2025-07-10
Four Arrested in Connection with UK Retailer Cyberattacks; M&S Chairman Confirms Social Engineering Involved
The UK's National Crime Agency (NCA) has published a press release stating that four people have been arrested in connection with the April 2025 cyberattacks on Marks & Spencer (M&S), Co-op, and Harrods. On July 10, 2025, "two males aged 19, another aged 17, and a 20-year-old female were apprehended in the West Midlands and London ... on suspicion of Computer Misuse Act offences, blackmail, money laundering and participating in the activities of an organised crime group," and their devices were seized for analysis. Archie Norman, chairman of Marks & Spencer since 2017, stated in a July 8 hearing with the UK Parliament's Business and Trade Sub-Committee on Economic Security that the attack on M&S was initiated via social engineering, with an attacker impersonating an employee to request a password reset from a third-party support service. Norman also verified the presence of DragonForce ransomware, though according to Bleeping Computer, he and several media sources conflate the ransomware-as-a-service (RaaS) with an unrelated hacktivist group of the same name based in Malaysia. Norman did not state whether M&S paid a ransom, but he did disclose an early internal decision that "nobody at M&S would deal with the threat actors directly," possibly indicating the aid of a third-party negotiator.
Editor's Note
Kudos to UK law enforcement in tracking down and arresting these suspects. While people may comment on the young ages of the suspects, I would caution that they are likely involved in a bigger criminal gang and these four individuals are not solely responsible for the attack. Their collaborators may be located outside of the UK and indeed may be more technically capable with better operational security. So, the threat from this gang is most likely still there and organisations need to continue to ensure technical, people, and process controls are in place to defend against the methods used by this gang, and indeed others.

Brian Honan
In short, this is a case of a very successful Social Engineering attack followed up by ransomware. This was a well-crafted impersonation. As AI capabilities continue to evolve, so do extremely convincing impersonation capabilities. Make sure your validation processes are keeping up.

Lee Neely
Use of social engineering will only increase to get initial access to a network. Feels like MFA could have helped in defeating this social engineering attack. That said, quick work by law enforcement officials in finding and arresting the culprits. Well done!

Curtis Dukes
Read more in
National Crime Agency: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods
CyberScoop: UK arrests four for cyberattacks on major British retailers
The Hacker News: Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods
Bleeping Computer: Four arrested in UK over M&S, Co-op, Harrod cyberattacks
Bleeping Computer: M&S confirms social engineering led to massive ransomware attack