Harrods restricted internet access after attempted intrusion on its systems
- Organization
- Harrods
- Exploit
- Hacking
- Industry
- Retail
Harrods confirmed on 1 May 2025 that it had recently detected attempts to gain unauthorised access to some of its systems, making the London luxury department store the third major UK retailer in little over a week to disclose a cyber incident.
The company said its IT security team acted immediately and restricted internet access across its sites as a containment measure. Harrods reported no interruption to trading. The Knightsbridge flagship, the H beauty stores and its airport outlets all stayed open, and harrods.com continued to take orders.
The retailer did not say when the intrusion attempts began, which systems were targeted, whether ransomware was involved, or whether any customer or employee data had been reached. It said it was working with external experts on the investigation and declined to give further detail.
The UK National Cyber Security Centre said it was supporting Harrods alongside Marks and Spencer and the Co-op Group, both of which had disclosed intrusions days earlier. Contemporary reporting linked those two incidents to the DragonForce ransomware operation and to affiliates associated with the Scattered Spider cluster, but no group publicly claimed the Harrods attack and Harrods made no attribution of its own. NCSC chief executive Richard Horne described the run of retail incidents as a wake-up call for British organisations.