HomeSecurityPeople arrested for cyberattacks on Marks & Spencer, Co-op, Harrods

People arrested over cyberattacks on Marks & Spencer, Co-op, Harrods

The UK's National Crime Agency (NCA) has arrested four young men suspected of involvement in cyberattacks that hit major retail chains such as Marks & Spencer , Co-op and Harrods .

cyberattacks on Marks & Spencer, Co-op, Harrods

The NCA said in a statement that the arrested men – two 19-year-olds, a 17-year-old and a 20-year-old – face charges of breaching the Computer Misuse Act, extortion, money laundering and participating in organised cybercrime. Authorities made the arrests in the West Midlands and London, and seized electronic devices for further digital analysis.

See also: Ingram Micro: Restores its systems after ransomware attack

The NCA's deputy director and head of the National Cybercrime Unit, Paul Foster, described the investigation into the above cyberattacks as "high priority" and said the arrests were an important step in identifying and punishing those responsible.

Economic impact of hundreds of millions of pounds

The cyberattacks on Marks & Spencer and Co-op, which took place in April 2025, were assessed by the Cyber ​​Monitoring Centre (CMC) as a single, coordinated incident, with an estimated economic impact of between £270m and £440m. The attacks appear to have originated from the notorious cybercrime group Scattered Spider, known for its sophisticated social engineering and ransomware techniques.

Who are the Scattered Spiders?

Scattered Spider is not a typical criminal group, but a decentralized, English-speaking network of young hackers, known for its effectiveness in deceiving employees through fake phone calls (impersonating staff members). Experts point out that their strength comes not from revolutionary tools, but from their persistence and social engineering skills .

The group is an offshoot of the broader collective The Com, which is allegedly involved in a multitude of criminal activities: from phishing and SIM swapping, to swatting, extortion and even darker crimes, such as kidnappings and murders.

See also: Possible hacker contacted Qantas after attack

People arrested over cyberattacks on Marks & Spencer, Co-op, Harrods
People arrested over cyberattacks on Marks & Spencer, Co-op, Harrods

Targeting strategy and methods of action

According to analyses by Halcyon and Mandiant (a Google subsidiary), Scattered Spider operates methodically, regularly changing its operational targets by industry and region, each time focusing on where it sees increased potential for profit. Among its methods stands out the creation of fake login pages that mimic official company portals in order to steal employee credentials.

Mandiant recommends that organizations strengthen their security measures with robust multi-factor authentication (MFA) and training IT staff in identifying social engineering.

Ransomware is evolving – targeting the most vulnerable: people

The Scattered Spider cyberattacks on Marks & Spencer, Co-op and Harrods reveal a deeper shift in the cyberthreat landscape: security technology may be evolving, but human error remains the weakest link. Modern attacks are no longer limited to firewall-breaking techniques – instead, they aim to trick employees and administrators through realistic and personalized social engineering attacks.

See also: IdeaLab confirms data theft in ransomware attack

Governments and companies should adopt a “Zero Trust”, where no access is taken for granted and every action requires confirmation. The future of cybersecurity now lies in education, prevention and intelligent threat detection – not just software hardening.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS