UK Arrests Four in Major Retail Cyber Attacks on M&S, Co-op, Harrods

UK Police Arrest Four in Major Retail Cyber Attacks Linked to Scattered Spider, Losses Near $592 Million

  • Authorities arrested four people in the U.K. for cyber attacks on major retailers.
  • The attacks affected Marks & Spencer, Co-op, and Harrods, with losses estimated up to $592 million.
  • Suspects are linked to the organized cybercrime group known as Scattered Spider.
  • Attackers used advanced social engineering and Ransomware tactics to breach organizations.
  • Experts advise organizations to strengthen verification procedures and adopt robust security measures to protect against similar threats.

On Thursday, the U.K. National Crime Agency (NCA) arrested four individuals in connection with cyber attacks that targeted major retailers Marks & Spencer, Co-op, and Harrods. The suspects, aged 17 to 20, were apprehended at their residences in the West Midlands and London. Authorities seized electronic devices as evidence.

- Advertisement -

Officials charged the suspects with offenses including computer misuse, blackmail, money laundering, and involvement in an organized crime group. According to the NCA, these arrests followed a focused investigation into cyber incidents that caused significant disruptions and losses.

“Since these attacks took place, specialist NCA cybercrime investigators have been working at pace and the investigation remains one of the Agency’s highest priorities,” said Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, in an official statement. “Today’s arrests are a significant step in that investigation but our work continues, alongside partners in the U.K. and overseas, to ensure those responsible are identified and brought to justice.”

According to the Cyber Monitoring Centre, the cyber attacks against Marks & Spencer and Co-op in April 2025 were labeled a “single combined cyber event,” causing losses estimated between $363 million and $592 million. The NCA has not confirmed the exact group behind the attacks but reports indicate the involvement of the decentralized crime crew known as Scattered Spider. This group uses tactics like social engineering—tricking people into giving up confidential information—and ransomware, which is malicious software that locks data until a ransom is paid.

During a recent U.K. Parliament committee hearing, Marks & Spencer stated that the attack on its network was ransomware-based and connected to the DragonForce ransomware group, who reportedly worked with other affiliated actors.

- Advertisement -

Security experts highlight that Scattered Spider mostly consists of young, native English speakers who use fake calls to IT help desks to gain access. The group is reportedly part of a wider collective called The Com, which carries out crimes like phishing, SIM swapping, extortion, and social engineering across different industries.

Google-owned Mandiant explained that Scattered Spider tends to focus on one industry at a time, using phishing websites that mimic real company logins to steal user credentials. “Organizations can take proactive steps like training their help desk staff to enforce robust identity verification processes and deploying phishing-resistant multi-factor authentication to defend against these intrusions,” said Charles Carmakal, CTO at Mandiant Consulting. Carmakal also described the arrests as “a significant win” in the fight against the e-crime syndicate, emphasizing the importance of international cooperation to curb such threats.

Previous actions against this group have led to temporary drops in activity, according to experts, offering organizations a chance to bolster their defenses before further attacks occur.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Coinbase Launches AI Agent Wallets

Coinbase programmers revealed on Wednesday that the company is launching crypto wallet infrastructure to...

BlackRock Sees Asian Crypto ETF Boom Unleashing Trillions

A 1% crypto allocation from Asia's $108 trillion household wealth could spark nearly $2...

800 held as Cambodia busts Xinli Casino scam center

Cambodian police detained 800 people of various nationalities during a raid on the 18th...

Coinbase Stock Down 34% in 2026 as Crypto Market Sinks

Coinbase stock (COIN) has plunged 34% year-to-date and 8% in a single day ahead...

Patch Tuesday: Microsoft Fixes 59 Flaws, 6 Zero-Days

Major software vendors, including Microsoft, Adobe, and SAP, released critical security patches on February...

Must Read

This is How to Buy and Sell Bitcoin

Now more than ever, there are a variety of ways to enter and exit the crypto market. While this is good, the availability of...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!