News
  • Login
  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Monday, April 27, 2026
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    Was Harry and Meghan’s Australia trip a success?

    Video shows correspondents’ dinner suspect charge checkpoint

    Mali defence minister killed as country hit by wave of rebel attacks

    Missing 5-year-old girl likely abducted from Outback home, police say

    Orbán steps down from Hungarian parliament after landslide defeat

    Death toll in Colombia highway bus bomb attack rises to 20

    Did Trump’s intervention save eight Iranian women from execution?

    Trump and officials ‘likely’ targets of press dinner shooting suspect, authorities believe

    Aboriginal children's book pulled over illustrator's Bondi attack comments

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    'It lit a fire in me' – the barrister who was told she'd never amount to much

    Win or bust for Rangers as Hearts test at Tynecastle on May bank holiday looms large

    URC: Wales hopeful Morgan Morris aims for strong finish to toughest year

    On the beat with NI’s police

    King’s US visit will go ahead as planned, Buckingham Palace says

    Man becomes seventh Millionaire jackpot winner

    Why the voice note craze is yet to truly explode in Britain

    'I know what I saw' – Scotland's history of big cat sightings

    Coventry v Wrexham: Don Hyam hails Coventry City’s rise but wants same for Wrexham

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    Oil prices rise as US-Iran peace talks stall

    How long has fast food been around and when did it become popular?

    Three ways the latest inflation figures affect you

    England shirt overpriced, says £40k kits collector

    McDonald's boss on abuse claims: 'I don't want to talk about the past'

    UK borrowing lowest for three years but Iran war clouds outlook

    Island's inflation rate is 2.7%, new figures show

    China car giant BYD says it can thrive without US

    US justice department drops probe into Fed chairman Jerome Powell

  • Tech
  • Entertainment & Arts

    Dancers say Lizzo ‘needs to be held accountable’ over harassment claims

    Freddie Mercury: Contents of former home being sold at auction

    Harry Potter and the Cursed Child marks seven years in West End

    Sinéad O’Connor: In her own words

    Tom Jones: Neighbour surprised to find singer in flat below

    BBC presenter: What is the evidence?

    Watch: The latest on BBC presenter story… in under a minute

    Watch: George Alagiah’s extraordinary career

    BBC News presenter pays tribute to ‘much loved’ colleague George Alagiah

    Excited filmgoers: 'Barbie is everything'

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

M&S hackers sent abuse and ransom demand directly to CEO

June 7, 2025
in Tech
8 min read
245 8
0
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Joe Tidy

Cyber correspondent, BBC World Service

Bloomberg via Getty Images The M&S logo is seen pictured next to a note saying 'est. 1884' on the side of a Marks and Spencer store with an out-of-focus anonymous shopper holding a canvas bag in the foreground, in London on 1 MayBloomberg via Getty Images

The Marks & Spencer hackers sent an abuse-filled email directly to the retailer’s boss gloating about what they had done and demanding payment, BBC News has learnt.

The message to M&S CEO Stuart Machin – which was in broken English – was sent on the 23 April from the hacker group DragonForce using an employee email account.

The email confirms for the first time that M&S has been hacked by the ransomware group – something that M&S has so far refused to acknowledge.

“We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers,” the hackers wrote.

“The dragon wants to speak to you so please head over to [our darknet website].”

The cyber attack has been hugely damaging for M&S, costing it an estimated £300m. More than six weeks on, it is still unable to take online orders

The extortion email was shown to the BBC by a cyber-security expert.

The message, which includes a racist term, was sent to the M&S CEO and seven other executives.

As well as bragging about installing ransomware across the M&S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.

Nearly three weeks later customers were informed by the company that their data may have been stolen.

The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) – which has provided IT services to M&S for over a decade.

The Indian IT worker based in London has an M&S email address but is a paid TCS employee.

It appears as though he himself was hacked in the attack.

TCS has previously said it is investigating whether it was the gateway for the cyber-attack.

The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&S.

M&S has declined to comment entirely.

‘We can both help each other’

A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee. This is further indication that the email is authentic.

Sharing the link – the hackers wrote: “let’s get the party started. Message us, we will make this fast and easy for us.”

