Desk live·
ForensicPost
Breaches/Actors/File 25-0512

Scattered Spider Worked UK Retail From April, Then Moved to US Retail

The cluster reported behind the 2025 retail intrusions worked UK retail from April, moved to US retail in late May, and moved on again. The rotation is the tell.

Constructed geometry · not a chart of case data
TargetRetail sector
ActorScattered Spider
D. Kennedy & S. Rosler12 min readConfidence: medium3 sources reviewed

Reporting attributes the 2025 retail intrusions to the loose cluster tracked as Scattered Spider, and describes a consistent shape: UK retailers from April, US retailers from late May, other sectors after that.

Sector Rotation Is A Research Artefact, Not A Preference

A group that works one industry at a time is not expressing an interest in groceries or jewellery. It is reusing research.

Social engineering against a service desk requires knowing what that desk expects: the identity-verification script, the vocabulary, the outsourcing arrangement, the name of the ticketing system. Within a sector those details repeat, because the same handful of vendors and the same handful of outsourcers serve everybody.

Learn one retailer’s help desk and you have substantially learned the sector’s. That is why the campaign moves in blocks and then jumps.

Which Means The Warning Is Legible In Advance

This is unusually actionable. Most of the threat intelligence in this database tells organisations what happened elsewhere without telling them what to do differently. Sector rotation says something narrower and more useful: when a peer in your industry is compromised through its service desk, you are inside the research window.

A Caution About The Label

"Scattered Spider" names a fluid set of individuals, not an organisation with a membership list. Techniques and infrastructure are shared across overlapping groups, and attributing a given intrusion to the name is a judgement about tradecraft resemblance rather than an identification.

This desk’s position, filed at 26-0429 and 26-0322, is that the label is useful for describing method and unreliable for counting incidents. Graded medium for that reason: the pattern is well evidenced, the boundary of the group is not.

This is an analysis file

Built on published reporting of the 2025 retail campaign, listed below, read against the incident files in this database. Attribution is as reported; we have not independently established it. Corrections: corrections@forensicpost.com.

Sources
  1. UK retail giant Co-op confirms hackers stole all 6.5 million customer recordsTechCrunch
  2. Why the world’s most prestigious retailers are facing a cybercrime waveBlackFog
  3. Retail under attack: 2025 cyber breaches hit Cartier, Louis Vuitton, M&S and moreSangfor
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary