News
  • Login
  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Sunday, April 26, 2026
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    Aboriginal children's book pulled over illustrator's Bondi attack comments

    Explosions and gunfire as armed groups launch co-ordinated attacks across Mali

    Who is the anti-colonial activist grabbing attention in West Africa?

    Everest flood warning neglected for years, Nepal officials tell BBC

    BBC visits Chernobyl ghost city 40 years after world’s worst nuclear accident

    Mexico says US agents killed in crash weren’t permitted to operate there

    Trump cancels US envoys' trip to Pakistan for talks on Iran war

    Trump said RFK Jr could run ‘wild’ with health policy. Instead he’s reined him in

    Woman trapped in poo for three hours after outback toilet collapses

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Why the voice note craze is yet to truly explode in Britain

    'I know what I saw' – Scotland's history of big cat sightings

    Coventry v Wrexham: Don Hyam hails Coventry City’s rise but wants same for Wrexham

    Padel making a racquet across NI

    Starmer insists 'majority' of Labour MPs back his leadership

    Woman and child die after getting into difficulty in water

    The Papers: 'Falklands tell Trump to back off' and 'Harry does a Diana'

    Ronnie O’Sullivan and John Higgins renew their rivalry at the 2026 World Snooker Championship

    'Very funny' naked statue of Monty Python's Terry Jones to be unveiled

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    England shirt overpriced, says £40k kits collector

    McDonald's boss on abuse claims: 'I don't want to talk about the past'

    UK borrowing lowest for three years but Iran war clouds outlook

    Island's inflation rate is 2.7%, new figures show

    China car giant BYD says it can thrive without US

    US justice department drops probe into Fed chairman Jerome Powell

    US soldier charged after winning $400,000 betting on removal of Maduro

    Asbestos toy warnings

    Stock markets are too high and set to fall, says Bank of England deputy

  • Tech
  • Entertainment & Arts

    Dancers say Lizzo ‘needs to be held accountable’ over harassment claims

    Freddie Mercury: Contents of former home being sold at auction

    Harry Potter and the Cursed Child marks seven years in West End

    Sinéad O’Connor: In her own words

    Tom Jones: Neighbour surprised to find singer in flat below

    BBC presenter: What is the evidence?

    Watch: The latest on BBC presenter story… in under a minute

    Watch: George Alagiah’s extraordinary career

    BBC News presenter pays tribute to ‘much loved’ colleague George Alagiah

    Excited filmgoers: 'Barbie is everything'

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

M&S hackers sent abuse and ransom demand directly to CEO

June 7, 2025
in Tech
8 min read
245 8
0
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Joe Tidy

Cyber correspondent, BBC World Service

Bloomberg via Getty Images The M&S logo is seen pictured next to a note saying 'est. 1884' on the side of a Marks and Spencer store with an out-of-focus anonymous shopper holding a canvas bag in the foreground, in London on 1 MayBloomberg via Getty Images

The Marks & Spencer hackers sent an abuse-filled email directly to the retailer’s boss gloating about what they had done and demanding payment, BBC News has learnt.

The message to M&S CEO Stuart Machin – which was in broken English – was sent on the 23 April from the hacker group DragonForce using an employee email account.

The email confirms for the first time that M&S has been hacked by the ransomware group – something that M&S has so far refused to acknowledge.

“We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers,” the hackers wrote.

“The dragon wants to speak to you so please head over to [our darknet website].”

The cyber attack has been hugely damaging for M&S, costing it an estimated £300m. More than six weeks on, it is still unable to take online orders

The extortion email was shown to the BBC by a cyber-security expert.

The message, which includes a racist term, was sent to the M&S CEO and seven other executives.

As well as bragging about installing ransomware across the M&S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.

Nearly three weeks later customers were informed by the company that their data may have been stolen.

The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) – which has provided IT services to M&S for over a decade.

The Indian IT worker based in London has an M&S email address but is a paid TCS employee.

It appears as though he himself was hacked in the attack.

TCS has previously said it is investigating whether it was the gateway for the cyber-attack.

The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&S.

M&S has declined to comment entirely.

‘We can both help each other’

A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee. This is further indication that the email is authentic.

