Skip to main content

Harrods restricts Internet access after detecting intrusion attempts

Harrods reported unauthorised access attempts to certain systems and restricted Internet connectivity at its sites as a preventive measure, just days after the M&S and Co-op incidents.

CybersecuritySeintec Team2-3 min read
Harrods restricts Internet access after detecting intrusion attempts

News summary

Harrods reported unauthorised access attempts to certain systems and restricted Internet connectivity at its sites as a preventive measure, just days after the M&S and Co-op incidents.

When several companies within the same sector are attacked, it is advisable to immediately review credentials, help desk, remote access, providers, and alerts instead of waiting to become the next victim.

Source: Reuters — 1 May 2025

What happened

On 1 May 2025 Harrods reported attempts of unauthorised access to some of its systems and, as a preventive measure, restricted internet connectivity at its sites. The announcement came just days after similar incidents at Marks & Spencer and Co-op, suggesting a wave of attacks against the British retail sector.

Harrods did not confirm an impact equivalent to that of its competitors at the time; the connectivity restriction was presented as a preventive containment measure, not confirmation of a breach with compromised data.

What it means for a mid-sized business

When several companies in the same sector are attacked within a short period, it usually indicates that a particular group or technique is succeeding against that type of organisation, not that these are isolated cases.

For a business in the same sector, or one with a similar profile (physical and online sales, a recognisable brand, many staff with access to support), the right reaction is not to wait to become the next victim, but to immediately review the same points that failed in the known cases.

What to review

Facing a wave of attacks against your own sector, urgently review:

  • Identity-verification processes at the help desk and access support.
  • Credentials and passwords for privileged accounts, rotating them if there are signs of risk.
  • Remote access and third-party provider access, checking permissions and real need for each.
  • Active security alerts and the ability to detect anomalous access in real time.

Frequently Asked Questions

Did Harrods confirm a data breach?
In the initial announcement, the company referred to unauthorised access attempts and a preventive connectivity restriction, without confirming at that time a data breach equivalent to other affected retailers.
Why were several UK retailers attacked almost at once?
Sector reporting pointed to a common social-engineering pattern against support services, which appears to have affected several chains within a short period.
What should a business do when it sees competitors being attacked?
Immediately review its own identity-verification processes, remote access and security alerts, rather than assuming the risk does not apply to it.

At Seintec, we help companies transform these types of technological risks into realistic improvement plans. If you wish to review your situation, contact us and an expert will guide you.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.