DragonForce Ransomware Strikes: Harrods, M&S, Co-Op Among UK Retailers Hit

DragonForce Ransomware Strikes: Harrods, M&S, Co-Op Among UK Retailers Hit

Coordinated Cyber Onslaught Cripples Top UK Retailers

In a sweeping and methodical cyber campaign, a group known as DragonForce has unleashed a wave of ransomware attacks against some of the UK’s most prominent retailers. Marks & Spencer, Co-op, and Harrods are among the confirmed victims in what experts describe as one of the most disruptive assaults on British retail infrastructure to date.

Retail Disruption at Scale

Cybersecurity analysts from SentinelOne revealed that Marks & Spencer was compromised as early as February 2025. DragonForce deployed its ransomware payload against the retailer’s VMware ESXi systems, crippling core platforms responsible for e-commerce and payment processing. The fallout was immediate: online sales halted for five days, translating to a staggering £3.8 million in lost revenue each day and a market valuation dip of over half a billion pounds.

Meanwhile, the Co-op Group acknowledged a data breach on May 2nd, with unauthorized access to names and contact details of its membership base. While financial data and credentials reportedly remained secure, internal memos suggested that attackers may have infiltrated employee communications—prompting unusual safeguards such as mandatory video presence and real-time identity checks during virtual meetings.

On May 1st, luxury giant Harrods confirmed it had also been hit. In response, the retailer swiftly cut internet access across its network to contain the threat. Despite the incident, the flagship Knightsbridge store and satellite locations continued operating with minimal disruption.

Inside DragonForce: The Ransomware Engine Behind the Attacks

Once a Malaysia-based hacktivist collective, DragonForce has morphed into a full-fledged cybercrime enterprise offering ransomware-as-a-service (RaaS) to global affiliates. Their malware arsenal leverages high-grade encryption standards—AES-256, RSA, and more recently, ChaCha8—for rapid file locking.

Initial intrusion methods vary but commonly include phishing schemes, exploitation of unpatched software, and use of stolen credentials. Once inside a target’s environment, DragonForce actors deploy reconnaissance and privilege escalation tools such as Mimikatz, PingCastle, and Advanced IP Scanner. They are known to use sophisticated Windows API functions like DuplicateTokenEx() and CreateProcessWithTokenW() to seize SYSTEM-level control.

The ransomware toolkit is modular and highly configurable, supporting automated execution, file path targeting, and specialized scanning for ESXi hosts using command-line flags like -vmsvc and -paths.

Behind the Curtain: DragonForce’s Expanding Cybercrime Syndicate

Investigators have uncovered that attackers tied to the DragonForce ecosystem are actively exploiting high-impact software flaws—among them, the infamous Log4Shell (CVE-2021-44228), which remains a favorite entry point due to its widespread exposure.

Adding another layer of complexity, several incidents within the UK retail sector have been tentatively linked to “Scattered Spider”—a decentralized, loosely affiliated group of young, English-speaking cyber operatives. While independent, these actors reportedly rent DragonForce’s ransomware platform in exchange for a 20% share of any extorted payments, transforming DragonForce into less a single threat actor and more a sprawling cybercrime syndicate.

In a bold move earlier this year, DragonForce launched a white-label offering that allows affiliates to rebrand their attacks under new ransomware identities—effectively enabling them to mask attribution and confuse forensic investigators. This strategic pivot has prompted some experts to describe DragonForce as the backbone of a growing “Ransomware Cartel”—a service provider in the business of cyber extortion.

In response to the attacks, the UK’s National Cyber Security Centre (NCSC) issued a fresh advisory to retailers, urging them to harden defenses, patch known vulnerabilities, and enhance detection capabilities. Consumers were also advised to take immediate protective steps, including updating passwords and closely monitoring bank transactions for signs of fraud.

These incidents underline a sobering reality: ransomware threats are no longer isolated campaigns but part of a broader ecosystem of for-hire cybercrime, where technical sophistication meets scalable business models. In this new digital battleground, security is no longer optional—it’s existential.

More Articles & Posts