
What happened
In the closing weeks of April 2025, Marks and Spencer told the public it was managing a cyber incident. Its own further update, issued 25 April, says the retailer paused taking orders through its website and apps as part of proactive containment, and notes customers were first told of the incident on the Tuesday before. Co-op and Harrods each confirmed incidents of their own within days. The National Cyber Security Centre's guidance for the sector, published 4 May and updated through July, says it was working with the affected organisations but was not, at that point, able to say whether the incidents were linked. On 10 July, the National Crime Agency announced four arrests in the West Midlands and London, of two 19-year-old men, a 17-year-old boy and a 20-year-old woman, on suspicion of Computer Misuse Act offences, blackmail, money laundering and organised crime.
Confidence and limits
A retailer's own disclosure, a national technical authority's guidance and a law-enforcement arrest announcement all describe the same spring, which is unusually strong corroboration for a live case. What the record does not establish is a single culprit. The NCSC stops short of confirming a common actor, and the arrests concern people suspected in connection with the attacks collectively, not evidence tying one person to one company's intrusion. The NCSC's guidance references reporting on tactics researchers associate with a group commonly called Scattered Spider, without attributing these specific incidents to it.
Why it mattered
The pattern here is not a novel exploit but a familiar one, aimed at people rather than code. M&S's decision to pause its own online ordering mid-incident is the detail worth sitting with: a retailer chose measurable, public revenue loss over leaving a live intruder connected to systems handling customer orders and payment data. The NCSC's guidance frames that kind of rapid containment as evidence of resilience, not failure. The incidents also showed how one technique, gaining trust at a help desk, reached three large organisations within weeks of each other.
Defensive takeaway
Check whether your help desk can reset a password or a multi-factor enrolment for a privileged account without an independent identity check that a caller cannot talk their way around, and rehearse the decision to take systems offline before you need to make it under pressure.
- Can help desk staff explain, unprompted, the verification steps required before an MFA reset on a privileged account?
- Who has the authority to take customer-facing systems offline, and how fast can that decision actually be executed?
- Would your organisation know within days, rather than weeks, whether a similar intrusion had reached data export?
None of the statements cited here, nor the NCSC's guidance, nor the NCA's arrest announcement name a confirmed perpetrator. What they establish, together, is a documented sequence of disclosure, containment choices and an ongoing law-enforcement response, which is a more durable lesson for a defender than attribution would be.
Check whether your help desk can reset a password or MFA enrolment for a privileged account without an identity check a caller cannot talk their way around, and rehearse the decision to take systems offline.
A retailer's own disclosure, national guidance and a law-enforcement arrest announcement corroborate the incidents and the arrests; none of the three establishes a single actor behind all three retailers.
Sources & reading trail
M&S's own account of pausing online and app orders and containing the incident, and that customers were first told of it on the Tuesday before.
company-primary · Source published: 25 April 2025 · Retrieved: 16 September 2026
NCSC guidance stating it was not yet able to say whether the retail incidents were linked, and referencing reported help-desk social-engineering tactics.
government-primary · Source published: 4 May 2025 · Retrieved: 16 September 2026
Confirms all three named retail victims and records four arrests on suspicion of Computer Misuse Act offences, blackmail, money laundering and organised crime.
government-primary · Source published: 10 July 2025 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.