Four arrested in UK over M&S, Co-op, Harrod cyberattacks

As first reported by BleepingComputer, the cyberattacks were attributed to threat actors classified as Scattered Spider, with associated hackers tied to numerous breaches over the past few years, including MGM, Twilio, Coinbase, DoorDash, Caesars, MailChimp, Riot Games, and Reddit. The UK's National Crime Agency (NCA) arrested four people suspected of being involved in cyberattacks on major retailers in the country, including Marks & Spencer, Co-op, and Harrods. During the attacks on Co-op and Marks & Spencer, the threat actors attempted to deploy the DragonForce ransomware. Although the NCA did not mention Scattered Spider in its announcement, the ethnicity, social engineering tactics, and ages of the arrested individuals match the typical profile of Scattered Spider members, as has been established from previous arrests in the US, Britain, and Spain. However, as these threat actors are believed to be part of a larger collective of diverse English-speaking threat actors that congregate on Discord, Telegram, and online forums, it is unlikely to cause a complete halt to attacks. Marks & Spencer had to pause online orders soon after the attack, and later confirmed that customer data had been stolen, forcing password resets for all customers. Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. The suspects are believed to be linked to cyberattacks on M&S, Co-op, and Harrods between late April and early May, causing massive disruptions and a negative impact on the businesses targeted by the hackers. "Since these attacks took place, specialist NCA cybercrime investigators have been working at pace and the investigation remains one of the Agency's highest priorities," stated NCA's Deputy Director, Paul Foster.

This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 10 Jul 2025 13:50:10 +0000


