UK police arrest four people, a 20-year-old woman and three men aged 17 to 19, in connection to the M&S and Co-op hacks that began in mid-April and caused havoc
Dunno, not making a particular point, other than that I've been around for ages. Don't cause havoc kids, at least not in these kinds of ways. [embedded post] Eric Geller / @ericjgeller.com : British authorities today arrested four young people suspected of hacking U.K. retailers Marks & Spencer, Co-op, and Harrods. Cyber experts linked the attacks (and others on insurance companies, aviation firms, and U.S. retailers) to Scattered Spider. www.nationalcrimeagency.gov.uk/news/ retail-... … Graham Cluley / @grahamcluley.com : It's a stark reminder that major UK businesses remain prime targets for cybercriminals. — More details here: www.bbc.co.uk/news/article... Catalin Cimpanu / @campuscodi.risky.biz : These arrests are the definition of “don't shit where you eat” [embedded post] Paul Bernal / @paulbernal : So often the suggestion is made that these are ‘sophisticated’ hacks from foreign hacking teams, but the reality is often young British kids. — “Four arrested in connection with M&S and Co-op cyber-attacks” www.bbc.com/news/article... Cynthia Brumfield / @metacurity.com : Holy sh*t. [embedded post] Mastodon: Kevin Beaumont / @GossiTheDog@cyberplace.social : 17 and two 19 year old teens picked up over Co-op and M&S hacks, and a 20 year old woman. — Pretend to be surprised. — https://www.bbc.com/... X: @nca_uk : Four people have been arrested in the UK as part of a National Crime Agency investigation into cyber attacks targeting M&S, Co-op and Harrods. Read the full story ➡️ https://www.nationalcrimeagency.gov.uk/ ... [image] Sam Stepanyan / @securestep9 : #ScatteredSpider: 3 teenagers aged 17-19 and a 20-year-old woman arrested in the UK this morning in connection with cyber attacks on Marks & Spencer (M&S) and Co-op retail chains in April-May this year (luxury store Harrods was also affected): 👇 Greg Young / @orangeklaxon : Unusual that attackers are in the same country as the victims. Troy Hunt / @troyhunt : The @NCA_UK have picked up 4 people in relation to the recent retail hacks, most of them still just teenagers https://nationalcrimeagency.gov.uk/ ... Chris Stokel-Walker / @stokel : These arrests are only on suspicion of offences of course but regardless of those arrested's innocence or guilt, the speed at which arrests have come is really quick compared to previous allegations around cybercrime John Hultquist / @johnhultquist : Four UK arrests in Scattered Spider incidents. Suspects are 17 to 20 years old. https://therecord.media/... Forums: Hacker News : Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods r/cybersecurity : Four arrested in connection with M&S and Co-op cyber-attacks Beehaw : Four arrested in connection with M&S and Co-op cyber attacks
Context & Ripple Effects
The arrests follow a spring sequence in which M&S disclosed that customer data had been taken after its cyberattack, while Co-op and Harrods also reported incidents. The M&S disclosure made the episode a customer-data and retail-operations issue, not merely an attempted intrusion: M&S confirmed customer data was taken.
Authorities and security researchers have connected the retailer incidents to the Scattered Spider label, alongside reported activity affecting insurance, aviation, and U.S. retail targets. That makes the arrests a consequential test of whether law enforcement can translate campaign-level attribution into individual cases.
First-order effects
- The National Crime Agency’s arrests move the M&S and Co-op cases into an active suspect-led investigation, potentially enabling investigators to seek evidence tied to the alleged intrusions.
- M&S, Co-op, and Harrods gain a clearer law-enforcement response after the earlier M&S customer-data theft disclosure, though the arrests do not by themselves resolve the affected companies’ recovery or customer-data obligations.
Second-order effects
- A case connecting suspects to multiple retailers could help investigators map shared tactics and infrastructure across the reported cluster, improving coordination among affected businesses and authorities.
- The alleged links to attacks beyond UK retail raise the stakes for organizations in insurance, aviation, and U.S. retail that may assess whether their incidents share a common threat actor or methods.
Third-order effects
- If authorities substantiate the alleged connections, the episode would reinforce a shift from treating each breach as an isolated corporate incident toward investigating coordinated, cross-sector cybercrime campaigns.
- The outcome will also test the durability of public threat-actor attribution: arrests can strengthen confidence in a campaign label if evidence is presented, while weak cases would underscore its limits.
The trend: This is one data point in the growing effort to convert cyberattack clustering and threat-intelligence attribution into cross-border criminal enforcement cases.