Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
In a devastating wave of cybercrime, UK retailers were hit hard in a coordinated series of attacks that began in April. Marks & Spencer was the first to suffer—customers were locked out of their “Click and Collect” orders, online payments failed, and shelves began to empty rapidly.
Shortly after, Co-Op confirmed it had proactively shut down key IT systems during a cyber incident. Next, Harrods also faced an attempted breach. Then came a chilling development. Dior, part of the LVMH group, disclosed on May 14 that attackers had accessed customer data including names, emails, phone numbers, and postal addresses—though financial information remained secure.
A single threat actor is believed to be behind these attacks. Cybersecurity experts linked the incidents to the Scattered Spider collective, operating through DragonForce ransomware. Known for targeting one sector at a time, Scattered Spider had previously attacked MGM and Caesars in the U.S. and now appeared to have turned its sights on UK retail.
Explore our exclusive, in-depth timeline for the full breakdown of these shocking events and understand how one of the UK’s most vital sectors came under siege.
Don't forget to read our blog on this relentless saga of cyber terror in our blog on the UK Retail Cyber Attacks.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.