{"id":56266,"date":"2025-06-07T12:15:14","date_gmt":"2025-06-07T12:15:14","guid":{"rendered":"https:\/\/kede.com.br\/news\/ms-hackers-sent-abuse-and-ransom-demand-directly-to-ceo\/"},"modified":"2025-06-07T12:15:16","modified_gmt":"2025-06-07T12:15:16","slug":"ms-hackers-sent-abuse-and-ransom-demand-directly-to-ceo","status":"publish","type":"post","link":"https:\/\/kede.com.br\/news\/ms-hackers-sent-abuse-and-ransom-demand-directly-to-ceo\/","title":{"rendered":"M&#038;S hackers sent abuse and ransom demand directly to CEO"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"\">\n<div data-component=\"byline-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<div data-testid=\"byline-new\" class=\"sc-801dd632-0 eSlECZ\">\n<div data-testid=\"byline-new-contributors\" class=\"sc-801dd632-12 jSIeFi\">\n<div class=\"sc-801dd632-5 kRoBHa\">\n<div><span class=\"sc-801dd632-7 lasLGY\">Joe Tidy<\/span><\/p>\n<p><span>Cyber correspondent, BBC World Service<\/span><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-3b6b161a-0 kVRMhO\">\n<div data-testid=\"hero-image\" class=\"sc-d1200759-1 kycbVO\"><img sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/7640\/live\/d6e069b0-429f-11f0-835b-310c7b938e84.jpg.webp\" loading=\"eager\" alt=\"Bloomberg via Getty Images The M&amp;S logo is seen pictured next to a note saying 'est. 1884' on the side of a Marks and Spencer store with an out-of-focus anonymous shopper holding a canvas bag in the foreground, in London on 1 May\" class=\"sc-d1200759-0 dvfjxj\"\/><span class=\"sc-d1200759-2 gwFzuU\">Bloomberg via Getty Images<\/span><\/div>\n<\/div>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">The Marks &amp; Spencer hackers sent an abuse-filled email directly to the retailer&#8217;s boss gloating about what they had done and demanding payment, BBC News has learnt.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The message to M&amp;S CEO Stuart Machin &#8211; which was in broken English &#8211; was sent on the 23 April from the hacker group DragonForce using an employee email account.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The email confirms for the first time that M&amp;S has been hacked by the ransomware group \u2013 something that M&amp;S has so far refused to acknowledge.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers,&#8221; the hackers wrote.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;The dragon wants to speak to you so please head over to [our darknet website].&#8221;<\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">The cyber attack has been hugely damaging for M&amp;S, costing it an estimated \u00a3300m. More than six weeks on, it is still unable to take online orders<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The extortion email was shown to the BBC by a cyber-security expert.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The message, which includes a racist term, was sent to the M&amp;S CEO and seven other executives.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">As well as bragging about installing ransomware across the M&amp;S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Nearly three weeks later <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c62v34zv828o\" class=\"sc-f9178328-0 bGFWdi\" rel=\"noopener\">customers were informed <\/a>by the company that their data may have been stolen.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) &#8211; which has provided IT services to M&amp;S for over a decade.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The Indian IT worker based in London has an M&amp;S email address but is a paid TCS employee.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">It appears as though he himself was hacked in the attack.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">TCS has previously said <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c989le2p3lno\" class=\"sc-f9178328-0 bGFWdi\" rel=\"noopener\">it is investigating<\/a> whether it was the gateway for the cyber-attack.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&amp;S.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">M&amp;S has declined to comment entirely.<\/p>\n<\/div>\n<p><h2 class=\"sc-f98b1ad2-0 eOFjmw\">&#8216;We can both help each other&#8217;<\/h2>\n<\/p>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee.  This is further indication that the email is authentic.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Sharing the link \u2013 the hackers wrote: &#8220;let&#8217;s get the party started. Message us, we will make this fast and easy for us.&#8221;<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The criminals also appear to have details about the company&#8217;s cyber-insurance policy too saying &#8220;we know we can both help each other handsomely : ))&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The M&amp;S CEO has <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c93llkg4n51o\" class=\"sc-f9178328-0 bGFWdi\" rel=\"noopener\">refused to say<\/a> if the company has paid a ransom to the hackers.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">DragonForce ended the email with an image of a dragon breathing fire.