In April 2025, thousands of shoppers were suddenly unable to complete their purchases at UK retailer Marks and Spencer.
The FTSE 100 group had been paralysed by a cyber attack, which resulted in charges of £131mn, sending shivers through corporate boardrooms across the UK.
However the assailants, who belonged to a hacking collective known as Scattered Spider, were not the usual type of “threat actor” but a new breed of cybercriminal: young, English-speaking and motivated by improving their reputation among fellow hackers rather than solely for financial gain.
The attack was one of a series of cybercrimes committed by perpetrators that fit a similar profile, including hits on Transport for London (TfL) and on UK retailers Harrods and the Co-Op. The trend has forced cyber experts to reassess the profile of criminals behind security breaches.
Over the past five years there has been a shift, says Rafe Pilling, a director of threat intelligence at the cyber security group Sophos, with the types of individuals and groups behind the attacks becoming more diverse.










