News
  • Login
  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Saturday, June 7, 2025
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    Bouncy castle operator cleared in tragedy that killed six children

    Hey, stop whining, do something on climate change

    South Sudan – the African country producing fashion’s favourite models

    China’s driverless lorries hope to expand

    The furniture fraud who hoodwinked the Palace of Versailles

    Moment Chile earthquake rocks live TV show

    Body of Thai hostage recovered from Gaza, Israel says

    Riot police and protesters clash after LA immigration raids

    Lunch cook tells trial meal was ‘special’

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Second boy dies after M4 slip road minibus crash near Reading

    Rod Stewart cancels US gigs ahead of Glastonbury legends slot

    Police appeal after fatal SUV crash in West Lothian

    Michael Sheen’s children’s book tackles homelessness

    Murdered farmer was ‘kind, strong and loving’

    SNP to “learn lessons” as Labour wins crucial by-election

    Leicester v Sale team news: Youngs & Cole on Tigers bench, Curry & Roebuck back for Sharks

    Two men found guilty over Waringstown murder

    Up to £3bn could be spent in Scotland

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    Tariffs prompt record plunge in US imports, cutting trade deficit

    Why food firms are scrambling to cut down on ingredients

    Oreo maker sues Aldi in US over ‘copycat’ packaging

    Wollaston-based Dr Martens profits slump by more than 90%

    Arrests made in crackdown by regulators

    Donald Trump doubles US steel and aluminium tariffs to 50%

    Europe cuts interest rates as Trump’s tariffs loom

    UK inflation number for April too high after data blunder

    UK temporarily spared from Donald Trump’s 50% steel tariffs

  • Tech
  • Entertainment & Arts

    Dancers say Lizzo ‘needs to be held accountable’ over harassment claims

    Freddie Mercury: Contents of former home being sold at auction

    Harry Potter and the Cursed Child marks seven years in West End

    Sinéad O’Connor: In her own words

    Tom Jones: Neighbour surprised to find singer in flat below

    BBC presenter: What is the evidence?

    Watch: The latest on BBC presenter story… in under a minute

    Watch: George Alagiah’s extraordinary career

    BBC News presenter pays tribute to ‘much loved’ colleague George Alagiah

    Excited filmgoers: 'Barbie is everything'

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

M&S hackers sent abuse and ransom demand directly to CEO

June 7, 2025
in Tech
8 min read
245 7
0
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Joe Tidy

Cyber correspondent, BBC World Service

Bloomberg via Getty Images The M&S logo is seen pictured next to a note saying 'est. 1884' on the side of a Marks and Spencer store with an out-of-focus anonymous shopper holding a canvas bag in the foreground, in London on 1 MayBloomberg via Getty Images

The Marks & Spencer hackers sent an abuse-filled email directly to the retailer’s boss gloating about what they had done and demanding payment, BBC News has learnt.

The message to M&S CEO Stuart Machin – which was in broken English – was sent on the 23 April from the hacker group DragonForce using an employee email account.

The email confirms for the first time that M&S has been hacked by the ransomware group – something that M&S has so far refused to acknowledge.

“We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers,” the hackers wrote.

“The dragon wants to speak to you so please head over to [our darknet website].”

The cyber attack has been hugely damaging for M&S, costing it an estimated £300m. More than six weeks on, it is still unable to take online orders

The extortion email was shown to the BBC by a cyber-security expert.

The message, which includes a racist term, was sent to the M&S CEO and seven other executives.

As well as bragging about installing ransomware across the M&S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.

Nearly three weeks later customers were informed by the company that their data may have been stolen.

The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) – which has provided IT services to M&S for over a decade.

The Indian IT worker based in London has an M&S email address but is a paid TCS employee.

It appears as though he himself was hacked in the attack.

TCS has previously said it is investigating whether it was the gateway for the cyber-attack.

The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&S.

M&S has declined to comment entirely.

‘We can both help each other’

A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee. This is further indication that the email is authentic.

Sharing the link – the hackers wrote: “let’s get the party started. Message us, we will make this fast and easy for us.”

The criminals also appear to have details about the company’s cyber-insurance policy too saying “we know we can both help each other handsomely : ))”.

