Four Hackers Arrested by UK Police for Attacks on M&S, Co-op and Harrods Stores

Digital devices confiscated for forensic analysis under the Computer Misuse Act, blackmail, money laundering, and organized crime charges. The charges under the Computer Misuse Act carry maximum sentences of 10 years imprisonment for unauthorized access with intent to commit further offenses, while the organized crime participation charges could result in additional penalties. Modern retail cyber attacks typically exploit SQL injection vulnerabilities, Cross-Site Scripting (XSS) flaws, or Remote Code Execution (RCE) exploits to gain initial network access. The NCA’s National Cyber Crime Unit has prioritized this investigation, deploying specialized analysts trained in Advanced Persistent Threat (APT) detection and attribution methodologies. The coordinated nature of these April attacks indicates possible deployment of Command and Control (C2) infrastructure, allowing attackers to maintain persistent access across multiple retail networks. Additional charges include blackmail, money laundering, and participation in organized crime activities, indicating the sophisticated nature of the alleged operation. The involvement of blackmail charges suggests potential ransomware deployment or threats of data exfiltration involving sensitive customer information, including payment card data and personal identifiers. The coordinated operation, conducted on July 10, 2025, targeted a cybercriminal group allegedly responsible for breaching the digital infrastructure of Marks & Spencer, Co-op, and Harrods in April 2025. This case highlights the growing threat of organized cybercrime against retail establishments and demonstrates law enforcement’s enhanced capabilities in digital forensics and threat attribution. Four suspects aged 17-20 arrested by the NCA in the West Midlands and London for April cyber attacks on M&S, Co-op, and Harrods. The arrests involved comprehensive digital forensic analysis protocols, with investigators seizing multiple electronic devices, including laptops, smartphones, and storage media. Investigators are likely analyzing network packet captures and system event logs to identify indicators of compromise, such as unusual DNS queries, suspicious SSL certificate usage, and abnormal data transfer patterns. Breaches exploited ERP and payment system vulnerabilities, involving ransomware, data theft, and command-and-control infrastructure.

This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 10 Jul 2025 16:20:14 +0000


Cyber News related to Four Hackers Arrested by UK Police for Attacks on M&S, Co-op and Harrods Stores

What is Proposition E and Why Should San Francisco Voters Oppose It? - In addition to removing certain police oversight authority from the Police Commission and expanding the circumstances under which police may conduct high-speed vehicle chases, Proposition E would also amend existing laws passed in 2019 to protect San ...
1 year ago Eff.org
CVE-2021-36845 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions < 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. ...
3 years ago
San Francisco Police's Live Surveillance Yields Almost 200 Hours of Spying-Including of Music Festivals - A new report reveals that in just three months, from July 1 to September 30, 2023, the San Francisco Police Department racked up 193 hours and 19 minutes of live access to non-city surveillance cameras. That means for the equivalent of 8 days, police ...
1 year ago Eff.org
Threatening Emails Rattle Bengal Schools: Police Pursue Latvia Lead - In a statement announced Tuesday, the Kolkata Police said that more than 20 schools across the city have been threatened with bombs, which have been later revealed as hoaxes. According to the sender, bombs had been placed in numerous classrooms ...
1 year ago Cysecurity.news
Four Hackers Arrested by UK Police for Attacks on M&S, Co-op and Harrods Stores - Digital devices confiscated for forensic analysis under the Computer Misuse Act, blackmail, money laundering, and organized crime charges. The charges under the Computer Misuse Act carry maximum sentences of 10 years imprisonment for unauthorized ...
4 weeks ago Cybersecuritynews.com
25 Best Managed Security Service Providers (MSSP) - 2025 - Pros & Cons: ProsConsStrong threat intelligence & expert SOCs.High pricing for SMBs.24/7 monitoring & rapid incident response.Complex UI and steep learning curve.Flexible, scalable, hybrid deployments.Limited visibility into endpoint ...
1 month ago Cybersecuritynews.com
Four arrested by UK police over ransomware attacks on M&S, Co-op and Harrods | The Record from Recorded Future News - Four individuals in Britain were arrested early on Thursday morning by the National Crime Agency on suspicion of involvement in a range of ransomware attacks targeting the British retail sector earlier this year. “Since these attacks took place, ...
4 weeks ago Therecord.media
Police dismantle pirated TV streaming network that made $5.7 million - Spanish police have dismantled a network of illegal media content distribution that, since the start of its operations in 2015, has made over $5,700,000. The investigation began in November 2022 following a complaint submitted by the Alliance for ...
1 year ago Bleepingcomputer.com
Victory! Police Drone Footage is Not Categorically Exempt From California's Public Records Law - Video footage captured by police drones sent in response to 911 calls cannot be kept entirely secret from the public, a California appellate court ruled last week. The police department is the first law enforcement agency in the country to use drones ...
1 year ago Eff.org
Four arrested in UK over M&S, Co-op, Harrod cyberattacks - As first reported by BleepingComputer, the cyberattacks were attributed to threat actors classified as Scattered Spider, with associated hackers tied to numerous breaches over the past few years, including ...
4 weeks ago Bleepingcomputer.com Scattered Spider Dragonforce
Harrods the next UK retailer targeted in a cyberattack - In a statement shared with BleepingComputer, Harrods says threat actors recently attempted to hack into their systems, causing the company to restrict access to sites. However, an internal email sent by Chief Digital and Information Officer Rob ...
3 months ago Bleepingcomputer.com Dragonforce Scattered Spider
Harrods the next UK retailer targeted in a cyberattack - In a statement shared with BleepingComputer, Harrods says threat actors recently attempted to hack into their systems, causing the company to restrict access to sites. However, an internal email sent by Chief Digital and Information Officer Rob ...
3 months ago Bleepingcomputer.com Scattered Spider Dragonforce
Police dismantles investment fraud ring stealing €10 million - “They persuaded their victims to make fake investments through a network of fake advisors and experts, manipulated websites, and telephone call centers,” the police says. In organized operations like the one dismantled by the Spanish ...
1 month ago Bleepingcomputer.com
500k Irish National Police records exposed by third party The Register - A third-party contractor running a database without password protection exposed more than 500,000 records related to vehicle seizures by the Irish National Police. Security researcher Jeremiah Fowler found various records dating back to 2017 ...
1 year ago Theregister.com
Ransomware hackers 'wreaking havoc' arrested in Ukraine - European cyber police have arrested a 32-year-old suspected of being the ringleader of a ransomware gang operating in Ukraine. In raids across the country authorities seized laptops and arrested four other alleged hackers. The gang are accused of ...
1 year ago Bbc.com
Dutch police breached by a state actor - “The police have been informed by the intelligence services that it is very likely a ‘state actor’, in other words: another country or perpetrators on behalf of another country.” reads the update on the data breach published ...
10 months ago Securityaffairs.com
Kelvin Security hacking group leader arrested in Spain - The Spanish police have arrested one of the alleged leaders of the 'Kelvin Security' hacking group, which is believed to be responsible for 300 cyberattacks against organizations in 90 countries since 2020. News of the arrest of a leader of the ...
1 year ago Bleepingcomputer.com
Hangzhou's Cybersecurity Breakthrough: How ChatGPT Elevated Ransomware Resolution - The Chinese media reported on Thursday that local police have arrested a criminal gang from Hangzhou who are using ChatGPT for program optimization to carry out ransomware attacks for the purpose of extortion. An organization in the Shangcheng ...
1 year ago Cysecurity.news
Feds Seize LockBit Ransomware Websites, Offer Decryption Tools, Troll Affiliates - U.S. and U.K. authorities have seized the darknet websites run by LockBit, a prolific and destructive ransomware group that has claimed more than 2,000 victims worldwide and extorted over $120 million in payments. Instead of listing data stolen from ...
1 year ago Krebsonsecurity.com LockBit
Brazilian police arrest IT worker over $100 million cyber theft | The Record from Recorded Future News - Local news outlets and the Associated Press reported on Friday that João Roque, an employee of C&M Software, was nabbed by police and told them he sold his login credentials to hackers who had approached him earlier this year. Police told the ...
1 month ago Therecord.media
Surge of swatting attacks targets corporate executives and board members - At around 8:45 pm on February 1, 2023, a caller to the Groveland, Massachusetts, 911 emergency line told dispatchers that he harmed someone in a home on Marjorie Street in the upscale small town 34 miles north of Boston. The caller also said he would ...
2 years ago Csoonline.com Cloak
Drone As First Responder Programs Are Swarming Across the United States - Police DFR programs involve a fleet of drones, which can range in number from four or five to hundreds. In response to 911 calls and other law enforcement calls for service, a camera-equipped drone is launched from a regular base to get to the ...
1 year ago Eff.org
9 Best DDoS Protection Service Providers for 2024 - eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More. One of the most powerful defenses an organization can employ against distributed ...
1 year ago Esecurityplanet.com
Major Retail Chains Suffer Data Breaches Amid Rising Cyber Threats to Consumer Trust - These incidents, occurring amid a 52% year-over-year rise in retail cyber vulnerabilities according to a 2025 survey, highlight the escalating risks facing an industry that processes billions of sensitive customer transactions annually. At M&S, ...
2 months ago Cybersecuritynews.com Hunters Scattered Spider
Spain arrests 34 cybercriminals who stole data of 4 million people - The Spanish National Police have dismantled a cybercriminal organization that carried out a variety of computer scams to steal and monetize the data of over four million people. Law enforcement in the country conducted 16 targeted searches in Madrid, ...
1 year ago Bleepingcomputer.com LockBit Ragnar Locker