In July 2025, the UK's National Crime Agency announced the arrest of four individuals in connection with the cyberattacks on Marks & Spencer, the Co-op, and Harrods — an event significant enough that it is worth pausing on how unusual it actually is. The overwhelming majority of ransomware attacks, even large, well-attributed ones, never result in an arrest. The attackers typically operate from jurisdictions with no meaningful extradition relationship with the victim's country, communicate through infrastructure designed to resist exactly this kind of investigation, and disband or rebrand under a new name well before law enforcement can build a prosecutable case.
Scattered Spider, the loosely organised group believed responsible, is a partial exception to that pattern for a specific and somewhat ironic reason: unlike many ransomware crews that operate with tight operational security through anonymous forums and encrypted channels, Scattered Spider's core technique — fluent, confident social engineering over the phone — requires operators to actually talk, extensively, in real time, in English, to real people. One security researcher's assessment of the group's exposure is worth repeating: its members have shifted away from the anonymous online infrastructure that historically protected cybercriminals, toward voice communication that consistently exposes them to investigation and, eventually, indictment.
That is not a universal lesson about cybercrime enforcement improving broadly — it is a lesson about one group's specific operational choice creating an unusual point of exposure. Most ransomware operators remain effectively unreachable by Western law enforcement, and the economics of ransomware-as-a-service, where the operators renting out the infrastructure are geographically and operationally separated from the affiliates carrying out any particular attack, are specifically designed to make sure that stays true.
For organisations building an incident response plan, the practical takeaway is not to expect an arrest to materialise as part of recovery. It is a genuinely good outcome when it happens, and worth taking as a small data point on the risk calculus of certain attack methods, but the operating assumption for any ransomware incident should still be that recovery, cleanup, and prevention are entirely on the victim organisation to manage — law enforcement action, if it comes at all, is a bonus outcome measured in months or years, not a response measured in days.