Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Threats, Incidents and Claims

Cyber Attacks on Retailers: How the 2025 UK Wave Got In

By the Assured Cyber Protection team · Updated 2026 · Reviewed
Cyber Attacks on Retailers: How the 2025 UK Wave Got In

The thing worth understanding about cyber attacks on retailers in Britain is that the 2025 wave did not start with clever malware. It started with a phone call. Attackers talked their way past a human being who had the authority to reset a password, and everything that followed, the encrypted servers, the halted online orders, the profit warning, ran downhill from that one conversation.

That matters because it changes what you should spend money on. A retailer with a well-patched estate and a help desk that will reset anyone’s credentials for a convincing caller is still wide open. This page sets out what actually happened, what separated the worst-hit victim from the one that got off lighter, and the controls that close the route.

What happened over Easter 2025

In late April and early May 2025, three household-name UK retailers were hit in quick succession: Marks & Spencer, the Co-op and Harrods. M&S was the worst affected, losing contactless payments, click and collect and then online ordering entirely for weeks.

Two names sit behind it. Scattered Spider, a loose, largely English-speaking group known for social engineering rather than technical exploits, is credited with the intrusions. DragonForce, a ransomware-as-a-service operation, supplied the encryption payload. M&S’s chairman told a House of Commons committee that the attack was likely the work of DragonForce working with Scattered Spider.

The important detail for anyone running a retail business: the ransomware was the last step, not the first. The attackers were inside, moving around and taking data long before anything was encrypted.

Why the Co-op came out of it better

Both M&S and the Co-op had DragonForce ransomware aimed at them. It only detonated at M&S. The Co-op shut its own systems down before the encryptors could be deployed, and while that meant days of empty shelves and manual processes, it avoided the far longer recovery that encryption forces.

That is the single most transferable lesson from the whole episode, and it is not a technology decision. It is a governance one: does someone in your business have the authority, at 2am on a bank holiday, to disconnect systems that generate revenue, without waiting for a committee? If the answer is no, you have already chosen the M&S outcome.

Write it into the incident plan by name and role, rehearse it, and make clear that a wrong call made quickly is forgiven. Attackers deliberately choose bank holidays and weekends because that is when the decision-maker is unreachable.

The four arrests, and why they do not make you safer

In July 2025 the National Crime Agency arrested four people in connection with the M&S, Co-op and Harrods attacks: two 19-year-old men, a 17-year-old man and a 20-year-old woman, on suspicion of offences under the Computer Misuse Act, blackmail, money laundering and participating in organised crime.

Two things follow from that. First, the profile is young and domestic, not a distant state actor, and the technique was persuasion. Second, ransomware-as-a-service means the tooling outlives any individual arrest: DragonForce rents its payload to affiliates, so removing one set of affiliates removes very little capability.

How common this actually is

The government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses, around 612,000 organisations, identified a breach or attack in the previous 12 months. The figure climbs with size: 65% of medium businesses and 69% of large businesses.

Phishing dominates, reported by 38% of businesses. Ransomware appears in only 1% of the survey, down from 3% in each of the two preceding years, which is easy to misread. Ransomware is rare per business and catastrophic per incident; the survey’s low percentage sits alongside a retail incident that ran to hundreds of millions in impact for a single company. Judge it on expected cost, not frequency.

The six controls that close this route

Ranked by how directly they would have interrupted the 2025 attacks.

1. Identity verification on the help desk. The entry point in these attacks was persuading support staff to reset credentials or enrol a new MFA device. Fix it with a scripted verification process the agent cannot skip, verification through a channel the caller did not choose (a callback to the number on record, or confirmation from a line manager), and a hard rule that urgency and seniority never shorten the process. Test it with your own social engineering attempt twice a year.

2. Phishing-resistant MFA on anything that matters. Codes sent by SMS and push notifications can both be defeated by a determined caller or a fatigue attack. Hardware keys or passkeys bound to the device cannot be read out over the phone. Prioritise administrators, finance, and remote access.

