Desk live·
ForensicPost
Ransomware/Method/File 26-0415

UK Retail Attacks Classified as a Category 2 Systemic Event

The UK retail attacks were classified as a "Category 2 systemic event" — a hurricane-style severity scale applied to cyber incidents. Shared vocabulary is how a sector learns to price risk.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetIncident severity classification
ActorUnattributed
D. Kennedy9 min readConfidence: high1 source reviewed

The M&S and Co-op attacks were classified by UK analysts as a "Category 2 systemic event", explicitly borrowing the vocabulary used for hurricanes.

This desk grades severity on every file it publishes, so we have some sympathy with anyone attempting a scale. It is harder than it looks and worth doing anyway.

Why Cyber Has Lacked One

Natural catastrophe scales work because the phenomenon is physical and measurable independently of who it hits. Wind speed is wind speed.

A cyber incident has no equivalent intrinsic magnitude. The same technique produces a footnote at one organisation — as in the Google file in 26-0619 — and a national supply disruption at another. Severity is a property of the victim and the coupling around it, not of the attack.

What A Scale Buys

Insurers need to reserve against events rather than incidents. Regulators need to distinguish routine losses from systemic ones. Boards need to know whether what happened to a peer was a bad week or an existential quarter.

None of that is possible while every incident is described in the same adjectives. A scale forces the assessing body to commit to a number and to publish its reasoning, which is checkable in a way "sophisticated attack" never is.

The Obvious Failure Mode

Any scale becomes a target once it carries consequences. If a category determines regulatory attention or insurance treatment, the affected organisation acquires a strong interest in the number, and the assessment becomes a negotiation.

The protection is the same as for our own grading: publish the criteria, publish the reasoning, and let people argue with it. We would rather be told our Sev 4 was wrong than have nobody able to check.

How we reported this

This is a standards file. Compiled from public reporting on the classification, listed below. The comparison to our own grading is our commentary and is labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. M&S, Co-op attacks a ‘Category 2 cyber hurricane’, say UK expertsComputer Weekly
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary