News
  • Login
  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Monday, December 8, 2025
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    'We deserve to have a say' – Australian teens on the social media ban

    Trump criticises Henry Cuellar over not switching parties after pardon

    Benin coup thwarted by loyalist troops, President Talon tells nation

    India’s poll workers flag harsh conditions amid rising deaths

    New US security strategy aligns with Russia’s vision, Moscow says

    Death of Venezuelan opposition figure in custody ‘vile’, US says

    Bethlehem Christmas tree lights up for first time since Gaza war

    California wild mushroom poisoning leaves 1 dead, 20 injured

    Can you ban kids from social media? Australia is about to try

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Heathrow ‘pepper spray attack’ and ‘Harry gun cop U-turn’

    Teenager Mitchell Lawrie beaten by Jimmy van Schie in WDF World Championship final

    Merthyr couple hope new room will stop A&E fear for ALN families

    Murder inquiry launched after child and woman die in fire

    Covid fraud and error cost taxpayers £10.9bn, report will say

    How Lando Norris achieved his lifetime’s ambition of F1 world title by ‘winning it my way’

    Army veteran shocked by XL bully owner’s sentence after attack

    Why do Gen Z have a growing appetite for retro tech?

    Champions Cup: Scarlets 16-17 Bristol – Louis Rees-Zammit seals win for Bears

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    Can Japan get more female business leaders?

    Canadia airline to halt flights ahead of strike

    What is the Office for Budget Responsibility and why has its boss resigned?

    Sold 30 items on Vinted? Don’t panic if you get a message about tax

    West Midlands people urged to ‘shop local’ and back small firms

    People admit to ‘secret spending’ without telling partners

    Five takeaways from the blockbuster Netflix Warner Brothers deal

    Ryanair scraps printed boarding passes to go fully digital

    Reeves will not face ethics probe over pre-Budget remarks

  • Tech
  • Entertainment & Arts

    Dancers say Lizzo ‘needs to be held accountable’ over harassment claims

    Freddie Mercury: Contents of former home being sold at auction

    Harry Potter and the Cursed Child marks seven years in West End

    Sinéad O’Connor: In her own words

    Tom Jones: Neighbour surprised to find singer in flat below

    BBC presenter: What is the evidence?

    Watch: The latest on BBC presenter story… in under a minute

    Watch: George Alagiah’s extraordinary career

    BBC News presenter pays tribute to ‘much loved’ colleague George Alagiah

    Excited filmgoers: 'Barbie is everything'

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

M&S hackers sent abuse and ransom demand directly to CEO

June 7, 2025
in Tech
8 min read
245 8
0
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Joe Tidy

Cyber correspondent, BBC World Service

Bloomberg via Getty Images The M&S logo is seen pictured next to a note saying 'est. 1884' on the side of a Marks and Spencer store with an out-of-focus anonymous shopper holding a canvas bag in the foreground, in London on 1 MayBloomberg via Getty Images

The Marks & Spencer hackers sent an abuse-filled email directly to the retailer’s boss gloating about what they had done and demanding payment, BBC News has learnt.

The message to M&S CEO Stuart Machin – which was in broken English – was sent on the 23 April from the hacker group DragonForce using an employee email account.

The email confirms for the first time that M&S has been hacked by the ransomware group – something that M&S has so far refused to acknowledge.

“We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers,” the hackers wrote.

“The dragon wants to speak to you so please head over to [our darknet website].”

The cyber attack has been hugely damaging for M&S, costing it an estimated £300m. More than six weeks on, it is still unable to take online orders

The extortion email was shown to the BBC by a cyber-security expert.

The message, which includes a racist term, was sent to the M&S CEO and seven other executives.

As well as bragging about installing ransomware across the M&S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.

Nearly three weeks later customers were informed by the company that their data may have been stolen.

The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) – which has provided IT services to M&S for over a decade.

The Indian IT worker based in London has an M&S email address but is a paid TCS employee.

It appears as though he himself was hacked in the attack.

TCS has previously said it is investigating whether it was the gateway for the cyber-attack.

The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&S.

M&S has declined to comment entirely.

‘We can both help each other’

A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee. This is further indication that the email is authentic.

Sharing the link – the hackers wrote: “let’s get the party started. Message us, we will make this fast and easy for us.”

The criminals also appear to have details about the company’s cyber-insurance policy too saying “we know we can both help each other handsomely : ))”.

The M&S CEO has refused to say if the company has paid a ransom to the hackers.

DragonForce ended the email with an image of a dragon breathing fire.

A graphic of a dragon breathing fire

This dragon image was appended to the hackers email, seen by the BBC

The email confirms for the first time the link between M&S’s hack and the nearly simultaneous Co-op cyber-attack, which DragonForce have also claimed responsibility for.

The two hacks – which began in late April – have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&S expects its operations to be disrupted until July.

Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.

DragonForce offers cyber-criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.

Anyone can sign up and use their malicious software to scramble a victim’s data or use their darknet website for their public extortion.

Nothing has appeared on the criminal’s darknet leak site about either Co-op or M&S but the hackers told the BBC last week that they were having IT issues of their own and would be posting information “very soon.”

Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&S implies that they are from China.

Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.

Scattered Spider is not really a group in the normal sense of the word. It’s more of a community which organises across sites like Discord, Telegram and forums – hence the description “scattered” which was given to them by cyber-security researchers at CrowdStrike.

Some Scattered Spider hackers are known to be teenagers in the US and UK.

The UK’s National Crime Agency said in a BBC documentary about the retail hacks, that they are focusing investigations on the group.

The BBC spoke to the Co-op hackers who declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

Two of them said they wanted to be known as “Raymond Reddington” and “Dembe Zuma” after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.

In a message to me, they boasted: “We’re putting UK retailers on the Blacklist.”

There have been a series of smaller cyber-attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&S and Harrods.

In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.

The UK’s national cyber-crime unit has confirmed to the BBC that the group is one of their key suspects.

As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”



Source link

Tags: AbuseCEOdemandhackersransom

Related Posts

Japan is facing a dementia crisis – can technology help?

December 8, 2025
0

Suranjana TewariAsia Business Correspondent, TokyoBBCScientists at Waseda University in Tokyo are developing caregiving robotsLast year, more than 18,000 older...

Elon Musk’s X fined €120m over ‘deceptive’ blue ticks

December 7, 2025
0

Liv McMahonTechnology reporterGetty ImagesThe EU has fined Elon Musk's social media platform X €120m (£105m) over its blue tick...

Twitch star QTCinderella says she wishes she never started streaming

December 6, 2025
0

Laura CressTechnology reporterBBCThe popular Twitch streamer QTCinderella says she would be a "happier person" if she could go back...

  • Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

    520 shares
    Share 208 Tweet 130
  • UK inflation: Supermarkets say price rises will ease soon

    513 shares
    Share 205 Tweet 128
  • Ballyjamesduff: Man dies after hit-and-run in County Cavan

    510 shares
    Share 204 Tweet 128
  • Somalia: Rare access to its US-funded 'lightning commando brigade

    508 shares
    Share 203 Tweet 127
  • Google faces new multi-billion advertising lawsuit

    508 shares
    Share 203 Tweet 127
  • Trending
  • Comments
  • Latest

Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

January 10, 2023

UK inflation: Supermarkets say price rises will ease soon

April 19, 2023

Ballyjamesduff: Man dies after hit-and-run in County Cavan

August 19, 2022

Stranger Things actor Jamie Campbell Bower praised for addiction post

0

NHS to close Tavistock child gender identity clinic

0

Cold sores traced back to kissing in Bronze Age by Cambridge research

0

Volcanic eruption may have triggered Europe’s Black Death plague

December 8, 2025

Heathrow ‘pepper spray attack’ and ‘Harry gun cop U-turn’

December 8, 2025

Radio 1’s Big Weekend 2026 announced for Sunderland

December 8, 2025

Categories

Science

Volcanic eruption may have triggered Europe’s Black Death plague

December 8, 2025
0

Helen BriggsEnvironment correspondentGettyThe Black Death fundamentally altered medieval societyA volcanic eruption around the year 1345 may have set off...

Read more

Heathrow ‘pepper spray attack’ and ‘Harry gun cop U-turn’

December 8, 2025
News

Copyright © 2020 JBC News Powered by JOOJ.us

Explore the JBC

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

Copyright © 2020 JBC News Powered by JOOJ.us

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
News
More Sites

    MORE

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
  • News

    JBC News