RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 25 April 2025 event · prepared 16 September 2026

A help desk call became the way into three UK retailers in 2025

M&S, NCSC and NCA records describe a help-desk social-engineering wave across three retailers and the case for fast containment.

Visual for this record: A help desk call became the way into three UK retailers in 2025
Visual published by ncsc.gov.uk, shown for identification of the record. Credit: ncsc.gov.uk · source page ↗ Rights: owner-review-pending.

What happened

In the closing weeks of April 2025, Marks and Spencer told the public it was managing a cyber incident. Its own further update, issued 25 April, says the retailer paused taking orders through its website and apps as part of proactive containment, and notes customers were first told of the incident on the Tuesday before. Co-op and Harrods each confirmed incidents of their own within days. The National Cyber Security Centre's guidance for the sector, published 4 May and updated through July, says it was working with the affected organisations but was not, at that point, able to say whether the incidents were linked. On 10 July, the National Crime Agency announced four arrests in the West Midlands and London, of two 19-year-old men, a 17-year-old boy and a 20-year-old woman, on suspicion of Computer Misuse Act offences, blackmail, money laundering and organised crime.

Confidence and limits

A retailer's own disclosure, a national technical authority's guidance and a law-enforcement arrest announcement all describe the same spring, which is unusually strong corroboration for a live case. What the record does not establish is a single culprit. The NCSC stops short of confirming a common actor, and the arrests concern people suspected in connection with the attacks collectively, not evidence tying one person to one company's intrusion. The NCSC's guidance references reporting on tactics researchers associate with a group commonly called Scattered Spider, without attributing these specific incidents to it.

Why it mattered

The pattern here is not a novel exploit but a familiar one, aimed at people rather than code. M&S's decision to pause its own online ordering mid-incident is the detail worth sitting with: a retailer chose measurable, public revenue loss over leaving a live intruder connected to systems handling customer orders and payment data. The NCSC's guidance frames that kind of rapid containment as evidence of resilience, not failure. The incidents also showed how one technique, gaining trust at a help desk, reached three large organisations within weeks of each other.

Defensive takeaway

Check whether your help desk can reset a password or a multi-factor enrolment for a privileged account without an independent identity check that a caller cannot talk their way around, and rehearse the decision to take systems offline before you need to make it under pressure.

  • Can help desk staff explain, unprompted, the verification steps required before an MFA reset on a privileged account?
  • Who has the authority to take customer-facing systems offline, and how fast can that decision actually be executed?
  • Would your organisation know within days, rather than weeks, whether a similar intrusion had reached data export?

None of the statements cited here, nor the NCSC's guidance, nor the NCA's arrest announcement name a confirmed perpetrator. What they establish, together, is a documented sequence of disclosure, containment choices and an ongoing law-enforcement response, which is a more durable lesson for a defender than attribution would be.

Defensive takeaway

Check whether your help desk can reset a password or MFA enrolment for a privileged account without an identity check a caller cannot talk their way around, and rehearse the decision to take systems offline.

A retailer's own disclosure, national guidance and a law-enforcement arrest announcement corroborate the incidents and the arrests; none of the three establishes a single actor behind all three retailers.

Sources & reading trail

Cyber Incident - Further Update ↗

M&S's own account of pausing online and app orders and containing the incident, and that customers were first told of it on the Tuesday before.

company-primary · Source published: 25 April 2025 · Retrieved: 16 September 2026

Incidents impacting retailers – recommendations from the NCSC ↗

NCSC guidance stating it was not yet able to say whether the retail incidents were linked, and referencing reported help-desk social-engineering tactics.

government-primary · Source published: 4 May 2025 · Retrieved: 16 September 2026

Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods ↗

Confirms all three named retail victims and records four arrests on suspicion of Computer Misuse Act offences, blackmail, money laundering and organised crime.

government-primary · Source published: 10 July 2025 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.