broken, in store, on Friday. Contactless payments weren't working at all.

  11. herman Silver badge

    Money machines

    And nobody in all of Blighty knows how to get cash at an ATM to pay for their fags and crumpets?

    1. graemep
      Coat

      Re: Money machines

      Cash is boring. It works and is predictable.

    2. Terry 6 Silver badge

      Re: Money machines

      Think about it. If you are standing in front of the pay machine with a basket full of groceries you aren't in a position to wander off and find a cash machine- assuming there is one near by. I don't think I've seen one at my M and S store, it's certainly not near the checkout. And nowhere else in that location- a small retail park- has one.

  12. Miss Config
    Meh

    See For Myself

    I came across this problem yesterday when I was buying stuff in M&S using self-service check out and had trouble getting it to accept my debit card

    ( although it did eventually ).

  13. Nano nano

    Retailer

    Sainsbury uses AWS, for one

  14. druck Silver badge

    It's been all downhill since they got rid of the tills which returned any change down a slide at the back of the till, I loved that as a kid.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like