When Marks & Spencer, the Co-op, and Harrods all disclosed serious cyber incidents within weeks of one another in April and May 2025, the immediate public question was whether this was one attack or three. The answer mattered practically, not just for headlines: insurance treats a single systemic event very differently from three unrelated claims, and regulators need to know whether they are looking at one threat actor's campaign or a coincidental cluster.
That determination fell to the UK's Cyber Monitoring Centre, an independent, non-profit body set up by the insurance industry specifically to classify major cyber events. The CMC's assessment, given the same threat actor claiming responsibility for both M&S and the Co-op, the tight timing between the two, and matching tactics, techniques and procedures, was that the two incidents constituted 'a single combined cyber event' — formally classified as a Category 2 systemic event, with total financial impact estimated at £270 million to £440 million. Notably, the CMC's assessment did not fold in the Harrods incident, which was assessed separately despite the overlapping timeline.
The Co-op's outcome differed from M&S's in one important respect: it detected suspicious activity early enough to proactively shut down parts of its own IT systems before attackers could achieve the same level of disruption, limiting the damage relative to what M&S experienced. That is a useful natural experiment in incident response — two retailers targeted by what regulators believe was the same actor, with materially different outcomes based on how quickly the intrusion was detected and how decisively systems were taken offline in response.
The broader significance of the CMC's classification is procedural as much as technical: it establishes that a new, independent, insurance-backed body is now willing and able to make an evidence-based determination about attack attribution and scale, separate from both the affected companies' own disclosures and from law enforcement's slower criminal investigation timeline. For an industry that has long struggled to get consistent, comparable data about the true scale of major cyber incidents, that is a meaningful piece of infrastructure to have in place.