Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
In a devastating wave of cybercrime, UK retailers were hit hard in a coordinated series of attacks that began in April. Marks & Spencer was the first to suffer—customers were locked out of their “Click and Collect” orders, online payments failed, and shelves began to empty rapidly.
Shortly after, Co-Op confirmed it had proactively shut down key IT systems during a cyber incident. Next, Harrods also faced an attempted breach. Then came a chilling development. Dior, part of the LVMH group, disclosed on May 14 that attackers had accessed customer data including names, emails, phone numbers, and postal addresses—though financial information remained secure.
A single threat actor is believed to be behind these attacks. Cybersecurity experts linked the incidents to the Scattered Spider collective, operating through DragonForce ransomware. Known for targeting one sector at a time, Scattered Spider had previously attacked MGM and Caesars in the U.S. and now appeared to have turned its sights on UK retail.
Explore our exclusive, in-depth timeline for the full breakdown of these shocking events and understand how one of the UK’s most vital sectors came under siege.
Don't forget to read our blog on this relentless saga of cyber terror in our blog on the UK Retail Cyber Attacks.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
Between April and July 2025, four major UK and European retailers – Marks & Spencer, Co-op, Harrods and Christian Dior – were targeted in a wave of cyber attacks widely linked to English-speaking cybercrime groups operating under banners such as Scattered Spider and the DragonForce ransomware-as-a-service operation. Marks & Spencer suffered the most damaging incident, with ransomware and social engineering causing weeks of disrupted online trading, empty shelves and a stolen customer database. Co-op confirmed hackers extracted member data, later admitting all 6.5 million members were affected. Harrods proactively restricted internet access after attempted unauthorised access, containing the incident within about a day. Christian Dior confirmed a separate customer-data theft, reported by French media in May 2025. Together, the incidents became one of the most significant retail cybersecurity events in UK history, leading to National Crime Agency arrests in July 2025.
M&S first disclosed its cyber incident on 22 April 2025, with disruption to Click & Collect and contactless payments; investigators later traced the initial breach to activity as early as February 2025. Co-op confirmed it had shut down parts of its IT systems on 29 April 2025, just days after the M&S disclosure. Harrods confirmed it had been targeted on 1 May 2025, becoming the third major UK retailer hit within a week. Dior's incident was disclosed on 14 May 2025 via French outlet Le Monde, with the underlying data theft reported to have occurred in January 2025. Four arrests connected to the M&S, Co-op and Harrods attacks followed on 10 July 2025.
Attribution was never definitively confirmed for any of the four incidents. Security researchers and multiple media outlets pointed to the English-speaking hacking collective known as Scattered Spider (also tracked as Octo Tempest) for the intrusion technique used against M&S, and to the DragonForce ransomware-as-a-service operation for the ransomware deployed. Co-op and Harrods were also linked to DragonForce in reporting, and Dior's incident has similarly been associated with the group, though this was not independently confirmed in every case. On 10 July 2025, the UK's National Crime Agency arrested four people – a 20-year-old woman and three males aged 17 to 19 – in connection with the M&S, Co-op and Harrods attacks, on suspicion of Computer Misuse Act offences, blackmail, money laundering and organised crime group participation.
M&S disclosed on 22 April 2025 that it was managing a cyber incident affecting Click & Collect, contactless payments and online ordering. The company later paused all website and app orders, and stores experienced empty shelves as supply chains were disrupted. Investigators concluded the attackers gained initial access through social engineering targeting a third-party contractor (reported to be Tata Consultancy Services), tricking a service desk into resetting an internal password, before deploying ransomware associated with DragonForce. M&S confirmed that customer personal data – potentially affecting up to 9.4 million online accounts – had been accessed, though payment details and passwords were not compromised. Online disruption continued into July 2025, with the company estimating a c.£300 million hit to annual profit.
M&S estimated the attack would cost around £300 million in lost profit for the 2025/26 financial year, alongside more than £1 billion wiped from its stock market value at various points during the incident. Press reports put daily losses as high as several million pounds while online trading was suspended. M&S was reported to have cyber insurance and may have filed a claim of up to £100 million to offset some of the losses, though this only partly covers the estimated impact. These figures are drawn from press reporting and company disclosures rather than a single official reconciled total, so the precise final cost has not been independently confirmed.
No company has confirmed paying a ransom. M&S adopted what its chairman described as a "hands-off approach", declining to negotiate directly with the attackers and declining to comment publicly on any ransom payment; speculation about a possible payment arose after the DragonForce leak site reportedly did not list M&S. Co-op said its network "never suffered ransomware" because it proactively disconnected systems before encryption could take hold, and no ransom payment has been reported. Harrods likewise reported no ransom demand, having restricted access to its systems within hours of detecting attempted intrusion.
Co-op confirmed on 29 April 2025 that it had pre-emptively restricted access to some systems after detecting an attempted hack, leading to disrupted deliveries and empty shelves across its food stores for around three weeks. Forensic investigation confirmed hackers had extracted personal data – including names, contact details and dates of birth – belonging to Co-op Group members. Initially described as affecting "a significant number" of members, Co-op's chief executive confirmed on 16 July 2025 that all 6.5 million members had had their data taken. No financial data, transaction information or passwords were confirmed stolen, and no ransom was reported to have been paid.
Harrods confirmed on 1 May 2025 that it had experienced attempts to gain unauthorised access to its systems, becoming the third major UK retailer hit within a week after M&S and Co-op. Harrods' IT security team proactively restricted internet access at its sites as a precaution, but stores – including its Knightsbridge flagship – and the harrods.com website remained open throughout. The incident was contained within roughly 24 hours, and Harrods reported no evidence that customer data had been compromised, making it the least disruptive of the four incidents.
Christian Dior confirmed in May 2025 that an unauthorised third party had accessed certain customer data, after clients in Asia alerted the company. French outlet Le Monde reported that the underlying intrusion had occurred earlier, around January 2025, and that the stolen information included customers' names, email and postal addresses, and telephone numbers. Dior stated that no financial information, such as bank card details, was involved, and that its online shopping platform remained operational throughout, with no reported disruption to trading.
The attacks were closely clustered in time and shared several characteristics – social engineering against IT help desks or third parties, ransomware associated with the DragonForce operation, and tactics consistent with the Scattered Spider group – which led investigators and the media to treat them as part of the same wave of activity. The UK's National Cyber Security Centre said it was working with M&S, Co-op and Harrods to understand the incidents but did not confirm the attacks were formally linked. The National Crime Agency's July 2025 arrests covered suspects connected to the M&S, Co-op and Harrods incidents; Dior's breach, reported separately via French media, has not been confirmed as linked to the same group.
All four retailers engaged external cybersecurity specialists and notified relevant regulators, including the UK's National Cyber Security Centre. M&S brought in CrowdStrike, Microsoft and Fenix24 to help investigate and rebuild systems, paused online trading, and ran a phased restart into July 2025. Co-op restricted system access early, then gradually restored stock ordering and supply chains over several weeks, later offering members a goodwill discount. Harrods restricted internet access at its sites within hours, keeping stores and its website open throughout. Dior said it was working with cybersecurity experts, informing regulators, and notifying affected customers directly.
The 2025 UK retail attacks show how quickly a single social-engineering compromise – often via a third-party contractor or IT help desk – can escalate into weeks of operational disruption, stolen customer data and hundreds of millions of pounds in losses. Key lessons include the importance of rigorous third-party and supply-chain risk management, robust identity verification for password and MFA resets, tested incident response and business continuity plans, and rehearsed crisis communications for customers, media and regulators. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.