Desk live·
ForensicPost
Ransomware/Enforcement/File 25-0724

Four Arrested Over M&S, Co-op and Harrods Intrusions

UK authorities arrested four people in July 2025 in connection with the intrusions at Marks & Spencer, Co-op and Harrods. The oldest was twenty.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUK retail campaign
ActorScattered Spider
D. Kennedy11 min readConfidence: high2 sources reviewed

Four individuals aged between 17 and 20 were arrested in the United Kingdom in July 2025 in connection with the intrusions that disrupted Marks & Spencer, Co-op and Harrods earlier that year.

Set That Against What Those Incidents Cost

M&S reported a nine-figure operational impact, filed at 25-0430. Co-op lost the records of all 6.5 million members, at 25-0501. Harrods was targeted, at 25-0929.

The threat model that produces board-level security budgets is a resourced, organised, professional adversary. What arrived was a small number of teenagers with a telephone and a working knowledge of how help desks verify identity.

This Is The Third Time In This Corpus

The PowerSchool prosecution at 25-0521 concerned a single individual aged 20. The eleven-million-record public-sector file at 26-0420 involved a suspect still in school.

Three of the largest incidents in this database, and in each the party responsible was young, small, and using techniques that require no capital. The barrier to causing enormous damage is not capability. It is willingness — and the social-engineering route this desk files throughout requires only a plausible voice.

Which Does Not Make The Defence Easier

There is a comforting reading here — that the adversary is unsophisticated, and therefore beatable — which this desk does not accept.

An unsophisticated technique that works is not a lesser threat than a sophisticated one; it is a worse one, because it is available to far more people and cannot be countered by out-engineering it. The organisations affected had substantial security programmes. What they did not have was a service-desk process that could withstand a determined phone call.

How we reported this

Compiled from public reporting, listed below. Arrest is not conviction and no findings of guilt are asserted. This desk names individuals only after conviction; those arrested here are not named. Corrections: corrections@forensicpost.com.

Sources
  1. Crackdowns and takedowns: disrupting ransomware in 2025S-RM
  2. What the 2025 Scattered Spider attacks reveal about modern cyber crimeGRC Solutions
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary