Cyber-Attack Timeline: UK Retail Under Siege

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

UK Retail Timeline

Download Our Detailed Timeline on the Recent Cyber Attacks on UK Retailers

In a devastating wave of cybercrime, UK retailers were hit hard in a coordinated series of attacks that began in April. Marks & Spencer was the first to suffer—customers were locked out of their “Click and Collect” orders, online payments failed, and shelves began to empty rapidly.

Shortly after, Co-Op confirmed it had proactively shut down key IT systems during a cyber incident. Next, Harrods also faced an attempted breach. Then came a chilling development. Dior, part of the LVMH group, disclosed on May 14 that attackers had accessed customer data including names, emails, phone numbers, and postal addresses—though financial information remained secure.

A single threat actor is believed to be behind these attacks. Cybersecurity experts linked the incidents to the Scattered Spider collective, operating through DragonForce ransomware. Known for targeting one sector at a time, Scattered Spider had previously attacked MGM and Caesars in the U.S. and now appeared to have turned its sights on UK retail.

Explore our exclusive, in-depth timeline for the full breakdown of these shocking events and understand how one of the UK’s most vital sectors came under siege.

Don't forget to read our blog on this relentless saga of cyber terror in our blog on the UK Retail Cyber Attacks.

 

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed UK Cyber Attacks timeline document.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the UK Retail Cyber Attacks 2025

  • 1. What happened in the 2025 UK retail cyber attacks on M&S, Co-op, Harrods and Dior?

    Between April and July 2025, four major UK and European retailers – Marks & Spencer, Co-op, Harrods and Christian Dior – were targeted in a wave of cyber attacks widely linked to English-speaking cybercrime groups operating under banners such as Scattered Spider and the DragonForce ransomware-as-a-service operation. Marks & Spencer suffered the most damaging incident, with ransomware and social engineering causing weeks of disrupted online trading, empty shelves and a stolen customer database. Co-op confirmed hackers extracted member data, later admitting all 6.5 million members were affected. Harrods proactively restricted internet access after attempted unauthorised access, containing the incident within about a day. Christian Dior confirmed a separate customer-data theft, reported by French media in May 2025. Together, the incidents became one of the most significant retail cybersecurity events in UK history, leading to National Crime Agency arrests in July 2025.

  • 2. When did the M&S, Co-op, Harrods and Dior cyber attacks happen, and how did the timeline unfold?

    M&S first disclosed its cyber incident on 22 April 2025, with disruption to Click & Collect and contactless payments; investigators later traced the initial breach to activity as early as February 2025. Co-op confirmed it had shut down parts of its IT systems on 29 April 2025, just days after the M&S disclosure. Harrods confirmed it had been targeted on 1 May 2025, becoming the third major UK retailer hit within a week. Dior's incident was disclosed on 14 May 2025 via French outlet Le Monde, with the underlying data theft reported to have occurred in January 2025. Four arrests connected to the M&S, Co-op and Harrods attacks followed on 10 July 2025.

  • 3. Who was behind the UK retail cyber attacks on M&S, Co-op, Harrods and Dior?

    Attribution was never definitively confirmed for any of the four incidents. Security researchers and multiple media outlets pointed to the English-speaking hacking collective known as Scattered Spider (also tracked as Octo Tempest) for the intrusion technique used against M&S, and to the DragonForce ransomware-as-a-service operation for the ransomware deployed. Co-op and Harrods were also linked to DragonForce in reporting, and Dior's incident has similarly been associated with the group, though this was not independently confirmed in every case. On 10 July 2025, the UK's National Crime Agency arrested four people – a 20-year-old woman and three males aged 17 to 19 – in connection with the M&S, Co-op and Harrods attacks, on suspicion of Computer Misuse Act offences, blackmail, money laundering and organised crime group participation.

  • 4. What happened in the Marks & Spencer (M&S) cyber attack?

    M&S disclosed on 22 April 2025 that it was managing a cyber incident affecting Click & Collect, contactless payments and online ordering. The company later paused all website and app orders, and stores experienced empty shelves as supply chains were disrupted. Investigators concluded the attackers gained initial access through social engineering targeting a third-party contractor (reported to be Tata Consultancy Services), tricking a service desk into resetting an internal password, before deploying ransomware associated with DragonForce. M&S confirmed that customer personal data – potentially affecting up to 9.4 million online accounts – had been accessed, though payment details and passwords were not compromised. Online disruption continued into July 2025, with the company estimating a c.£300 million hit to annual profit.

