M&S, Co-op, and Harrods 2025: Scattered Spider, a Phone Call to the Help Desk, and £440 Million
Breach Summary
Between April 22 and May 1, 2025, three of the most recognizable retailers in Britain — Marks & Spencer, the Co-operative Group, and Harrods — disclosed cyber incidents within nine days of each other. The Cyber Monitoring Centre later classified the M&S and Co-op events as a single combined cyber event with a financial impact between £270 million and £440 million.
The access method was the same at each: a phone call to an outsourced IT help desk, an English-speaking caller with a plausible story about a locked-out employee, and a multi-factor authentication reset granted to an attacker. M&S lost online ordering for six weeks. The tradecraft on display in April 2025 is the same tradecraft that reached Apollo Global Management in July 2026.
What Happened
Marks & Spencer. Customers reported disruption to Click & Collect and in-store returns beginning April 21, 2025. M&S confirmed a cyber incident on April 22. Within days the retailer suspended all online and telephone orders and sent warehouse staff home as inventory management systems went down. On May 7 the company confirmed customer data had been accessed — names, email addresses, dates of birth, and order history. Passwords and payment card details were not compromised. Online ordering resumed in stages beginning June 10, after 46 days. M&S later quantified the impact at roughly £300 million.
Co-operative Group. Co-op detected suspicious activity on April 30 and proactively shut down critical IT systems across its retail and banking operations to contain the intrusion. The shutdown was a defensive choice made under pressure, and it worked: the containment limited the damage while imposing significant operational cost.
Harrods. On May 1 the luxury retailer confirmed it had been targeted and had restricted internet access across store facilities as a precaution. Harrods stated the attack was contained early with no customer data accessed and no interruption to store or online operations.
In June 2025 the Cyber Monitoring Centre — the UK non-profit established by the insurance industry to categorize major cyber events — assessed the M&S and Co-op incidents as a single combined cyber event, citing one threat actor claiming responsibility for both, the close timing, and matching tactics. It classified the event as Category 2 systemic, with a total financial impact estimated between £270 million and £440 million. Harrods was excluded from the assessment for lack of sufficient information about cause and impact.
On July 10, 2025, the National Crime Agency arrested four individuals — a 20-year-old woman, two 19-year-old men, and a 17-year-old — on suspicion of Computer Misuse Act offences, blackmail, money laundering, and participation in an organised crime group.
Attack Vector Detail
The vector was help desk social engineering, executed by phone.
The attacker calls the target's IT service desk claiming to be an employee — typically one with enough seniority to justify urgency and enough public footprint that name, department, and reporting line are recoverable from LinkedIn. The story involves a locked account, a lost phone, or a failed MFA enrollment. The caller is fluent, patient, and unremarkable. The help desk agent, whose job is to restore access quickly, resets multi-factor authentication on the account.
At M&S, the help desk was operated by an outsourced IT services provider. Reporting indicated the account whose MFA was reset held privileged access. From there the attackers reached domain administrator, the customer database, and the operational capability to deploy ransomware.
Two structural observations. First, the identity provider was never defeated. M&S's identity management was strong enough that a direct technical attack would have been substantial work. The help desk was reachable by anyone with a phone. Second, outsourcing the help desk outsourced the verification standard without transferring the consequence. The provider's agents were following their own procedures. Those procedures were not built to withstand a targeted, well-researched impersonation of a specific employee.
This is the same attack chain documented in Cloudskope's technical analysis of the 2026 Wall Street wave: How a Phone Call Beats MFA.
Breach Pattern Timeline
- April 21-22, 2025 — M&S customers report disruption; M&S confirms a cyber incident on April 22.
- April 25, 2025 — M&S suspends online and telephone orders; warehouse operations disrupted.
- April 30, 2025 — Co-op detects suspicious activity and proactively shuts down critical IT systems.
- May 1, 2025 — Harrods restricts internet access across store facilities after detecting an attempted intrusion.
- May 5, 2025 — Reporting identifies help desk password and MFA reset manipulation as the shared access method.
- May 6, 2025 — NCSC issues updated guidance emphasizing help desk verification standards and phishing-resistant MFA.
