The retail sector is being targeted by ransomware attacks , with incidents increasing by 58% in the second quarter of 2025 (compared to the previous one). According to the latest report from BlackFog , the UK appears to be playing a leading role in the attacks, with leading retailers such as Marks & Spencer (M&S), The Co-op and Harrods at the centre of the digital war.

British companies in the spotlight – Attack by the Scattered Spider group
The attacks on the above companies are linked to the Scattered Spider group and included the development of ransomware. The attacks led to severe operational disruptions and significant financial losses. On July 10, British authorities arrested four suspects for participating in this action, intensifying the effort to limit cyber threats in the country.
In addition to British businesses, global brands such as Dior, Adidas, Louis Vuitton, Cartier and Victoria's Secret have also suffered cyberattacks, confirming that the retail sector has become a top target for cybercriminals.
See also: Authorities dismantle Diskstation ransomware gang
Why is the retail sector being targeted?
According to BlackFog, retailers are of particular interest to hackers due to the nature of their operations: they have complex supply chains, sensitive customer data , and payment data. Even a temporary disruption to a retailer’s operations can result in huge losses, which increases the likelihood of a ransom payment — making companies more vulnerable to blackmail.
As the researchers point out, “the urgent need for recovery is driving many companies to pay the ransom, reinforcing the business strategy of ransomware groups.”
Ransomware attacks launch globally
The overall picture is even more worrying. In the second quarter of 2025, 276 confirmed ransomware attacks, a number that increased by 63% compared to the same quarter of 2024.The months of April and May in particular recorded record numbers with 89 and 91 attacks respectively.
95% of attacks included data theft, while in many cases, encryption of systems was not necessary to achieve the attackers' goals.
See also: Albemarle County hit by Ransomware attack
The most affected industries
Although the retail sector is under pressure, the most targeted sector was healthcare with 52 attacks (18.8%), followed by government them (16.3%) and services (12%)to pay ransom.
The Qilin group emerged as the most active of the quarter, accounting for 10% of confirmed cases, followed by INC Ransom, Interlock, Akira, and Medusa
The invisible problem: Unreported attacks
One of the most shocking findings of the report is the lack of transparency: it is estimated that only 1 in 5 ransomware attacks are publicly reported. Specifically, 1446 incidents were not reported (a 19% increase compared to 2024). Qilin was again the most active group in unreported incidents (15%).
Internal confirmation: M&S chairman is “nailing” the market
Indicative of the lack of transparency is the testimony of Archie Norman, chairman of Marks & Spencer, before the UK Parliament. He revealed that he is aware of at least two serious attacks on major companies that were not publicly reported in the last four months.

The critical need for transparency and defense
The rapid increase in ransomware attacks in the retail sector (and beyond) highlights not only the technological vulnerability of businesses, but also the inadequate response in terms of management and disclosure. In a world where cybersecurity is becoming an integral part of corporate survival, strengthening protection mechanisms, but also transparency towards the public and regulators, are the only way forward.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: GLOBAL GROUP: New Ransomware-as-a-Service business
🔐 The next big challenge for companies is not if they will be attacked, but when — and how to manage it.
Ransomware protection
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using email security solutions for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
Source: www.infosecurity-magazine.com
