{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail"},"incident":{"title":"Harrods restricts internet access after intrusion attempts in UK retail wave","date":"2025-05-01","date_precision":"day","victim_org":"Harrods","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"Harrods disclosed no technical detail, so no assessment of AI involvement is possible.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.","how_it_worked":"Harrods has never described the mechanics, so the entry attempt is characterised here only by the campaign it belonged to. The wave that hit UK retail in April and May 2025 was driven by English-speaking crews who phoned retailer service desks impersonating staff to obtain password and MFA resets, then escalated inside the identity provider. Harrods' response, cutting external internet access at sites while investigating, is consistent with defending against credential-based lateral movement rather than a software exploit, but the company has confirmed nothing further.","lessons":"Fast containment helped here, but the durable control against this campaign is out-of-band identity proofing before any help desk credential or MFA reset.","confidence":"Alleged","sources":[{"title":"Luxury department store Harrods suffered a cyberattack","url":"https://securityaffairs.com/177330/cyber-crime/luxury-department-store-harrods-suffered-a-cyberattack.html","publisher":"Security Affairs"},{"title":"Harrods alerts customers to new data breach linked to third-party provider","url":"https://securityaffairs.com/182752/data-breach/harrods-alerts-customers-to-new-data-breach-linked-to-third-party-provider.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail"}}