Harrods Cyber Incident 2025: When Identity Defenses Actually Work
The third target of the UK retail wave cut its own internet access, kept trading, and said almost nothing. The wave broke against it. Months later, 430,000 customer records left anyway, through a supplier Harrods has never named. Both halves are the story
Case type: Attempted intrusion / third-party data breach
Identified: Late Apr 2025; Sept 2025 Disclosed: May 1, 2025; Sept 26, 2025
Attribution: Wave linked to Scattered Spider / DragonForce; Sept actor unnamed
By the time the attackers reached Harrods, everyone knew they were coming. Marks & Spencer had been encrypted over Easter. Co-op had pulled its own plug days later. Harrods was third in line, and it did what third in line makes possible: it restricted its own internet access before the intruders could establish themselves, kept every store trading, and let the wave break against it.
Then it said almost nothing, and for four months that looked like the whole story: the quiet near-miss of the UK retail wave. In late September it stopped being the whole story. Roughly 430,000 Harrods customers began receiving notifications that their data had been taken, not from Harrods, whose systems held, but from a third-party supplier the company has never publicly named. This post covers both incidents, because together they make a point neither makes alone: you can win the fight you prepared for and still lose data through a door you outsourced.
The spring incident is the least-documented event in this series, which is itself a fact worth noticing. Attempts to gain unauthorized access to Harrods systems, later dated by the company to late April 2025, were detected as the retail wave crested. On May 1, Harrods confirmed the attempts and its response: internet access restricted across all sites, including the Knightsbridge flagship and its H Beauty stores, as a deliberate precaution, the same self-imposed-degradation play Co-op had run days earlier, executed here before establishment rather than after. Stores and online sales kept operating. Reporting linked the attempt to the same Scattered Spider and DragonForce ecosystem as the M&S and Co-op attacks, and the National Crime Agency's July arrests covered all three retailers' cases. Harrods itself never confirmed the attribution, the vector, or any data loss. There has never been evidence the attempt succeeded.
The autumn incident inverted everything about the spring. On September 26, Harrods began notifying approximately 430,000 customers, largely its online shoppers, a fraction of a customer base that mostly buys in store, that their data had been taken in a breach at one of its third-party providers. The exposed records held names and contact details, and possibly marketing data such as Harrods membership tier and co-branded card affiliation, but no passwords, payment data, or order histories. Harrods was emphatic on two points: none of its own systems were compromised, and the incident was unconnected to the spring attempt. Within days it confirmed the threat actor had made contact, and answered publicly: “We will not be engaging with them.” Reports followed of the actor contacting affected customers directly, the extortionist's next move when the company won't pick up. The NCSC and Metropolitan Police opened investigations, Harrods pledged a review of its vendor relationships, and to this day, neither the supplier nor the actor has been publicly named.
The wave you see, and the door you don't
Harrods' year is this series in miniature. The spring showed what preparation, sector-wide warning, and decisive self-restriction can do: the same ecosystem that encrypted M&S and stole Co-op's entire membership base got nothing here that anyone can point to. The autumn showed the boundary of all of it. Vigilance, sequence, and a willing trigger finger defend your network. They do not defend the copies of your customer data sitting in a supplier's systems, where your monitoring doesn't reach and your incident response doesn't get a vote.
The front door held. The data left through a vendor anyway.
This is the third time this series has watched data exit through a trusted third party: Caesars through a vendor's help desk, thousands of MOVEit victims through a product their vendors' vendors ran, and now Harrods through a supplier it won't name. The pattern is now common enough that reporting around this incident cited supply chain compromise as a driver of a large share of modern extortion attacks. The perimeter organizations actually have is the union of every vendor holding their data, and most organizations have never drawn that map.
Third in line, and ready because of it
One underappreciated reason Harrods' spring went well: it went third. M&S's disaster bought Co-op hours of warning; Co-op's response bought Harrods days. By the time the attackers turned to Knightsbridge, the sector's alarm was ringing, the playbook was in the newspapers, and the precautionary self-restriction that would have looked drastic three weeks earlier looked obvious. That's a real defensive mechanism, the sector functioning as an immune system, and it only works when early victims disclose fast and specifically. Which is what makes Harrods' own near-silence, legitimate as a legal and brand strategy, worth weighing honestly: quiet victims consume the sector's shared learning without replenishing it. Co-op's CEO went on national television with specifics; Harrods issued statements measured in sentences. Both are defensible postures. Only one of them helps whoever is fourth in line.
Not one decision. A set of conditions.
Harrods' split year, a repelled direct assault and a lost vendor-side dataset, was set by four conditions:
When the company won't talk, they call the customers
The September actor's follow-through deserves its own note. Refused by Harrods, the attackers reportedly began contacting affected customers directly, converting a corporate extortion into hundreds of thousands of personal ones. It is the same escalation Clop pioneered at scale after MOVEit and 23andMe's attacker attempted with ethnicity-sorted lists: when the organization holds firm, the pressure moves to the people in the data. Organizations planning their own refusal posture, rightly, in most cases, need to plan for this second act: warning affected individuals early, telling them exactly what the data could and couldn't enable, and giving them a channel to report contact attempts. A refusal strategy that doesn't include the customers is only half written.
"Quiet Is Not the Same as Safe."
Harrods' 2025 splits cleanly into the incident it controlled and the one it couldn't. The spring belongs on the short list of defensive successes in this series: warned by the wave, it acted before the attempt became an intrusion and paid for the win only in restricted connectivity and a few careful statements. The autumn is the counterweight: 430,000 customers exposed through a supplier, an extortionist rebuffed and redirected at the customers themselves, and a vendor review that arrived as a consequence rather than a control.
Together they close this series' UK retail chapter with its clearest lesson. Defending the organization and defending the data are no longer the same project. One lives inside your walls and rewards vigilance, sequence, and nerve. The other lives wherever your vendors put it, and it rewards only the mapping, contracting, and oversight done before anyone calls. Harrods won the first project in April. Nobody had fully scoped the second, and in September it billed.
BECAUSE REPELLING THE ATTACK YOU SAW COMING ONLY COUNTS UNTIL THE DOOR YOU OUTSOURCED OPENS.
Sources
The Register, "Harrods blames its supplier after crims steal 430k customers' data in fresh attack," September 29, 2025: https://www.theregister.com/2025/09/29/harrods_blames_thirdparty_supplier_after
ITPro, "Harrods rejects contact with hackers, after 430,000 customer records stolen from third-party provider," September 29, 2025: https://www.itpro.com/security/harrods-rejects-contact-with-hackers-after-430-000-customer-records-stolen-from-third-party-provider
Cybernews, "Harrods' third-party breach exposes 430,000," September 30, 2025: https://cybernews.com/news/uk-harrods-third-party-breach-430000-customers-impacted-second-retail-attack/


Comments