BREAKING: Arrests Made in M&S, Co-op, and Harrods Cyber-Attack Investigation

July 15, 2025

Published: July 15, 2025
Author: Cybergen Team


The UK’s National Crime Agency (NCA) has made a major breakthrough in one of the most high-profile cyber investigations of the year. Four individuals aged between 17 and 20 have been arrested in connection with the devastating April 2025 cyber-attacks on Marks & Spencer (M&S), Co-op, and Harrods.


The suspects—two 19-year-olds, a 17-year-old, and a 20-year-old woman—were detained across the West Midlands, Staffordshire, and London. They are being held on suspicion of several serious offences under the Computer Misuse Act, including blackmail, money laundering, and involvement in organised crime.

The Investigation

The Cyber Attack: What Happened?

The attack was attributed to Scattered Spider, a notorious cybercrime group linked to multiple high-profile intrusions. The group is believed to have used advanced social engineering tactics, including SIM-swapping and phishing, to gain access to internal systems. Once inside, they deployed ransomware using the DragonForce platform to encrypt key systems and extort payment.


Marks & Spencer alone is reported to have suffered financial losses of up to £300 million, making this one of the most damaging cyber-attacks on a UK business in recent memory.


Click here to read more into it.

Why This Matters

This case underscores the growing threat of organised cybercrime, especially from younger, tech-savvy individuals capable of using sophisticated tools and techniques. It also highlights the importance of cyber resilience, employee training, and multi-layered security in protecting businesses from social engineering attacks.


The arrests will no doubt be welcome news to impacted businesses and consumers, but they also serve as a reminder: cybersecurity is no longer just an IT issue, it's a business-critical priority.

Summary

Who was arrested?

Four suspects (ages 17–20) arrested in the West Midlands, Staffordshire, and London on July 10, 2025.


What are the charges?

Suspected violations include the Computer Misuse Act, blackmail, money laundering, and participating in organised crime.


Which hack was this?

The April 2025 cyber‑attacks that severely disrupted online orders at M&S (nearly seven-week pause), Co‑op, and Harrods.


Who’s behind it?

The perpetrators are linked to the Scattered Spider hacking group and the DragonForce ransomware‑as‑a‑service operation.


Next steps?

The arrested suspects remain in custody and are being questioned as digital forensic investigations proceed. The NCA continues international cooperation to identify all involved parties.

University of Glasgow quad with lush green lawn, stone buildings, and a tall tower under a partly cloudy sky.
October 17, 2025
Explore why schools, colleges and universities attract cyberattacks. Learn the key threats, vulnerabilities and how to strengthen your defences with actionable steps.
Woman in a server room checks equipment, surrounded by rows of blinking servers and cables.
October 15, 2025
Learn how Zero Trust Architecture is reshaping cyber defence for technology companies. Understand its principles, risks of ignoring it, and practical steps to protect your organisation.
October 14, 2025
Electronic Health Records, or EHRs, have transformed healthcare. They allow medical professionals to store, share and access patient data in seconds. This convenience has improved treatment accuracy, reduced paperwork, and increased collaboration across healthcare systems. Yet it has also created a new battlefield for cybercriminals. Healthcare data is now one of the most targeted assets worldwide. Recent years have seen a sharp rise in cyberattacks on hospitals and clinics. Threat actors understand the high value of health data. A single patient record can sell for hundreds of pounds on illegal markets. These records contain names, dates of birth, addresses, medical histories, insurance details, and even payment information. Unlike financial data, health data does not expire. Once stolen, it can be misused indefinitely. This blog is written for healthcare professionals, IT teams, security officers, and decision-makers responsible for data protection. The aim is to help you understand the risks, strengthen defences, and build confidence in safeguarding digital health systems. EHR cybersecurity is about more than technology. It is about trust. Patients rely on healthcare providers to protect their most private information. A single data breach can damage that trust permanently.
Two engineers in hard hats monitor data on multiple computer screens.
October 13, 2025
Learn how to protect pipeline SCADA systems from cyber intrusions. Explore real-world case studies, technical defences, and expert strategies to secure your operational technology.
Industrial factory interior with machinery, assembly lines, and carts.
October 12, 2025
Learn why ransomware is a rising threat to manufacturing plants. Explore real-world examples, data-driven insights, and expert guidance to strengthen your cybersecurity defences and protect production operations.
Cargo plane being loaded with crates by a worker on the tarmac at sunset.
October 7, 2025
Learn how cybersecurity supports airport infrastructure management, protects passenger data, and secures aviation systems from digital threats. Discover best practices, frameworks, and Cybergen Security solutions for stronger airport resilience.
Big Ben clock tower bathed in warm sunlight, part of the Houses of Parliament, London.
October 4, 2025
Learn how government systems face the growing threat of cyber warfare, what attacks target national infrastructure, and how Cybergen helps build resilience through advanced cybersecurity.
Man and woman in business attire reviewing documents at a table; light streams through a window.
October 4, 2025
Learn how law firms can strengthen cybersecurity to protect sensitive client data, prevent breaches, and meet UK compliance standards with Cybergen’s expert guidance.
Black man in a white coat in a pharmacy, looking down at shelves of medicines.
October 2, 2025
Protect pharmaceutical research from cyber espionage. Learn about current threats, risks, real-world breaches, and practical security steps. Expert advice from Cybergen Security.