BREAKING: Arrests Made in M&S, Co-op, and Harrods Cyber-Attack Investigation

July 15, 2025

Published: July 15, 2025
Author: Cybergen Team


The UK’s National Crime Agency (NCA) has made a major breakthrough in one of the most high-profile cyber investigations of the year. Four individuals aged between 17 and 20 have been arrested in connection with the devastating April 2025 cyber-attacks on Marks & Spencer (M&S), Co-op, and Harrods.


The suspects—two 19-year-olds, a 17-year-old, and a 20-year-old woman—were detained across the West Midlands, Staffordshire, and London. They are being held on suspicion of several serious offences under the Computer Misuse Act, including blackmail, money laundering, and involvement in organised crime.

The Investigation

The Cyber Attack: What Happened?

The attack was attributed to Scattered Spider, a notorious cybercrime group linked to multiple high-profile intrusions. The group is believed to have used advanced social engineering tactics, including SIM-swapping and phishing, to gain access to internal systems. Once inside, they deployed ransomware using the DragonForce platform to encrypt key systems and extort payment.


Marks & Spencer alone is reported to have suffered financial losses of up to £300 million, making this one of the most damaging cyber-attacks on a UK business in recent memory.


Click here to read more into it.

Why This Matters

This case underscores the growing threat of organised cybercrime, especially from younger, tech-savvy individuals capable of using sophisticated tools and techniques. It also highlights the importance of cyber resilience, employee training, and multi-layered security in protecting businesses from social engineering attacks.


The arrests will no doubt be welcome news to impacted businesses and consumers, but they also serve as a reminder: cybersecurity is no longer just an IT issue, it's a business-critical priority.

Summary

Who was arrested?

Four suspects (ages 17–20) arrested in the West Midlands, Staffordshire, and London on July 10, 2025.


What are the charges?

Suspected violations include the Computer Misuse Act, blackmail, money laundering, and participating in organised crime.


Which hack was this?

The April 2025 cyber‑attacks that severely disrupted online orders at M&S (nearly seven-week pause), Co‑op, and Harrods.


Who’s behind it?

The perpetrators are linked to the Scattered Spider hacking group and the DragonForce ransomware‑as‑a‑service operation.


Next steps?

The arrested suspects remain in custody and are being questioned as digital forensic investigations proceed. The NCA continues international cooperation to identify all involved parties.

July 17, 2025
Discover how healthcare penetration testing secures patient records, protects EMR systems, and ensures NHS and HIPAA data compliance. Learn best practices today.
July 16, 2025
Having a DLP policy in your business is essential. In this blog, we explore what data loss prevention is and why it’s more important than ever for organisations to take it seriously. We all know that data, especially corporate and customer data has become a prime commodity for cybercriminals. Without a proper Data Loss Prevention (DLP) strategy, sensitive data like intellectual property, payment card information, Social Security numbers, and health records is at constant risk of being lost, stolen, or misused by attackers. In today's increasingly digital and remote-first world, where cyberattacks are becoming more frequent and complex, DLP has evolved from a “nice-to-have” to a non-negotiable for every organisation big or small.
An oil rig in the middle of the ocean at sunset.
July 15, 2025
Explore how cyber threats targeting oil and gas are evolving, from ransomware to OT reconnaissance, and discover practical steps to secure infrastructure, ensure safety, and stay compliant in a high-risk digital landscape.
A robotic arm is working in a factory.
July 14, 2025
Explore penetration testing for ICS and SCADA environments. Learn about threats, best practices, and how Cybergen supports critical infrastructure protection.
A blue background with a cloud icon and a person using a laptop.
July 11, 2025
Learn how to create powerful cloud penetration testing reports. Discover what clients need to see, how to explain cloud-specific risks, and boost your cybersecurity reporting.
A man is sitting in front of a computer screen in a dark room.
July 10, 2025
Learn how to detect and defend against lateral movement in corporate networks using behavioural analytics, SIEM, EDR, and zero-trust security. Explore expert strategies from Cybergen.
A blue background with a cloud and an arrow pointing up.
July 9, 2025
Learn how to protect your business from cyber threats with an effective disaster recovery and business continuity strategy. Explore Cybergen’s guide for actionable insights.
A spider is silhouetted against a blue background with a glitch effect.
July 8, 2025
Few groups have captured the attention of cybersecurity professionals and industry leaders as forcefully as Scattered Spider. Recently, a wave of cyberattacks rocked several well-known British high street retailers. One particularly high-profile attack has been attributed to this sophisticated group of cybercriminals, sparking widespread concern across the retail sector.  What makes Scattered Spider a formidable adversary is not just their technical skill, but their agility, persistence, and use of sophisticated social engineering tactics. This blog post aims to shed light on their operations, explore a recent ransomware campaign, and most importantly, provide actionable recommendations to help organisations bolster their defences.
Two men are standing next to each other in an office looking at a laptop.
July 7, 2025
Discover real-world penetration testing stories, best practices, and advice from cybersecurity experts. Learn how Cybergen Security helps organisations defend against cyber threats.
A group of people are sitting on the floor with their legs crossed and using laptops.
July 6, 2025
Discover how cybersecurity is transforming the education sector in 2025. Learn about rising threats, best practices, and how institutions can build digital resilience with advanced protection strategies.
Show More