# UK police arrest four in cyberattack probe tied to Marks & Spencer, Co-op and Harrods

British authorities have arrested four people in connection with cyberattacks that targeted Marks & Spencer, Co-op and Harrods, bringing a new phase to an investigation that has rattled some of the country’s best-known retailers.

The National Crime Agency said the suspects were detained on suspicion of blackmail, money laundering, offences under the Computer Misuse Act and participation in an organized crime group. Police identified them as two British males aged 17 and 19, a 20-year-old British woman and a 19-year-old Latvian man.

The case has become one of the most closely watched cybercrime investigations in the U.K. because of the scale of disruption reported by the retailers. Marks & Spencer said an April attack stopped it from processing online orders, left store shelves empty and cost the company about 300 million pounds, or $407 million. Co-op said attackers stole customer personal data, disrupted payments and prevented shelves from being restocked. Harrods also faced restrictions on online access in May after it was unable to process orders.

The arrests suggest investigators are working from the theory that the attacks were not isolated incidents but part of a coordinated criminal operation. The NCA described the case as an organized crime ring, a framing that matches the charge profile and the scale of the disruption. The agency did not immediately disclose details of the alleged methods used in the attacks or whether any of the suspects had operational roles beyond the alleged conspiracy.

The investigation lands in a broader retail threat environment in which cybercriminals have repeatedly targeted firms with payment disruption, extortion and data theft. In this case, the apparent mix of business interruption and customer-data exposure raised the stakes beyond a standard systems outage. For retailers, the consequences can spill quickly into logistics, store operations and consumer trust.

The NCA said the arrests were linked to damaging attacks on the three chains, but it did not provide a public timeline for any future charges or court proceedings. For now, the central question is whether the arrests mark the start of a wider dismantling of the network behind the incidents or simply a first wave of custody in a still-developing case.

Retail cyberattacks have increasingly forced companies and law enforcement to treat digital intrusion as a physical-world business risk. In this case, the reported impact reached from online checkout systems to store inventory and customer data, giving the investigation significance well beyond the technology sector.

What happens next will depend on forensic evidence, interviews and any further arrests. But the latest move by British police shows the response to the attacks has now shifted from containment inside retail systems to criminal enforcement outside them.