The M&S CEO has refused to say if the company has paid a ransom to the hackers.

DragonForce ended the email with an image of a dragon breathing fire.

A graphic of a dragon breathing fire

This dragon image was appended to the hackers email, seen by the BBC

The email confirms for the first time the link between M&S’s hack and the nearly simultaneous Co-op cyber-attack, which DragonForce have also claimed responsibility for.

The two hacks – which began in late April – have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&S expects its operations to be disrupted until July.

Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.

DragonForce offers cyber-criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.

Anyone can sign up and use their malicious software to scramble a victim’s data or use their darknet website for their public extortion.

Nothing has appeared on the criminal’s darknet leak site about either Co-op or M&S but the hackers told the BBC last week that they were having IT issues of their own and would be posting information “very soon.”

Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&S implies that they are from China.

Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.

Scattered Spider is not really a group in the normal sense of the word. It’s more of a community which organises across sites like Discord, Telegram and forums – hence the description “scattered” which was given to them by cyber-security researchers at CrowdStrike.

Some Scattered Spider hackers are known to be teenagers in the US and UK.

The UK’s National Crime Agency said in a BBC documentary about the retail hacks, that they are focusing investigations on the group.

The BBC spoke to the Co-op hackers who declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

Two of them said they wanted to be known as “Raymond Reddington” and “Dembe Zuma” after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.

In a message to me, they boasted: “We’re putting UK retailers on the Blacklist.”

There have been a series of smaller cyber-attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&S and Harrods.

In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.

The UK’s national cyber-crime unit has confirmed to the BBC that the group is one of their key suspects.

As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”



Source link

Tags: AbuseCEOdemandhackersransom

Related Posts

NatWest apologises as banking app goes offline

June 6, 2025
0

Tom GerkenTechnology reporterGetty ImagesNatWest has apologised after customers were left unable to use its mobile banking app in the...

Stores open at midnight as fans rush to buy Nintendo Switch 2

June 5, 2025
0

Tom GerkenTechnology reporterPeter GillibrandNewsbeat reporterWatch: Fans queue overnight for the launch of the Nintendo Switch 2The Nintendo Switch 2...

TikTok blocks searches for extreme thinness ‘skinnytok’ hashtag

June 4, 2025
0

TikTok is preventing users searching for "skinnytok" - a hashtag which critics say directs people towards content which "idolises...

  • Ballyjamesduff: Man dies after hit-and-run in County Cavan

    510 shares
    Share 204 Tweet 128
  • Somalia: Rare access to its US-funded 'lightning commando brigade

    508 shares
    Share 203 Tweet 127
  • Uganda arrest over deadly New Year Freedom City mall crush

    507 shares
    Share 203 Tweet 127
  • George Weah: Hopes for Liberian football revival with legend as President

    506 shares
    Share 202 Tweet 127
  • Google faces new multi-billion advertising lawsuit

    506 shares
    Share 202 Tweet 127
  • Trending
  • Comments
  • Latest

Ballyjamesduff: Man dies after hit-and-run in County Cavan

August 19, 2022

Somalia: Rare access to its US-funded 'lightning commando brigade

November 23, 2022

Uganda arrest over deadly New Year Freedom City mall crush

January 3, 2023

Stranger Things actor Jamie Campbell Bower praised for addiction post

0

NHS to close Tavistock child gender identity clinic

0

Cold sores traced back to kissing in Bronze Age by Cambridge research

0

Second boy dies after M4 slip road minibus crash near Reading

June 7, 2025

Tariffs prompt record plunge in US imports, cutting trade deficit

June 7, 2025

Ros Atkins on… Ukraine’s Operation ‘Spider’s Web’

June 7, 2025

Categories

England

Second boy dies after M4 slip road minibus crash near Reading

June 7, 2025
0

An 11-year-old boy has become the second child to die after a minibus overturned on a motorway slip road.Othniel...

Read more

Tariffs prompt record plunge in US imports, cutting trade deficit

June 7, 2025
News

Copyright © 2020 JBC News Powered by JOOJ.us

Explore the JBC

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

Copyright © 2020 JBC News Powered by JOOJ.us

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
News
More Sites

    MORE

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
  • News

    JBC News