Four individuals aged between 17 and 20 were arrested in the United Kingdom in July 2025 in connection with the intrusions that disrupted Marks & Spencer, Co-op and Harrods earlier that year.
Set That Against What Those Incidents Cost
M&S reported a nine-figure operational impact, filed at 25-0430. Co-op lost the records of all 6.5 million members, at 25-0501. Harrods was targeted, at 25-0929.
The threat model that produces board-level security budgets is a resourced, organised, professional adversary. What arrived was a small number of teenagers with a telephone and a working knowledge of how help desks verify identity.
This Is The Third Time In This Corpus
The PowerSchool prosecution at 25-0521 concerned a single individual aged 20. The eleven-million-record public-sector file at 26-0420 involved a suspect still in school.
Three of the largest incidents in this database, and in each the party responsible was young, small, and using techniques that require no capital. The barrier to causing enormous damage is not capability. It is willingness — and the social-engineering route this desk files throughout requires only a plausible voice.
Which Does Not Make The Defence Easier
There is a comforting reading here — that the adversary is unsophisticated, and therefore beatable — which this desk does not accept.
An unsophisticated technique that works is not a lesser threat than a sophisticated one; it is a worse one, because it is available to far more people and cannot be countered by out-engineering it. The organisations affected had substantial security programmes. What they did not have was a service-desk process that could withstand a determined phone call.
Compiled from public reporting, listed below. Arrest is not conviction and no findings of guilt are asserted. This desk names individuals only after conviction; those arrested here are not named. Corrections: corrections@forensicpost.com.