NCA Arrests Suspects Linked to Major Cyberattacks on UK Retailers
The UK’s National Crime Agency (NCA) has made significant strides in the fight against cybercrime by apprehending four individuals believed to be behind a series of cyberattacks targeting prominent retailers such as Marks & Spencer (M&S), Co-op, and Harrods. The arrests took place on July 10, 2025, in the West Midlands and London, marking a critical phase in an ongoing investigation into these disruptive activities that began earlier in the year.
Profile of the Suspects
The four suspects encompass a diverse age range, including two 19-year-old males, a 17-year-old male, and a 20-year-old female. Their charges are serious, involving violations under the Computer Misuse Act, blackmail, money laundering, and participation in an organized crime group. Notably, one of the detained individuals is a 19-year-old from Latvia, while the others are British nationals.
Coordinated Police Actions
Early morning raids at the suspects’ residences were executed in a synchronized manner, resulting in the seizure of several electronic devices intended for digital forensic analysis. Residents in Staffordshire reported seeing a substantial police presence, with officers wearing balaclavas breaching doors and gathering evidence. This operation was supported by both the West Midlands Regional Organized Crime Unit and the East Midlands Special Operations Unit, underscoring the collaborative effort to dismantle organized cybercrime networks.
NCA’s Statement on Ongoing Investigations
Paul Foster, the Deputy Director and head of the NCA’s National Cyber Crime Unit, emphasized that these arrests represent a “significant step” in an investigation that remains a top priority. He highlighted the agency’s commitment to working with both UK and international law enforcement partners to ensure that all individuals accountable for these cyberattacks will be pursued and prosecuted. Foster acknowledged the detrimental impact these crimes can have on businesses and praised retailers like M&S, Co-op, and Harrods for their cooperation throughout the investigation.
“Cyberattacks can be hugely disruptive for businesses,” Foster remarked, urging future victims to proactively engage with law enforcement. He assured affected parties that the NCA, along with local policing agencies, is well-equipped to assist in such situations.
Consequences of Cyberattacks on Major Retailers
The cyberattacks, which commenced in mid-April 2025, have significantly impacted the operations of affected retailers. Co-op has faced weeks of empty shelves as supply chains were disrupted, while M&S indicated that some IT systems may not be fully restored until as late as October or November. The retailer anticipates suffering estimated losses of around £300 million in profits, with the chairman explicitly describing the incident as a “deliberate attempt to destroy the business.”
Resources for Victims of Cybercrime
In light of these events, victims of cybercrime are encouraged to utilize the Government’s Cyber Incident Signposting Site, which provides essential guidance on reporting incidents and accessing support. This initiative aims to enhance coordination between businesses and law enforcement, ensuring that victims can effectively navigate the aftermath of such attacks.
The recent arrests serve as a powerful reminder that retail cyberattacks are being taken seriously by authorities. However, as these cyber threats continue to evolve, persistent investigations, advanced forensic responses, and cooperative efforts will be vital in safeguarding UK retailers and consumers alike against future cyber threats.