Cyber News related to Four arrested in UK over M&S, Co-op, Harrod cyberattacks

Four arrested in UK over M&S, Co-op, Harrod cyberattacks - As first reported by BleepingComputer, the cyberattacks were attributed to threat actors classified as Scattered Spider, with associated hackers tied to numerous breaches over the past few years, including ...
5 days ago Bleepingcomputer.com Scattered Spider Dragonforce
Hangzhou's Cybersecurity Breakthrough: How ChatGPT Elevated Ransomware Resolution - The Chinese media reported on Thursday that local police have arrested a criminal gang from Hangzhou who are using ChatGPT for program optimization to carry out ransomware attacks for the purpose of extortion. An organization in the Shangcheng ...
1 year ago Cysecurity.news
Understanding Each Link of the Cyberattack Impact Chain - It's often difficult to fully appreciate the impact of a successful cyberattack. Other consequences aren't so obvious - from a loss of customer trust and potential business to stolen data that may surface as part of another cyberattack years later. ...
1 year ago Securityboulevard.com
Europol shutters ransomware operation with kingpin arrests The Register - International law enforcement investigators have made a number of high-profile arrests after tracking a major cybercrime group for more than four years. A joint investigation team, spearheaded by French authorities, formed in 2019 to bring down a ...
1 year ago Theregister.com LockBit Rhysida
Police arrest four suspects linked to LockBit ransomware gang - Previous arrests of Lockbit ransomware actors (some of them already charged for various offenses) include Mikhail Pavlovich Matveev (aka Wazawaka) in May 2023, Artur Sungatov and Ivan Gennadievich Kondratiev (aka Bassterlord) in February 2024, and ...
9 months ago Bleepingcomputer.com LockBit
Police arrested four new individuals linked to the LockBit ransomware operation - “Europol supported a new series of actions against LockBit actors, which involved 12 countries and Eurojust and led to four arrests and seizures of servers critical for LockBit’s infrastructure.” reads the press release published by ...
9 months ago Securityaffairs.com LockBit
Chinese authorities arrest four in ransomware case involving ChatGPT - Four alleged cyberattackers have been arrested in mainland China for developing ransomware with the help of ChatGPT, the first case of its sort in the country. The South China Morning Post reported Friday that the suspects were arrested in November ...
1 year ago Siliconangle.com
Law enforcement agencies arrest 4 alleged LockBit members | TechTarget - Authorities arrested four suspected members of the LockBit ransomware gang during the third phase of the international law enforcement effort dubbed Operation Cronos. Operation Cronos' efforts to disrupt the LockBit ransomware gang continue as ...
9 months ago Techtarget.com LockBit
LockBit Ransomware Affiliate Sentenced to Prison in Canada - A Russian-Canadian national was sentenced to nearly four years in prison in Canada for his role in the LockBit ransomware operation. The man, Mikhail Vasiliev, 34, was arrested in October 2022 in his home in Bradford, Ontario. In February 2024, he ...
1 year ago Securityweek.com LockBit
Ransomware hackers 'wreaking havoc' arrested in Ukraine - European cyber police have arrested a 32-year-old suspected of being the ringleader of a ransomware gang operating in Ukraine. In raids across the country authorities seized laptops and arrested four other alleged hackers. The gang are accused of ...
1 year ago Bbc.com
Police dismantle pirated TV streaming network that made $5.7 million - Spanish police have dismantled a network of illegal media content distribution that, since the start of its operations in 2015, has made over $5,700,000. The investigation began in November 2022 following a complaint submitted by the Alliance for ...
1 year ago Bleepingcomputer.com
Ransomware Attacks Strike South Africa, Decline in UAE - Cybercrime - and especially ransomware - traditionally have had an uneven impact across the Middle East and Africa, yet recent data suggests that ongoing geopolitical conflicts will likely raise the overall level of cyberattacks across the regions. ...
1 year ago Darkreading.com Molerats LockBit
Spain arrests 34 cybercriminals who stole data of 4 million people - The Spanish National Police have dismantled a cybercriminal organization that carried out a variety of computer scams to steal and monetize the data of over four million people. Law enforcement in the country conducted 16 targeted searches in Madrid, ...
1 year ago Bleepingcomputer.com LockBit Ragnar Locker
Spain arrests hackers who targeted politicians and journalists - In recent years, Spanish police has been successful in tracking and arresting several high-profile cybercriminals. This February, they arrested a hacker believed to have breached Guardia Civil, the Ministry of Defense, NATO, the U.S. Army, and ...
1 week ago Bleepingcomputer.com Scattered Spider
Major Cybercrime Crackdown: Encrypted Messenger Exclu Seized - Authorities have arrested 48 people in connection with Exclu, discovered two drug labs and a cocaine-processing facility, and confiscated $4.3 million, several kilograms of drugs, and luxury items. European law-enforcement authorities have seized ...
2 years ago Hackread.com
4 new LockBit-related arrests, identities of suspected Evil Corp members, affiliates revealed - Help Net Security - The third phase of Operation Cronos, which involved officers from the UK National Crime Agency (NCA), the FBI, Europol and other law enforcement agencies, has resulted in the arrest of four persons for allegedly participating in the LockBit ...
9 months ago Helpnetsecurity.com LockBit
Massive 911 S5 Botnet Dismantled, Chinese Mastermind Arrested - The US Justice Department announced on Wednesday that the massive 911 S5 proxy botnet has been dismantled and its alleged administrator, a Chinese national, has been arrested. The Treasury Department earlier this week announced sanctions against ...
1 year ago Packetstormsecurity.com
Suspected Desorden hacker arrested for breaching 90 organizations - Despite the large number of breaches, Group-IB says the hacker did not perform significant lateral movement, instead focusing on quick data exfiltration onto cloud servers and victim extortion. A suspected cyber criminal believed to have extorted ...
4 months ago Bleepingcomputer.com
Russian pro basketball player arrested for alleged role in ransomware attacks - Russian professional basketball player Daniil Kasatkin was arrested in France at the request of the United States for allegedly acting as a negotiator for a ransomware gang. This description closely matches similar language used by the ...
5 days ago Bleepingcomputer.com Hunters
Mideast Oil & Gas Facilities Could Face Cyber-Related Energy Disruptions - Middle East oil and gas operators will need to be vigilant about the risk of cyberattacks as the Israel-Gaza conflict continues, security experts warn, or else risk energy supply disruption globally. A recent report by S&P Global Ratings found that ...
1 year ago Darkreading.com
U.S. indicts Russian GRU hacker, offers $10 million reward - The U.S. indicted Russian national Amin Timovich Stigal for his alleged role in cyberattacks targeting Ukrainian government computer networks in an operation from the Russian foreign military intelligence agency prior to invading the country. The ...
1 year ago Bleepingcomputer.com
Detained Russian student allegedly helped Ukrainian hackers with cyberattacks - A Russian tech student could face treason charges for helping Ukrainian hackers carry out cyberattacks against Russia. A resident of the Siberian city of Tomsk, Seymour Israfilov was detained by Russian security services in October, but little ...
1 year ago Therecord.media
Maine Mass Shooting Disinformation Floods Social Media as Suspect Remains at Large - Following a mass shooting at a bowling alley and restaurant in Lewiston, Maine, yesterday evening that left at least 18 people dead, state police urgently warned residents to "Stay inside your home with the doors locked" as they mounted a manhunt for ...
1 year ago Wired.com
Over 300 arrested in international crackdown on cyber scams | The Record from Recorded Future News - In an international operation that stretched from last November to February, authorities from Benin, Côte d'Ivoire, Nigeria, Rwanda, South Africa, Togo and Zambia uncovered cross-border criminal networks that defrauded more than 5,000 victims. ...
3 months ago Therecord.media
Law enforcement conducts 'largest ever' botnet takedown - In the latest high-profile law enforcement action against cybercrime, agencies disrupted several notorious botnets and malware droppers widely used in ransomware attacks. Europol on Thursday announced that an international law enforcement action, ...
1 year ago Techtarget.com LockBit

Cyber Trends (last 7 days)