BREAKING: Arrests Made in M&S, Co-op, and Harrods Cyber-Attack Investigation

July 15, 2025

Published: July 15, 2025
Author: Cybergen Team


The UK’s National Crime Agency (NCA) has made a major breakthrough in one of the most high-profile cyber investigations of the year. Four individuals aged between 17 and 20 have been arrested in connection with the devastating April 2025 cyber-attacks on Marks & Spencer (M&S), Co-op, and Harrods.


The suspects—two 19-year-olds, a 17-year-old, and a 20-year-old woman—were detained across the West Midlands, Staffordshire, and London. They are being held on suspicion of several serious offences under the Computer Misuse Act, including blackmail, money laundering, and involvement in organised crime.

The Investigation

The Cyber Attack: What Happened?

The attack was attributed to Scattered Spider, a notorious cybercrime group linked to multiple high-profile intrusions. The group is believed to have used advanced social engineering tactics, including SIM-swapping and phishing, to gain access to internal systems. Once inside, they deployed ransomware using the DragonForce platform to encrypt key systems and extort payment.


Marks & Spencer alone is reported to have suffered financial losses of up to £300 million, making this one of the most damaging cyber-attacks on a UK business in recent memory.


Click here to read more into it.

Why This Matters

This case underscores the growing threat of organised cybercrime, especially from younger, tech-savvy individuals capable of using sophisticated tools and techniques. It also highlights the importance of cyber resilience, employee training, and multi-layered security in protecting businesses from social engineering attacks.


The arrests will no doubt be welcome news to impacted businesses and consumers, but they also serve as a reminder: cybersecurity is no longer just an IT issue, it's a business-critical priority.

Summary

Who was arrested?

Four suspects (ages 17–20) arrested in the West Midlands, Staffordshire, and London on July 10, 2025.


What are the charges?

Suspected violations include the Computer Misuse Act, blackmail, money laundering, and participating in organised crime.


Which hack was this?

The April 2025 cyber‑attacks that severely disrupted online orders at M&S (nearly seven-week pause), Co‑op, and Harrods.


Who’s behind it?

The perpetrators are linked to the Scattered Spider hacking group and the DragonForce ransomware‑as‑a‑service operation.


Next steps?

The arrested suspects remain in custody and are being questioned as digital forensic investigations proceed. The NCA continues international cooperation to identify all involved parties.

Neon AI letters with a glowing purple orbit on a dark tech-style background
June 3, 2026
Discover how Shadow AI is creating hidden security, compliance and data risks. Learn how to regain visibility, govern AI usage and reduce exposure.
Two professionals in a tech office with a laptop showing code and a digital globe display
May 19, 2026
Traditional threat intelligence is no longer enough. Discover how intelligence-led cybersecurity helps organisations predict, prioritise, and prevent cyber threats before they escalate.
Technician in a data center using a tablet beside server racks and digital displays
May 15, 2026
Discover the top network security priorities for CISOs in 2026, from modern firewalling and exposure management to Zero Trust, SASE, AI security, and cyber resilience.
CREST and Pen Test logos on a blue cybersecurity-themed background
May 12, 2026
Discover why CREST penetration testing is essential for identifying exploitable vulnerabilities, reducing cyber risk, and strengthening your organisation’s security posture.
May 11, 2026
Artificial intelligence is no longer emerging technology. It is already embedded inside the modern workplace. Across the UK, employees are using AI applications such as ChatGPT, Microsoft Copilot, Claude, Gemini, Perplexity, and countless specialist tools to improve productivity, save time, analyse information, draft reports, automate repetitive work, and accelerate decision-making. For many organisations, this represents an enormous opportunity. Teams can work faster, employees can automate administrative tasks, knowledge workers can produce content in minutes instead of hours, and businesses can gain competitive advantage through operational efficiency. However, there is another side to this story that many leadership teams, CISOs, and compliance professionals are only beginning to understand. Your employees are already using AI. The real question is whether you know how they are using it. Because while artificial intelligence is driving productivity, it is also creating a hidden security risk inside organisations, often without malicious intent, and frequently without employees even realising they are exposing sensitive information. The uncomfortable truth is that many businesses have already lost visibility and control. Employees are uploading confidential documents into public AI systems, sharing commercially sensitive information in prompts, exposing HR and financial data, pasting source code into third party models, and unknowingly bypassing existing data governance processes. In many cases, security teams simply do not see it happening. And if you cannot see it, you cannot control it. In 2026, secure AI adoption is rapidly becoming one of the most important priorities for cybersecurity leaders. The challenge is no longer whether employees should use AI. The challenge is how organisations can enable AI safely, securely, and compliantly without slowing innovation.
Hands typing on a laptop with a glowing AI interface on screen
April 28, 2026
Uncontrolled AI usage is creating hidden risks across organisations. Learn how to gain visibility, manage exposure, and take control of AI usage before it becomes a security or compliance issue.
Abstract digital globe with blue data streams and binary code racing through a tunnel-like network background
April 23, 2026
Insider threats are evolving as data moves faster than security controls. Learn how organisations can regain visibility and protect sensitive information.
Laptop with cyber data protection graphics, shield icons, and a hand touching a glowing security interface
April 20, 2026
Traditional data protection is no longer enough. Discover why organisations must shift to data control to manage modern cyber risk.
A person in a suit works at a desk with multiple monitors displaying complex data, charts, and a glowing digital lock.
April 11, 2026
AI is creating new, invisible data security risks. Learn how shadow AI, insider behaviour, and identity threats are exposing organisations, and how to defend against them.