The attack on Marks & Spencer landed in April, over the Easter weekend. But May was when Britain learned what it had cost. On May 13, M&S confirmed what customers had feared: attackers had taken personal data — names, contact details, dates of birth, order histories — though no usable card data or passwords. Then, presenting annual results on May 21, the retailer put a number on the damage that made every board in the country sit up: roughly £300 million off group operating profit, with online disruption expected to run into July. A cyberattack had become a line item in a FTSE 100 earnings report, measured in nine figures.
And M&S was not alone on the high street. The Co-op, which had taken systems offline on April 30, confirmed on May 2 that hackers had extracted the personal data of a significant number of current and former members — a figure its CEO would only later, in July, confirm reached some 6.5 million people. Harrods had fended off an attempted intrusion on May 1. In early May, actors identifying with the DragonForce ransomware operation stepped out of the shadows to tell the BBC they were behind all three — M&S, Co-op, and the Harrods attempt — an unusually public victory lap. The intrusions were widely tied to the Scattered Spider community, whose method was social engineering of third-party IT support rather than any exotic exploit.
Britain's National Cyber Security Centre said it was working with all three retailers, and its chief, Richard Horne, called the wave a wake-up call for British business. The lesson wasn't technical. Three of the country's best-known names had been felled not by a clever zero-day but by attackers talking their way past a help desk — and the bill, for M&S alone, was £300 million.
Coinbase and the $20 million demand
On May 14, Coinbase disclosed in an SEC filing that bribed overseas customer-support agents had been leaking customer data since around late December 2024 — and that on May 11 the company had received a $20 million extortion demand. The stolen data covered roughly 69,461 customers: names, addresses, government-ID images, partial Social Security numbers, masked bank details. Coinbase refused to pay, posted a $20 million bounty on the attackers instead, and estimated remediation costs of $180–400 million. Later Reuters reporting and US court filings tied the leaks to bribed agents at an outsourcing firm's site in Indore, India — one employee allegedly photographing customer records at about $200 an image. It was the year's clearest proof that the insider, well-paid to betray, is a threat no firewall addresses.
LockBit gets a taste of its own medicine
On May 7, LockBit's own dark-web affiliate panels were defaced — "Don't do crime CRIME IS BAD xoxo from Prague" — with a link to a dumped database from the gang's backend. The leak exposed nearly 60,000 Bitcoin addresses, over 4,400 ransom-negotiation chats, and plaintext credentials for about 75 panel users. The same taunt had defaced the Everest gang's site, hinting at a common attacker. Coming after 2024's law-enforcement takedown, the humiliation further eroded affiliate trust in what had been ransomware's most prolific brand — a reminder that the criminal economy is, among other things, a set of insecure web apps run by people with enemies.
Operation Sindoor's other front
When India launched Operation Sindoor on May 7, the retaliation came in two domains at once. Alongside the kinetic strikes, analysts recorded a coordinated surge of hacktivist and state-aligned cyberattacks on Indian networks — the first time cyberspace was widely described as an active front of an India–Pakistan crisis. Maharashtra Cyber's "Road of Sindoor" report logged more than 1.5 million attempted attacks on Indian digital infrastructure during the conflict window, attributed to seven groups operating from Pakistan and allied geographies — of which only around 150 were assessed to have actually succeeded. DDoS and defacement attempts targeted government and public-sector sites, though researchers like CloudSEK judged the great majority of hacktivist breach claims to be exaggerated, recycled, or false. The lasting lesson for India: in the next conflict, the information war and the cyber war arrive together — and telling a real breach from a boastful claim becomes a national-security skill.
⏳ Time capsule — May 2025
- On May 8, Cardinal Robert Prevost of Chicago was elected Pope Leo XIV — the first American pope in history.
- Bitcoin hit a then-record above $111,000 on May 22 — fittingly, the 15th anniversary of Bitcoin Pizza Day.
- On May 21, OpenAI announced it was acquiring Jony Ive's hardware startup io in a deal reported around $6.4 billion, its largest to date.
- Austria's JJ won the Eurovision Song Contest in Basel on May 17 with the operatic ballad "Wasted Love."
The £300 million wake-up call
M&S's £300 million became the number every British CISO quoted in budget meetings for the next year — the moment retail security stopped being an IT cost and became a boardroom risk. The Scattered Spider method it exposed — social-engineer the help desk, skip the exploit — went on to hit airlines in the summer and insurers before that, and the human-verification failures it revealed are why "help-desk identity proofing" is now an audit line item. Coinbase's bribed-insider breach previewed the year's uncomfortable truth that your outsourced back office holds your crown jewels, a theme that ran straight through to 2026's BPO-vector breaches. And Operation Sindoor's digital shadow left India with a doctrine it still refines: in modern conflict, the first casualty and the first target are both online.