<\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-3b6b161a-0 hoQmHM\">\n<div data-testid=\"image\" class=\"sc-d1200759-1 kycbVO\"><img src=\"https:\/\/static.files.bbci.co.uk\/bbcdotcom\/web\/20250529-103858-de9d27ef1-web-2.22.3-1\/grey-placeholder.png\" class=\"sc-d1200759-0 dkIvM hide-when-no-script\"\/><img sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/893b\/live\/e741d390-4216-11f0-b441-f5b5e458a38c.png.webp\" loading=\"lazy\" alt=\"A graphic of a dragon breathing fire\" class=\"sc-d1200759-0 dvfjxj\"\/><\/div>\n<\/div>\n<p><figcaption class=\"sc-536eff7b-0 FPsqq\">This dragon image was appended to the hackers email, seen by the BBC<\/figcaption><\/p>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">The email confirms for the first time the link between M&amp;S&#8217;s hack and the nearly simultaneous <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cze1eg3z307o\" class=\"sc-f9178328-0 bGFWdi\" rel=\"noopener\">Co-op cyber-attack<\/a>, which DragonForce have also claimed responsibility for.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The two hacks &#8211; which began in late April &#8211; have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&amp;S expects its operations to be disrupted until July.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">DragonForce offers cyber-criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Anyone can sign up and use their malicious software to scramble a victim&#8217;s data or use their darknet website for their public extortion.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Nothing has appeared on the criminal&#8217;s darknet leak site about either Co-op or M&amp;S but the hackers told the BBC last week that they were having IT issues of their own and would be posting information &#8220;very soon.&#8221;<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&amp;S implies that they are from China.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Scattered Spider is not really a group in the normal sense of the word. It&#8217;s more of a community which organises across sites like Discord, Telegram and forums \u2013 hence the description &#8220;scattered&#8221; which was given to them by cyber-security researchers at CrowdStrike.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Some Scattered Spider hackers are known to be teenagers in the US and UK.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The UK&#8217;s National Crime Agency said in <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/iplayer\/episode\/m002d2lh\/inside-the-high-street-cyberattacks\" class=\"sc-f9178328-0 bGFWdi\" rel=\"noopener\">a BBC documentary <\/a>about the retail hacks, that they are focusing investigations on the group.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The BBC <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/crkx3vy54nzo\" class=\"sc-f9178328-0 bGFWdi\" rel=\"noopener\">spoke to the Co-op hackers<\/a> who declined to answer whether or not they were Scattered Spider. &#8220;We won&#8217;t answer that question&#8221; is all they said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Two of them said they wanted to be known as &#8220;Raymond Reddington&#8221; and &#8220;Dembe Zuma&#8221; after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">In a message to me, they boasted: &#8220;We&#8217;re putting UK retailers on the Blacklist.&#8221;<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">There have been a series of smaller cyber-attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&amp;S and Harrods.<\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">In the early stages of the M&amp;S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\"><a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/ckgnndrgxv3o\" class=\"sc-f9178328-0 bGFWdi\" rel=\"noopener\">The UK&#8217;s national cyber-crime unit<\/a> has confirmed to the BBC that the group is one of their key suspects.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. &#8220;We won&#8217;t answer that question&#8221; is all they said.<\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-3b6b161a-0 dFZIgd\">\n<div data-testid=\"image\" class=\"sc-d1200759-1 kycbVO\"><img src=\"https:\/\/static.files.bbci.co.uk\/bbcdotcom\/web\/20250529-103858-de9d27ef1-web-2.22.3-1\/grey-placeholder.png\" class=\"sc-d1200759-0 dkIvM hide-when-no-script\"\/><img sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp\" loading=\"lazy\" alt=\"A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: &#x201C;Tech Decoded: The world&#x2019;s biggest tech news in your inbox every Monday.&#x201D;\" class=\"sc-d1200759-0 dvfjxj\"\/><\/div>\n<\/div>\n<\/figure>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.com\/news\/articles\/cr58pqjlnjlo\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Joe Tidy Cyber correspondent, BBC World Service Bloomberg via Getty Images The Marks &amp; Spencer hackers sent an abuse-filled email directly to the retailer&#8217;s boss gloating about what they had done and demanding payment, BBC News has learnt. The message to M&amp;S CEO Stuart Machin &#8211; which was in broken English &#8211; was sent on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":56267,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[62],"tags":[1623,750,727,1286,1285],"_links":{"self":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts\/56266"}],"collection":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/comments?post=56266"}],"version-history":[{"count":1,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts\/56266\/revisions"}],"predecessor-version":[{"id":56268,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts\/56266\/revisions\/56268"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/media\/56267"}],"wp:attachment":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/media?parent=56266"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/categories?post=56266"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/tags?post=56266"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}