Three teenage boys and one 20-year-old woman were arrested in raids across the West Midlands and London early this morning. The arrests come after a National Crime Agency investigation into the cyberattacks that hit Marks & Spencer, Co-op and Harrods in April.
“Since these attacks took place, specialist NCA cybercrime investigators have been working at pace and the investigation remains one of the Agency’s highest priorities,” said Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit.
“Today’s arrests are a significant step in that investigation but our work continues, alongside partners in the UK and overseas, to ensure those responsible are identified and brought to justice.”
We do not yet know the identities of the four suspects, only that their electronic devices have been seized for forensic analysis and that all still remain in custody. They are being held on suspicion of Computer Misuse Act offences, notably blackmail, money laundering and participating in the activities of an organised crime group.
Impact of the M&S cyberattacks
We have already written on the impact of the cyberattack on M&S in particular, with many systems remaining offline. The company is estimated to have suffered a ยฃ300 million loss.
Meanwhile the UK’s National Cyber Security Centre updated its guidance on how to combat ransomware.
Today, we heard from Spencer Starkey, Executive VP of EMEA at SonicWall, with further comments on how to prepare for such attacks, who points out that “there is still currently no definitive timeline for full recovery” for M&S despite its work.
“We have seen at SonicWall that organisations were under critical attack for an average of 68 days in 2024, highlighting the potential for prolonged recovery periods following sophisticated cyberattacks,” said Starkey.
The company’s 2025 Threat Report flagged a further sharp rise. “Threat actors are now exploiting vulnerabilities within 48 hours of disclosure – far faster than most organisations can patch – highlighting a growing gap between threat velocity and enterprise readiness,” he said. “Retail is one of the key targets for hacker groups and bad actors.”
Ransomware won’t affect retailers alone
So how can you counteract such attacks? First, don’t imagine that only retailers are being targeted.
“It’s vital every single business has a robust roadmap in place to deploy if and when an attack happens,” said Starkey. “The preparation always begins with prevention: layered security systems and updated employee training are basic principles in todayโs risky environment. Everyone involved should have a well-defined role and key responsibilities before the crisis occurs.”
He also flags the key nature of communication, both to customers and employees. “[The] company must always strive to keep those channels flowing both ways, to reassure people and organisations who might be affected that they are doing everything possible to recover from and resolve the incident.”