Global Retail Under Siege: 58% Surge in Ransomware Attacks Hits Luxury Giants and UK Retail

Listen to this Post

Featured Image

Retail Industry on Red Alert

A chilling spike in ransomware attacks has rattled the global retail sector in Q2 2025, exposing major vulnerabilities in an industry already battling supply chain complexities, evolving consumer behavior, and intense competition. New data from cybersecurity firm BlackFog reveals a 58% increase in publicly disclosed attacks compared to the previous quarter — with UK retail brands experiencing the most aggressive targeting. Luxury powerhouses like Dior, Louis Vuitton, and Cartier, as well as household names such as M\&S, Harrods, and Adidas, have fallen victim to coordinated cyber offensives that threaten not only customer data but business continuity across the board. The rise is not isolated — it reflects a broader, systemic escalation of ransomware incidents globally, fueled by increasingly sophisticated threat actors and a lack of disclosure from affected organizations.

Retail Giants Targeted in Wave of Ransomware Strikes

In the second quarter of 2025, ransomware attacks against the global retail sector surged by 58%, with UK firms like Marks & Spencer (M\&S), The Co-op, and Harrods hit particularly hard. These high-profile incidents, all occurring in late April, have been linked to the notorious Scattered Spider group. The attacks inflicted serious operational disruptions and financial losses. On July 10, UK authorities arrested four individuals suspected of involvement. Other luxury and fashion retailers impacted during the period include Dior, Adidas, Louis Vuitton, Cartier, and Victoria’s Secret, underscoring the wide scale and sophistication of the threat.

According to BlackFog’s report released on July 16, the retail sector is increasingly appealing to ransomware groups because of its intricate supply chains and heavy dependence on continuous service — any interruption can cause enormous losses. The potential for rapid ransom payment and access to rich datasets, such as customer information and payment details, adds to the appeal for attackers.

The global scope of the crisis is alarming. Compared to the same quarter in 2024, ransomware incidents rose 63%, with 276 attacks reported. April and May each recorded record-breaking numbers, with 89 and 91 attacks respectively — the highest for those months since 2020. In 95% of cases, attackers not only encrypted data but also exfiltrated it. Healthcare topped the list of targeted industries (52 attacks), followed by government (45) and services (33).

Fifty-three distinct ransomware groups were identified, with Qilin leading the charge (28 attacks), followed by INC Ransom, Interlock, Akira, and Medusa. Notably, 35% of attacks went unclaimed. The geographic spread was vast, touching 88 countries including smaller nations like Tonga, Haiti, Fiji, and Barbados.

Alarmingly, most incidents remain hidden. The report identified 1,446 attacks that were not publicly disclosed, a 19% increase over Q2 2024. For every 100 incidents, only 19 are revealed. Qilin was again the most active in this shadowy category. The services and manufacturing sectors had the highest number of unreported breaches. M\&S chairman Archie Norman even told the UK Parliament he personally knew of major attacks that never made headlines. BlackFog’s data confirms that endpoint-based data exfiltration remains a core method of operation for all ransomware actors.

What Undercode Say:

The Strategic Shift Toward Retail

Ransomware attackers have clearly identified retail as a high-value, high-leverage industry. The combination of sensitive consumer data, financial records, and complex logistical operations creates a perfect storm where even brief service outages can lead to severe reputational and financial damage. Cybercriminals are banking on urgency. When companies are desperate to restore operations, they are more likely to pay ransom quickly — a trend that emboldens future attacks.

UK’s Vulnerability and Global Implications

The UK, with its concentration of legacy brands and digitally transforming retail giants, has emerged as ground zero in Q2 2025. The targeting of M\&S, Harrods, and The Co-op within a short time frame suggests coordinated planning, not opportunistic strikes. This signals a need for not just stronger cybersecurity tools but also public-private collaboration on threat intelligence and rapid incident response.

Data Theft Over Data Lockdown

The overwhelming majority of attacks (95%) now involve data exfiltration, a shift that reveals cybercriminals are not just interested in encrypting files but in selling or weaponizing stolen data. This approach raises stakes dramatically, especially in industries where brand trust is a key business asset. A breach that exposes customer addresses, credit card numbers, or purchase histories can lead to years of lost loyalty and legal battles.

The Disclosure Gap Is Dangerous

With over 1,400 attacks going unreported in Q2 alone, transparency remains a critical issue. Lack of public disclosure prevents broader industry awareness and limits opportunities for collective defense. More worryingly, it hinders regulators and law enforcement agencies from accurately tracking threat actors and trends. The fact that M\&S’s chairman testified about undisclosed attacks is a red flag for systemic underreporting, possibly driven by fear of stock market backlash or brand damage.

Rise of Qilin and Fragmented Threat Actor Landscape

The resurgence of groups like Qilin, along with the fragmented activity of 50+ other ransomware gangs, shows just how decentralized and resilient the ransomware ecosystem has become. While law enforcement made progress with arrests linked to the April UK attacks, the sheer number of actors in play makes it difficult to stem the tide. Many groups go unclaimed, suggesting either splinter cells or deliberate anonymity to avoid traceability.

Globalization of Threats

The spread of ransomware to nations like Tonga and Haiti underscores how cybercrime has truly gone global. No longer limited to Western economies, ransomware is infiltrating regions with weaker cybersecurity infrastructure. This reflects a broader trend of democratization in cybercrime — where ransomware-as-a-service models allow less technically skilled criminals to buy access to sophisticated tools.

Retail’s Digital Transformation Is a Double-Edged Sword

Retail’s fast-track digitalization post-COVID — with e-commerce, mobile payments, and cloud-based supply chains — has expanded attack surfaces. While necessary for growth and efficiency, these technologies introduce vulnerabilities that, when not adequately protected, become doorways for ransomware.

Time for Policy and Cyber Insurance Reform

Governments and regulatory bodies need to revisit laws around ransomware reporting and ransom payments. Companies must also rethink their cyber insurance strategies, especially as insurers tighten conditions due to escalating threats. Coverage limitations, rising premiums, and policy exclusions could soon leave firms more exposed than they realize.

🔍 Fact Checker Results:

✅ 58% surge in ransomware attacks on retail confirmed by BlackFog
✅ M\&S, Harrods, and Co-op were attacked in April 2025
✅ 1,446 ransomware attacks went unreported globally in Q2 2025

📊 Prediction:

🛡️ The retail sector will likely face an even sharper increase in targeted ransomware attacks in Q3 and Q4 2025 as attackers exploit seasonal shopping spikes and exploit new vulnerabilities in POS systems and cloud integrations. We predict over 2,000 undisclosed incidents by year-end, with Qilin and emerging threat groups dominating. Expect new mandates around breach disclosure and an increase in high-profile cyber-insurance litigation.

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub:
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin