Four Arrested in Cyberattacks Targeting M&S, Co-op, and Harrods

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

NCA Arrests Suspects Linked to Major Cyberattacks on UK Retailers

The UK’s National Crime Agency (NCA) has made significant strides in the fight against cybercrime by apprehending four individuals believed to be behind a series of cyberattacks targeting prominent retailers such as Marks & Spencer (M&S), Co-op, and Harrods. The arrests took place on July 10, 2025, in the West Midlands and London, marking a critical phase in an ongoing investigation into these disruptive activities that began earlier in the year.

Profile of the Suspects

The four suspects encompass a diverse age range, including two 19-year-old males, a 17-year-old male, and a 20-year-old female. Their charges are serious, involving violations under the Computer Misuse Act, blackmail, money laundering, and participation in an organized crime group. Notably, one of the detained individuals is a 19-year-old from Latvia, while the others are British nationals.

Coordinated Police Actions

Early morning raids at the suspects’ residences were executed in a synchronized manner, resulting in the seizure of several electronic devices intended for digital forensic analysis. Residents in Staffordshire reported seeing a substantial police presence, with officers wearing balaclavas breaching doors and gathering evidence. This operation was supported by both the West Midlands Regional Organized Crime Unit and the East Midlands Special Operations Unit, underscoring the collaborative effort to dismantle organized cybercrime networks.

NCA’s Statement on Ongoing Investigations

Paul Foster, the Deputy Director and head of the NCA’s National Cyber Crime Unit, emphasized that these arrests represent a “significant step” in an investigation that remains a top priority. He highlighted the agency’s commitment to working with both UK and international law enforcement partners to ensure that all individuals accountable for these cyberattacks will be pursued and prosecuted. Foster acknowledged the detrimental impact these crimes can have on businesses and praised retailers like M&S, Co-op, and Harrods for their cooperation throughout the investigation.

“Cyberattacks can be hugely disruptive for businesses,” Foster remarked, urging future victims to proactively engage with law enforcement. He assured affected parties that the NCA, along with local policing agencies, is well-equipped to assist in such situations.

Consequences of Cyberattacks on Major Retailers

The cyberattacks, which commenced in mid-April 2025, have significantly impacted the operations of affected retailers. Co-op has faced weeks of empty shelves as supply chains were disrupted, while M&S indicated that some IT systems may not be fully restored until as late as October or November. The retailer anticipates suffering estimated losses of around £300 million in profits, with the chairman explicitly describing the incident as a “deliberate attempt to destroy the business.”

Resources for Victims of Cybercrime

In light of these events, victims of cybercrime are encouraged to utilize the Government’s Cyber Incident Signposting Site, which provides essential guidance on reporting incidents and accessing support. This initiative aims to enhance coordination between businesses and law enforcement, ensuring that victims can effectively navigate the aftermath of such attacks.

The recent arrests serve as a powerful reminder that retail cyberattacks are being taken seriously by authorities. However, as these cyber threats continue to evolve, persistent investigations, advanced forensic responses, and cooperative efforts will be vital in safeguarding UK retailers and consumers alike against future cyber threats.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability On May 24, 2026, Roundcube issued a critical security advisory addressing vulnerabilities in its webmail product....

Australia and New Zealand sign Plan Tasman to enhance naval cooperation

The Royal Australian Navy and Royal New Zealand Navy have reinforced their enduring maritime partnership through the signing of Plan Tasman. Royal Australian Navy press...

Fake LastPass Authenticator Installer Uses Microsoft-Signed Driver to Disable Security Software and Steal Passwords

A fake LastPass Authenticator installer available on GitHub has been found to install a Windows kernel driver that disables antivirus and other security software,...

Air Force retires EC-130H Compass Call, replacing it with EA-37B

WASHINGTON — The Air Force has formally retired the EC-130H Compass Call, concluding over 40 years of operations for this electronic attack aircraft. The...