ZeroFox Intelligence Flash Report - Series of Cyberattacks Target UK Retail Organizations
|by Alpha Team

ZeroFox Intelligence Flash Report - Series of Cyberattacks Target UK Retail Organizations
Product Serial: F-2025-05-06a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on a series of recent cyberattacks targeting UK-based retail organizations, as well as the alleged involvement of the ransomware-as-a-service collective DragonForce.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- A series of prominent cyber incidents have targeted UK-based retail organizations in recent days, with Marks & Spencer (M&S), The Co-operative Group (Co-op), and Harrods allegedly implicated.
- DragonForce, a ransomware & digital extortion (R&DE) collective that operates as-a-service within deep and dark web (DDW) forums, has claimed responsibility for the attacks.
- As of the writing of this report, DragonForce’s dark web [.]onion victim leak page is inaccessible, and it is unknown if M&S, Co-op, or Harrods have been named on the site.
- If DragonForce is responsible for these attacks and its extortion attempts are unsuccessful, there is a very likely chance that stolen data will begin to be published to the collective’s leak site in the coming weeks.
Tags: tlp:clear, dark web, eu/russia, DDW Ransomware