Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Four Arrested in UK Over M&S, Co-op Cyberattacks

Three teens and a woman have been arrested by the UK’s NCA over the hacking of M&S, Co-op and Harrods.

Hacker arrested

Four individuals have been arrested in the United Kingdom as part of an investigation into the recent cyberattacks targeting major retailers, the country’s National Crime Agency (NCA) announced.

The suspects are a 20-year-old woman and three males, two aged 19 and one aged 17. They were arrested in the West Midlands and London in the morning of July 10 at their homes.

They are suspected of hacking, blackmail, money laundering, and participation in an organized crime group. 

Police seized their electronic devices and the suspects remain in custody for questioning. 

The four are believed to have been involved in the recent cyberattacks on retailers Marks & Spencer (M&S), Co-op, and Harrods.

A ransomware group calling itself DragonForce took credit for the attacks and the cybersecurity industry has linked the hacks to the notorious cybercrime group named Scattered Spider. The hackers were later spotted targeting US retailers as well. 

Advertisement. Scroll to continue reading.

Law enforcement agencies around the world have been stepping up their efforts against the cybercrime group. The US charged and arrested several alleged members in late 2024, and one individual has pleaded guilty, but attacks have since continued.

A 22-year-old man from the United Kingdom was arrested last month in Spain over his alleged leadership role in the Scattered Spider group, but the security industry has since continued issuing warnings

Whether the recent arrests of alleged Scattered Spider members will have an impact on the group’s activities remains to be seen. However, Charles Carmakal, CTO of Google Cloud’s Mandiant Consulting unit, is optimistic.

“The arrests of alleged Scattered Spider members is a significant win in the ongoing fight against this collective,” Carmakal told SecurityWeek. “Their aggressive social engineering tactics and relentless pursuit of access have proven particularly challenging for many defenders, and resulted in considerable damage to organizations in the UK and US.”

“This action by law enforcement underscores the critical importance of international collaboration in combating cybercrime. Previous arrests have impacted their operations, causing a significant lull in activity. This is a critical window for organizations to fortify their defenses against this collective,” he added.

*updated with comments from Mandiant

Related: Hawaiian Airlines Hacked as Aviation Sector Warned of Scattered Spider Attacks 

Related: Alleged Chinese State Hacker Wanted by US Arrested in Italy

Related: British Man Suspected of Being the Hacker IntelBroker Arrested, Charged

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.