Four Arrested in £440M Cyber Attack on Major UK Retailers

Four Arrested in £440M Cyber Attack on Major UK Retailers
In a significant development for cybersecurity in the retail sector, four individuals have been arrested in connection with a massive cyber attack that targeted major UK retailers Marks & Spencer, Co-op, and Harrods. The attacks, which occurred in April 2025, caused an estimated £440 million in damages and severely disrupted operations.

Q1 2025 Threat Landscape Report Reveals 75% Surge in Retail Ransomware
The Arrests and Investigation
The UK's National Crime Agency (NCA) announced the arrests, which took place across the West Midlands, Staffordshire, and London. The individuals arrested include two 19-year-old men, a 17-year-old male, and a 20-year-old woman. The arrests followed an extensive investigation into the cyber attacks that crippled the retailers' systems earlier this year.
Impact on Marks & Spencer, Co-op, and Harrods
The cyber attacks had a significant impact on the targeted retailers. Marks & Spencer (M&S) was particularly hard hit, with its website being taken offline following a ransomware attack. This disruption led to the removal of over 230 job vacancies and hampered in-store operations due to the failure of loyalty systems, handheld scanners, and internal apps. While details on the specific impact on Co-op and Harrods are still emerging, reports indicate that they also experienced significant operational disruptions.
Scattered Spider Connection
Security experts believe the suspects may be connected to the infamous hacking collective known as Scattered Spider. This group has been linked to previous high-profile cyber attacks, including those against gaming giants MGM and Caesars. Scattered Spider is known for its sophisticated and human-centric hacking techniques, making them a formidable threat to businesses. The DragonForce encryptor was reportedly used in the M&S attack, further linking it to this group.
The Growing Threat of Ransomware
This incident highlights the growing threat of ransomware attacks, particularly in the retail sector. Ransomware attacks involve hackers encrypting a company's data and demanding a ransom payment in exchange for the decryption key. These attacks can cause significant financial losses, reputational damage, and operational disruptions.
- Manufacturing, information technology and healthcare are top targets of cybercriminals.
- Ransomware attacks on the oil and gas industry increased dramatically between April 2024 and April 2025, spiking 935%.
Protecting Your Business and Yourself
To protect themselves from cyber attacks, businesses and individuals should take the following steps:
- Implement strong passwords and multi-factor authentication.
- Keep software and systems up to date with the latest security patches.
- Educate employees about phishing scams and other social engineering tactics.
- Invest in robust cybersecurity solutions, such as firewalls and intrusion detection systems.
- Regularly back up important data to a secure, offsite location.
- Develop a comprehensive incident response plan to address cyber attacks.
Key Takeaways
The cyber attacks on Marks & Spencer, Co-op, and Harrods serve as a stark reminder of the importance of cybersecurity in today's digital age. Businesses of all sizes must prioritize cybersecurity to protect themselves from the growing threat of cyber attacks. By taking proactive steps to improve their security posture, businesses can reduce their risk of becoming the next victim.
References
- Google News: Four arrested for cyberattacks on M&S, Co-op, and Harrods
- LinkedIn: NCA Arrest 4 Suspects For The Devastating Cyberattacks On...
- The Guardian: Four arrested over cyber-attacks on M&S, Co-op and Harrods
- Dark Reading: 4 Arrested in UK Over M&S, Co-op, Harrods Hacks
- Medium: Four Arrested in £440M Ransomware Hit on Marks & Spencer ...
- upday News: Cyber-attacks : 4 arrested over M&S, Co-op, Harrods ...
- LinkedIn: Cyberattacks on M&S, Co-op, and Harrods Spark Fears Over...
- Conosco: Harrods , M&S, Co - Op : cyber attacks signal urgent need for action
- FoodNavigator: Marks and Spencer , Co - op and Harrods cyber attacks
- BBC: Harrods latest retailer to be hit by cyber attack
- Reuters: UK police arrest four over cyberattacks on M&S, Co - op and Harrods
- Tech.co: 1.4 Million People Hit in Huge Allianz Life Cyberattack - Tech.co
- LinkedIn: Ransomware in Retail: M&S, Co - op & Harrods Hit in Coordinated...
- Cybernews: Who is behind the Marks & Spencer and Harrods hacks?
- Dark Reading: 4 Arrested in UK Over M&S, Co - op , Harrods Hacks
- Infosecurity Magazine: Inside DragonForce, the Group Tied to M&S, Co - op and Harrods Hacks
- The Hacker News: Four Arrested in £440M Cyber Attack on Marks & Spencer , Co - op ...
- Feature Image: Q1 2025 Threat Landscape Report Reveals 75% Surge in Retail Ransomware