3. Control over supplier and contractor access. Retail estates run on third parties: EPOS support, logistics, ecommerce platforms, outsourced IT. Every one of those accounts is a way in that your own joiners and leavers process never touches. Inventory them, time-limit them, apply the same MFA standard, and check who still has access from contracts that ended.

4. Segmentation between corporate IT and trading systems. The commercial damage in 2025 came from tills, warehouses and online ordering going down, not from the corporate file server. If a compromise of head-office IT can reach store and distribution systems on a flat network, one intrusion stops the business trading. Separate them and an incident becomes expensive rather than existential.

5. Backups you have actually restored from. Offline or immutable copies, held where a compromised domain administrator cannot delete them, and a restore rehearsed against a real recovery time target. Plenty of businesses discover during an incident that their backups were also encrypted, or that a full restore takes three weeks.

6. A tested incident plan with named authority. Who declares an incident, who can pull systems offline, who talks to the ICO, who talks to customers, and where the plan lives when the network is down. Our cyber security risk assessment guide covers building this out, and Cyber Essentials is a reasonable floor for the technical controls above rather than a ceiling.

The regulatory clock starts fast

If personal data is involved, and in a retail breach it almost always is, you have 72 hours from becoming aware to notify the ICO. That clock runs from awareness, not from the end of your investigation, and “we were still assessing it” is not an accepted reason for a late report. Our 72-hour notification calculator works out the deadline from the moment you became aware.

Card data brings a second set of obligations. Since 31 March 2025 all of the PCI DSS v4.0 requirements are mandatory, with no fallback to the older standard, and forensic investigation and card scheme assessments are a retail-specific head of loss that general cover often sub-limits or excludes.

Where insurance fits, and where it does not

Insurance is the last control on the list, not the first, and the 2025 incidents showed why. Cover recovered a fraction of the total impact at M&S, and the Co-op held front-end incident response cover without the balance sheet protection behind it. Neither company was made whole.

Buy it for what it genuinely funds: incident response retainers, forensics, legal and notification costs, and business interruption if the definition is wide enough to include outages at systems you do not own. Our breakdown of cyber insurance for retailers goes through the sub-limits that decide the payout, and how to read a cyber insurance policy covers the clauses that quietly do the work.

One underwriting point worth knowing before renewal: insurers increasingly want evidence that controls are live rather than an annual self-attestation, and a compliance gap you cannot evidence can turn into a disputed claim.

Frequently asked questions

Why are retailers targeted so often in cyber attacks? Retailers combine large customer databases, card payment data, and trading systems where an hour of downtime has an immediate and public cost. That last point is what makes them attractive to extortion: the pressure to pay is measurable in lost sales every hour the tills are down.

How did the attackers get into M&S and the Co-op? Through social engineering rather than a technical exploit. The intrusions are attributed to Scattered Spider, which is known for persuading help desk and support staff to reset credentials or register new multi-factor devices. DragonForce ransomware was deployed afterwards.

Does having ransomware protection software prevent this? Not on its own. If an attacker holds valid credentials and multi-factor access, much of what they do looks like legitimate administration. Identity controls, supplier access hygiene and network segmentation matter more than any single security product.

Are small retailers at risk, or only the big chains? The survey figures show 42% of micro businesses and 46% of small businesses identified a breach or attack in the last 12 months. Smaller retailers are less likely to be individually targeted but far more likely to be caught by opportunistic phishing, and they usually have less capacity to absorb the downtime.

How long do I have to report a retail data breach? 72 hours from becoming aware of it, if personal data is affected. The clock starts at awareness, not at the point your investigation concludes, and you can submit an initial report and follow up with detail later.

Would cyber insurance have covered the 2025 retail attacks? Partly. Cover recovered a portion of the losses at M&S but nothing close to the full impact, and the Co-op described holding front-end incident response cover without the wider balance sheet protection. Insurance funds a response; it does not replace the controls that prevent the incident.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.