What happened
Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.
How the deception worked
Harrods has never described the mechanics, so the entry attempt is characterised here only by the campaign it belonged to. The wave that hit UK retail in April and May 2025 was driven by English-speaking crews who phoned retailer service desks impersonating staff to obtain password and MFA resets, then escalated inside the identity provider. Harrods' response, cutting external internet access at sites while investigating, is consistent with defending against credential-based lateral movement rather than a software exploit, but the company has confirmed nothing further.
AI involvement · Unknown
Harrods disclosed no technical detail, so no assessment of AI involvement is possible.
The control that would have caught it· our reading, not a claim from the sources
Fast containment helped here, but the durable control against this campaign is out-of-band identity proofing before any help desk credential or MFA reset.
Sources (2)
- Luxury department store Harrods suffered a cyberattackSecurity Affairs·securityaffairs.comOpen ↗
- Harrods alerts customers to new data breach linked to third-party providerSecurity Affairs·securityaffairs.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.