logo

Should retailers be worried after three major U.K. companies confirm cyber incidents?

ID: 839e2b34-a22e-57a0-811f-ff9e6acfd810

STIX ID: report--839e2b34-a22e-57a0-811f-ff9e6acfd810

Feed Name: Arctic Wolf

Threat Score
78/100

Date Published: 2025-05-29

Date Updated: 2026-07-26

Author: Nick Dyer

...
...

Since April 2025, multiple high-profile UK retailers (Marks & Spencer, Co-Op, Adidas, Harrods) were impacted by coordinated supply-chain attacks attributed to the financially motivated group Scattered Spider; attackers reportedly used employee phishing and third‑party/supply‑chain manipulation to gain access and in some cases control virtualised infrastructure, leading to service outages, consumer data exposure, and potential ransomware/extortion losses. The report emphasizes that these are not zero‑day-driven incidents but largely human‑led compromises of supply chains and externally facing services, warns of material financial and insurance implications, and recommends four pillars of defence (awareness, detection/response, vulnerability remediation, and tested IR plans) while describing Arctic Wolf’s Incident360 retainer as a response option.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.