Sharing the link – the hackers wrote: “let’s get the party started. Message us, we will make this fast and easy for us.”

The criminals also appear to have details about the company’s cyber-insurance policy too saying “we know we can both help each other handsomely : ))”.

The M&S CEO has refused to say if the company has paid a ransom to the hackers.

DragonForce ended the email with an image of a dragon breathing fire.

A graphic of a dragon breathing fire

This dragon image was appended to the hackers email, seen by the BBC

The email confirms for the first time the link between M&S’s hack and the nearly simultaneous Co-op cyber-attack, which DragonForce have also claimed responsibility for.

The two hacks – which began in late April – have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&S expects its operations to be disrupted until July.

Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.

DragonForce offers cyber-criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.

Anyone can sign up and use their malicious software to scramble a victim’s data or use their darknet website for their public extortion.

Nothing has appeared on the criminal’s darknet leak site about either Co-op or M&S but the hackers told the BBC last week that they were having IT issues of their own and would be posting information “very soon.”

Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&S implies that they are from China.

Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.

Scattered Spider is not really a group in the normal sense of the word. It’s more of a community which organises across sites like Discord, Telegram and forums – hence the description “scattered” which was given to them by cyber-security researchers at CrowdStrike.

Some Scattered Spider hackers are known to be teenagers in the US and UK.

The UK’s National Crime Agency said in a BBC documentary about the retail hacks, that they are focusing investigations on the group.

The BBC spoke to the Co-op hackers who declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

Two of them said they wanted to be known as “Raymond Reddington” and “Dembe Zuma” after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.

In a message to me, they boasted: “We’re putting UK retailers on the Blacklist.”

There have been a series of smaller cyber-attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&S and Harrods.

In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.

The UK’s national cyber-crime unit has confirmed to the BBC that the group is one of their key suspects.

As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”



Source link

Tags: AbuseCEOdemandhackersransom

Related Posts

I brought my husband back for his funeral as a hologram

April 26, 2026
0

After nearly 60 years of marriage, Pam wanted to honour her husband Bill with a hologram at his funeral....

Palantir under fire for X ‘manifesto’ from co-founder Alex Karp

April 25, 2026
0

Dr Rhiannon Mihranian Osborne of the health campaign group Medact told the BBC: "Every day that the NHS continues...

White House memo claims mass AI theft by Chinese firms

April 24, 2026
0

A memo from Michael Kratsios says firms, mainly in China, are wrongfully distilling US AI models. Source link

  • Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

    523 shares
    Share 209 Tweet 131
  • UK inflation: Supermarkets say price rises will ease soon

    515 shares
    Share 206 Tweet 129
  • Ballyjamesduff: Man dies after hit-and-run in County Cavan

    510 shares
    Share 204 Tweet 128
  • Somalia: Rare access to its US-funded 'lightning commando brigade

    508 shares
    Share 203 Tweet 127
  • Google faces new multi-billion advertising lawsuit

    508 shares
    Share 203 Tweet 127
  • Trending
  • Comments
  • Latest

Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

January 10, 2023

UK inflation: Supermarkets say price rises will ease soon

April 19, 2023

Ballyjamesduff: Man dies after hit-and-run in County Cavan

August 19, 2022

Stranger Things actor Jamie Campbell Bower praised for addiction post

0

NHS to close Tavistock child gender identity clinic

0

Cold sores traced back to kissing in Bronze Age by Cambridge research

0

A 17th Century 'supercomputer' once owned by Indian royalty heads for auction

April 26, 2026

Why the voice note craze is yet to truly explode in Britain

April 26, 2026

The Drama star Jordyn Curet says playing young Zendaya is 'dream come true'

April 26, 2026

Categories

Science

A 17th Century 'supercomputer' once owned by Indian royalty heads for auction

April 26, 2026
0

The astrolabe - or astronomical computer - is possibly the largest in existence and has never been exhibited before....

Read more

Why the voice note craze is yet to truly explode in Britain

April 26, 2026
News

Copyright © 2020 JBC News Powered by JOOJ.us

Explore the JBC

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

Copyright © 2020 JBC News Powered by JOOJ.us

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
News
More Sites

    MORE

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
  • News

    JBC News