The new cyber threat: young, western and reckless

The new cyber threat: young, western and reckless 图片 1

In April 2025, thousands of shoppers were suddenly unable to complete their purchases at UK retailer Marks and Spencer.

The FTSE 100 group had been paralysed by a cyber attack, which resulted in charges of £131mn, sending shivers through corporate boardrooms across the UK.

However the assailants, who belonged to a hacking collective known as Scattered Spider, were not the usual type of “threat actor” but a new breed of cybercriminal: young, English-speaking and motivated by improving their reputation among fellow hackers rather than solely for financial gain.

The attack was one of a series of cybercrimes committed by perpetrators that fit a similar profile, including hits on Transport for London (TfL) and on UK retailers Harrods and the Co-Op. The trend has forced cyber experts to reassess the profile of criminals behind security breaches.

Over the past five years there has been a shift, says Rafe Pilling, a director of threat intelligence at the cyber security group Sophos, with the types of individuals and groups behind the attacks becoming more diverse.

“The majority of the threat still comes from Russian-speaking ransomware extortion groups and on the business email compromise side, Nigerian and West Africans,” he says. “But [increasingly]... it’s western teens, kids, young adults getting involved in sophisticated cyber crime on a larger scale.”

In addition to Scattered Spider, several other groups have emerged, including ShinyHunters and Hellcat, which fit this profile rather than coming from a Russian organised crime background. They are “leaking data, getting involved in ransomware and really causing a significant amount of havoc”, Pilling says.

The attacks have led to a series of high-profile arrests and charges, most notably of Owen Flowers and Thalha Jubair, two young British men who this month were sentenced to five years and six months in prison for the 2024 attack on TfL, which cost London’s transport authority up to £39mn.

The 2024 attack cost TfL up to £39mn © Daniel Harvey Gonzalez/Getty Images

Both men were already known to police and were seasoned cyber criminals, with Jubair also charged in the US for alleged crimes.

A report by cyber security consultancy S-RM found that its teams had responded to incidents involving 67 distinct ransomware groups in 2025, up from 58 the year before, noting that “the influx of newer, less predictable operators has made outcomes harder to predict”.

However, experts have warned that despite the high-profile attacks committed by these newer actors, there is still a strong undercurrent of more traditional hacking.

Pilling points to a survey by Sophos, which found that of the 10 most prolific ransomware groups, measured by the number of individuals they claim to have targeted, nine were Russian-speaking.

James Tytler, a senior associate at S-RM, says that while attacks by western-based actors have made headlines over the past year, there is still a “slow, steady burn” of the more established groups that have a “very tried and tested method that is shown to be working”.

The rapid adoption of artificial intelligence has also lowered the barrier to entry for would-be hackers, making it easier to carry out attacks, and has improved their ability to deceive victims, such as through fake phone calls or “deepfake” videos.

According to research commissioned by financial and risk advisory company Kroll, 76 per cent of organisations have experienced a security incident involving AI applications or models in the past two years.

Ciaran Martin, a professor at the University of Oxford’s Blavatnik School of Government and the former head of the UK National Cyber Security Centre (NCSC), says AI capabilities are already “very significant”.

Recommended

But he cautions that there is an “incongruity” between the narrative in the cyber security sector of AI taking hold and how much it is being used in reality.

“The industry is going bananas between AI cyber threats,” he says. But attackers are looking for the biggest gains for the lowest cost and sometimes it is cheaper for them not to use AI. They tend to go for “the easiest possible option”, says Martin.

The evolving world of threat actors and technology has sparked both the UK government and the NCSC to issue warnings to companies to take their cyber security more seriously.

In October last year, the chief executive of the NCSC Richard Horne said that CEOs who failed to prepare their companies for cyber attacks were “jeopardising their business’s future”.

At the same time, four ministers, including UK chancellor Rachel Reeves and business secretary Peter Kyle, co-signed a letter to business leaders urging them to “take the necessary steps to protect your business and our wider economy from cyber attacks”.

“In this increasingly hostile landscape,” the letter continued, “organisations recover better from incidents when they have planned for the worst and rehearsed their business continuity and recovery.”

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论