- May 7, 2025 — M&S confirms customer data was accessed.
- May 10, 2025 — NCSC and NCA publicly identify Scattered Spider as the primary suspect.
- June 10, 2025 — M&S resumes some online ordering after a 46-day suspension.
- June 2025 — CMC classifies M&S and Co-op as a single combined Category 2 systemic event, £270-440M.
- July 10, 2025 — NCA arrests four individuals aged 17 to 20.
- September 2025 — Jaguar Land Rover attacked; £1.9bn impact.
- July 2026 — Apollo Global Management compromised via the same help desk vishing pattern.
Executive Lessons
Five questions to answer this week:
- Who can reset MFA in our environment, and what do they verify first? If the answer is name, department, and manager, the procedure is defeated.
- Is our help desk outsourced? If so, what does the contract say about identity verification standards, and have we audited against it?
- Have we tested it? Commission an authorized social engineering assessment against your own service desk. The result is either reassurance or the most valuable finding of the year.
- Where is phishing-resistant MFA deployed, and where is it not? Privileged accounts and executives first.
- If an attacker held domain administrator for four hours, what is our detection and containment path? M&S was offline for six weeks.
Private Equity Implications
For sponsors with retail, consumer, or any operationally-dependent business in the portfolio, this event is the clearest available demonstration that cyber risk is operational risk, not an IT line item.
M&S did not lose data and continue trading. It lost the ability to sell online for six weeks during a period of otherwise strong growth. Co-op shut down critical systems proactively and absorbed the operational cost of that decision. The financial impact was denominated in lost trading, not in remediation cost or regulatory penalty.
The diligence implication is direct. A target's cyber exposure should be assessed against a business-interruption scenario, not only a data-breach scenario. The questions: how long could this company not transact? What is the daily gross margin at risk? Does the cyber insurance policy cover business interruption from a cyber event, and at what limit against that daily figure?
The second implication is help desk verification as a diligence line item. Any target using an outsourced IT provider with credential reset authority has handed the keys to a third party whose verification standard the target likely has never audited. That belongs in cyber due diligence, and it is cheap to check.
How Cloudskope Can Help
Cloudskope assesses exactly this exposure: help desk verification procedures, MFA reset paths, phishing-resistant authentication coverage, and privileged access blast radius. SARTUS™ covers identity posture and active-compromise indicators in a three-day assessment, then remediates what can be closed through configuration and policy correction in three more. Fixed fee, defined scope.
Frequently Asked Questions
What happened to Marks & Spencer, Co-op, and Harrods?
Between April 22 and May 1, 2025, all three UK retailers disclosed cyber incidents. Attackers called outsourced IT help desks impersonating employees and convinced agents to reset multi-factor authentication on privileged accounts, then used that access to reach domain administrator and deploy ransomware. M&S suspended online ordering for 46 days.
How much did the UK retail attacks cost?
The Cyber Monitoring Centre classified M&S and Co-op as a single combined Category 2 systemic event with a financial impact between £270 million and £440 million. Harrods was excluded from that assessment for lack of sufficient information. M&S alone quantified roughly £300 million in impact.
Who was responsible?
The NCSC and National Crime Agency publicly identified Scattered Spider — also tracked as UNC3944 and Octo Tempest — as the primary suspect. In July 2025 the NCA arrested four individuals aged 17 to 20 on suspicion of Computer Misuse Act offences, blackmail, money laundering, and participation in an organised crime group.
Did multi-factor authentication fail?
MFA was not technically defeated. It was administratively reset by a help desk agent who believed they were assisting a legitimate employee. This is why phishing-resistant MFA and hardened help desk verification are separate, complementary controls — the first protects the authentication, the second protects the reset path.
How does this connect to the 2026 attacks on Apollo and other financial firms?
The same tradecraft. The August 2026 vishing wave that compromised Apollo Global Management and targeted Blackstone, Bridgewater, and Bain Capital used help desk and employee impersonation by phone to capture credentials and authenticated sessions. UK retail in 2025 was the demonstration; Wall Street in 2026 was the escalation.
.png)