Desk live·
ForensicPost
Ransomware/Retail/File 26-0204

Harrods Targeted in the Same Scattered Spider Wave as M&S and Co-op

Harrods was targeted in the same wave as M&S and the Co-op. A crew working one sector in sequence is exploiting a shared supplier estate, not a shared weakness in the brands.

Constructed geometry · not a chart of case data
TargetHarrods
ActorScattered Spider
S. Rosler8 min readConfidence: medium1 source reviewed

Harrods was among the UK retailers targeted in the wave that included Marks & Spencer and the Co-op, and is named among the victims connected to the subsequent arrests filed in 26-0725.

Three prominent retailers in one market, in one window, by one crew. That is a targeting decision worth taking apart.

Sector-Sequential Targeting Is Efficient

Working a single sector concentrates reusable knowledge. Organisations in the same market use the same handful of outsourced service desk providers, the same retail platforms, the same logistics software, and frequently the same consultancies.

A call script refined against one retailer’s outsourced desk is likely to work against another’s, because it may be the same desk. Reconnaissance amortises across targets in a way it does not when an attacker moves between industries.

Which Makes Sector Information Sharing The Counter

If the adversary’s advantage is reuse across peers, the defensive counter is the same reuse in the other direction — and it depends on a retailer telling its competitors what happened, quickly, before the competitors are called.

That is a genuinely hard ask during an active incident, with lawyers advising silence and a market watching. It is also the only defensive mechanism that operates on the same timescale as the campaign.

Graded medium: the targeting is consistently reported, and per-retailer technical detail beyond the M&S account has not been published.

How we reported this

Compiled from public reporting, listed below. Incident detail specific to Harrods has not been disclosed publicly and we are not inferring it from the other cases. Corrections: corrections@forensicpost.com.

Sources
  1. Harrods, M&S hit by cyberattack: what happened, who’s behind it?Al Jazeera
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary