BusinessPostCorner.com
No Result
View All Result
Thursday, July 3, 2025
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources
BusinessPostCorner.com
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources
No Result
View All Result
BusinessPostCorner.com
No Result
View All Result

M&S hackers sent abuse and ransom demand directly to CEO

June 6, 2025
in Business
Reading Time: 8 mins read
A A
0
M&S hackers sent abuse and ransom demand directly to CEO
ShareShareShareShareShare
Joe Tidy

Cyber correspondent, BBC World Service

Bloomberg via Getty Images The M&S logo is seen pictured next to a note saying 'est. 1884' on the side of a Marks and Spencer store with an out-of-focus anonymous shopper holding a canvas bag in the foreground, in London on 1 MayBloomberg via Getty Images

The Marks & Spencer hackers sent an abuse-filled email directly to the retailer’s boss gloating about what they had done and demanding payment, BBC News has learnt.

The message to M&S CEO Stuart Machin – which was in broken English – was sent on the 23 April from the hacker group DragonForce using an employee email account.

The email confirms for the first time that M&S has been hacked by the ransomware group – something that M&S has so far refused to acknowledge.

“We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers,” the hackers wrote.

“The dragon wants to speak to you so please head over to [our darknet website].”

The cyber attack has been hugely damaging for M&S, costing it an estimated £300m. More than six weeks on, it is still unable to take online orders

The extortion email was shown to the BBC by a cyber-security expert.

The message, which includes a racist term, was sent to the M&S CEO and seven other executives.

As well as bragging about installing ransomware across the M&S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.

Nearly three weeks later customers were informed by the company that their data may have been stolen.

The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) – which has provided IT services to M&S for over a decade.

The Indian IT worker based in London has an M&S email address but is a paid TCS employee.

It appears as though he himself was hacked in the attack.

TCS has previously said it is investigating whether it was the gateway for the cyber-attack.

The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&S.

M&S has declined to comment entirely.

‘We can both help each other’

A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee. This is further indication that the email is authentic.

Sharing the link – the hackers wrote: “let’s get the party started. Message us, we will make this fast and easy for us.”

The criminals also appear to have details about the company’s cyber-insurance policy too saying “we know we can both help each other handsomely : ))”.

The M&S CEO has refused to say if the company has paid a ransom to the hackers.

DragonForce ended the email with an image of a dragon breathing fire.

A graphic of a dragon breathing fire

This dragon image was appended to the hackers email, seen by the BBC

The email confirms for the first time the link between M&S’s hack and the nearly simultaneous Co-op cyber-attack, which DragonForce have also claimed responsibility for.

The two hacks – which began in late April – have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&S expects its operations to be disrupted until July.

Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.

DragonForce offers cyber-criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.

Anyone can sign up and use their malicious software to scramble a victim’s data or use their darknet website for their public extortion.

Nothing has appeared on the criminal’s darknet leak site about either Co-op or M&S but the hackers told the BBC last week that they were having IT issues of their own and would be posting information “very soon.”

Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&S implies that they are from China.

Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.

Scattered Spider is not really a group in the normal sense of the word. It’s more of a community which organises across sites like Discord, Telegram and forums – hence the description “scattered” which was given to them by cyber-security researchers at CrowdStrike.

Some Scattered Spider hackers are known to be teenagers in the US and UK.

The UK’s National Crime Agency said in a BBC documentary about the retail hacks, that they are focusing investigations on the group.

The BBC spoke to the Co-op hackers who declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

Two of them said they wanted to be known as “Raymond Reddington” and “Dembe Zuma” after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.

In a message to me, they boasted: “We’re putting UK retailers on the Blacklist.”

There have been a series of smaller cyber-attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&S and Harrods.

In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.

The UK’s national cyber-crime unit has confirmed to the BBC that the group is one of their key suspects.

As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”

Credit: Source link

ShareTweetSendPinShare
Previous Post

Trump vs Musk: Crypto Market Turns Red, Tesla Closes 14% Lower

Next Post

Wollaston charity supports one in 16 babies across the county

Next Post
Wollaston charity supports one in 16 babies across the county

Wollaston charity supports one in 16 babies across the county

Binance Pay Lights Up French Riviera: 80+ Merchants Now Take Stablecoins Instantly

Binance Pay Lights Up French Riviera: 80+ Merchants Now Take Stablecoins Instantly

July 3, 2025
Former OpenAI researcher Lucas Beyer pours cold water on 0 million Meta signing bonus 

Former OpenAI researcher Lucas Beyer pours cold water on $100 million Meta signing bonus 

June 27, 2025
Why the world’s superyachts are getting bigger and bigger

Why the world’s superyachts are getting bigger and bigger

July 2, 2025
Zohran Mamdani doesn’t think there should be billionaires but would work with them

Zohran Mamdani doesn’t think there should be billionaires but would work with them

June 29, 2025
How I localized AI-generated emails for international markets without losing the human touch

How I localized AI-generated emails for international markets without losing the human touch

July 1, 2025
Sen. Tim Scott Sets Sept. 30 Deadline For Crypto Market Structure Legislation

Sen. Tim Scott Sets Sept. 30 Deadline For Crypto Market Structure Legislation

June 27, 2025
BusinessPostCorner.com

BusinessPostCorner.com is an online news portal that aims to share the latest news about following topics: Accounting, Tax, Business, Finance, Crypto, Management, Human resources and Marketing. Feel free to get in touch with us!

Recent News

House of Representatives approves ‘big beautiful bill’ in victory for Donald Trump

House of Representatives approves ‘big beautiful bill’ in victory for Donald Trump

July 3, 2025
Tether Targets South America’s Surplus Power for Low-Carbon Bitcoin Mining – But Will Volatility Bite?

Tether Targets South America’s Surplus Power for Low-Carbon Bitcoin Mining – But Will Volatility Bite?

July 3, 2025

Our Newsletter!

Loading
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2023 businesspostcorner.com - All Rights Reserved!

No Result
View All Result
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources

© 2023 businesspostcorner.com - All Rights Reserved!