The criminals also appear to have details about the company’s cyber-insurance policy too saying “we know we can both help each other handsomely : ))”.

The M&S CEO has refused to say if the company has paid a ransom to the hackers.

DragonForce ended the email with an image of a dragon breathing fire.

A graphic of a dragon breathing fire

This dragon image was appended to the hackers email, seen by the BBC

The email confirms for the first time the link between M&S’s hack and the nearly simultaneous Co-op cyber-attack, which DragonForce have also claimed responsibility for.

The two hacks – which began in late April – have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&S expects its operations to be disrupted until July.

Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.

DragonForce offers cyber-criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.

Anyone can sign up and use their malicious software to scramble a victim’s data or use their darknet website for their public extortion.

Nothing has appeared on the criminal’s darknet leak site about either Co-op or M&S but the hackers told the BBC last week that they were having IT issues of their own and would be posting information “very soon.”

Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&S implies that they are from China.

Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.

Scattered Spider is not really a group in the normal sense of the word. It’s more of a community which organises across sites like Discord, Telegram and forums – hence the description “scattered” which was given to them by cyber-security researchers at CrowdStrike.

Some Scattered Spider hackers are known to be teenagers in the US and UK.

The UK’s National Crime Agency said in a BBC documentary about the retail hacks, that they are focusing investigations on the group.

The BBC spoke to the Co-op hackers who declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

Two of them said they wanted to be known as “Raymond Reddington” and “Dembe Zuma” after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.

In a message to me, they boasted: “We’re putting UK retailers on the Blacklist.”

There have been a series of smaller cyber-attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&S and Harrods.

In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.

The UK’s national cyber-crime unit has confirmed to the BBC that the group is one of their key suspects.

As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”



Source link

Tags: AbuseCEOdemandhackersransom

Related Posts

OpenAI boss 'deeply sorry' for not telling police of mass shooting suspect's account

April 27, 2026
0

Sam Altman on Thursday wrote a brief letter of apology to the people of Tumbler Ridge, Canada in the...

I brought my husband back for his funeral as a hologram

April 26, 2026
0

After nearly 60 years of marriage, Pam wanted to honour her husband Bill with a hologram at his funeral....

Palantir under fire for X ‘manifesto’ from co-founder Alex Karp

April 25, 2026
0

Dr Rhiannon Mihranian Osborne of the health campaign group Medact told the BBC: "Every day that the NHS continues...

  • Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

    523 shares
    Share 209 Tweet 131
  • UK inflation: Supermarkets say price rises will ease soon

    515 shares
    Share 206 Tweet 129
  • Ballyjamesduff: Man dies after hit-and-run in County Cavan

    510 shares
    Share 204 Tweet 128
  • Somalia: Rare access to its US-funded 'lightning commando brigade

    508 shares
    Share 203 Tweet 127
  • Google faces new multi-billion advertising lawsuit

    508 shares
    Share 203 Tweet 127
  • Trending
  • Comments
  • Latest

Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

January 10, 2023

UK inflation: Supermarkets say price rises will ease soon

April 19, 2023

Ballyjamesduff: Man dies after hit-and-run in County Cavan

August 19, 2022

Stranger Things actor Jamie Campbell Bower praised for addiction post

0

NHS to close Tavistock child gender identity clinic

0

Cold sores traced back to kissing in Bronze Age by Cambridge research

0

UK's biggest ever environmental pollution claim reaches High Court

April 27, 2026

'It lit a fire in me' – the barrister who was told she'd never amount to much

April 27, 2026

Malala's brother Khushal on fleeing the Taliban and facing the manosphere

April 27, 2026

Categories

Science

UK's biggest ever environmental pollution claim reaches High Court

April 27, 2026
0

One of the UK's largest chicken producers and a water company accused of polluting three rivers including the River...

Read more

'It lit a fire in me' – the barrister who was told she'd never amount to much

April 27, 2026
News

Copyright © 2020 JBC News Powered by JOOJ.us

Explore the JBC

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

Copyright © 2020 JBC News Powered by JOOJ.us

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
News
More Sites

    MORE

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
  • News

    JBC News