  • 5. How much did the M&S cyber attack cost, and was M&S insured?

    M&S estimated the attack would cost around £300 million in lost profit for the 2025/26 financial year, alongside more than £1 billion wiped from its stock market value at various points during the incident. Press reports put daily losses as high as several million pounds while online trading was suspended. M&S was reported to have cyber insurance and may have filed a claim of up to £100 million to offset some of the losses, though this only partly covers the estimated impact. These figures are drawn from press reporting and company disclosures rather than a single official reconciled total, so the precise final cost has not been independently confirmed.

  • 6. Was a ransom paid in the M&S, Co-op or Harrods cyber attacks?

    No company has confirmed paying a ransom. M&S adopted what its chairman described as a "hands-off approach", declining to negotiate directly with the attackers and declining to comment publicly on any ransom payment; speculation about a possible payment arose after the DragonForce leak site reportedly did not list M&S. Co-op said its network "never suffered ransomware" because it proactively disconnected systems before encryption could take hold, and no ransom payment has been reported. Harrods likewise reported no ransom demand, having restricted access to its systems within hours of detecting attempted intrusion.

  • 7. What happened in the Co-op cyber attack, and what data was stolen?

    Co-op confirmed on 29 April 2025 that it had pre-emptively restricted access to some systems after detecting an attempted hack, leading to disrupted deliveries and empty shelves across its food stores for around three weeks. Forensic investigation confirmed hackers had extracted personal data – including names, contact details and dates of birth – belonging to Co-op Group members. Initially described as affecting "a significant number" of members, Co-op's chief executive confirmed on 16 July 2025 that all 6.5 million members had had their data taken. No financial data, transaction information or passwords were confirmed stolen, and no ransom was reported to have been paid.

  • 8. What happened in the Harrods cyber attack?

    Harrods confirmed on 1 May 2025 that it had experienced attempts to gain unauthorised access to its systems, becoming the third major UK retailer hit within a week after M&S and Co-op. Harrods' IT security team proactively restricted internet access at its sites as a precaution, but stores – including its Knightsbridge flagship – and the harrods.com website remained open throughout. The incident was contained within roughly 24 hours, and Harrods reported no evidence that customer data had been compromised, making it the least disruptive of the four incidents.

  • 9. What happened in the Christian Dior cyber attack?

    Christian Dior confirmed in May 2025 that an unauthorised third party had accessed certain customer data, after clients in Asia alerted the company. French outlet Le Monde reported that the underlying intrusion had occurred earlier, around January 2025, and that the stolen information included customers' names, email and postal addresses, and telephone numbers. Dior stated that no financial information, such as bank card details, was involved, and that its online shopping platform remained operational throughout, with no reported disruption to trading.

  • 10. Were the M&S, Co-op, Harrods and Dior cyber attacks connected?

    The attacks were closely clustered in time and shared several characteristics – social engineering against IT help desks or third parties, ransomware associated with the DragonForce operation, and tactics consistent with the Scattered Spider group – which led investigators and the media to treat them as part of the same wave of activity. The UK's National Cyber Security Centre said it was working with M&S, Co-op and Harrods to understand the incidents but did not confirm the attacks were formally linked. The National Crime Agency's July 2025 arrests covered suspects connected to the M&S, Co-op and Harrods incidents; Dior's breach, reported separately via French media, has not been confirmed as linked to the same group.

  • 11. How did M&S, Co-op, Harrods and Dior respond to the cyber attacks?

    All four retailers engaged external cybersecurity specialists and notified relevant regulators, including the UK's National Cyber Security Centre. M&S brought in CrowdStrike, Microsoft and Fenix24 to help investigate and rebuild systems, paused online trading, and ran a phased restart into July 2025. Co-op restricted system access early, then gradually restored stock ordering and supply chains over several weeks, later offering members a goodwill discount. Harrods restricted internet access at its sites within hours, keeping stores and its website open throughout. Dior said it was working with cybersecurity experts, informing regulators, and notifying affected customers directly.

  • 12. What can other organisations learn from the M&S, Co-op, Harrods and Dior cyber attacks?

    The 2025 UK retail attacks show how quickly a single social-engineering compromise – often via a third-party contractor or IT help desk – can escalate into weeks of operational disruption, stolen customer data and hundreds of millions of pounds in losses. Key lessons include the importance of rigorous third-party and supply-chain risk management, robust identity verification for password and MFA resets, tested incident response and business continuity plans, and rehearsed crisis communications for customers, media and regulators. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.