
M&S and Co-Op: BBC reporter on talking to the hackers
When I cautiously asked what this was, the people behind the Telegram account - which had no name or profile picture - gave me the inside track on what they claimed to have done to M&S and the Co-op, in cyber attacks that caused mass disruption.Through messages back-and-forth over the next five hours, it became clear to me that these apparent hackers were fluent English speakers and although they claimed be messengers, it was obvious they were closely linked to - if not intimately involved in - the M&S and Co-op hacks.They shared evidence proving that they had stolen a huge amount of private customer and employee information. I checked out a sample of the data they had given me - and then securely deleted it.
Messages that confirmed suspicions
They were clearly frustrated that Co-op wasn't giving in to their ransom demands but wouldn't say how much money in Bitcoin they were demanding of the retailer in exchange for the promise that they wouldn't sell or give away the stolen data.After a conversation with the BBC's Editorial Policy team, we decided that it was in the public interest to report that they had provided us with evidence proving that they were responsible for the hack. I quickly contacted the press team at the Co-op for comment, and within minutes the firm, who had initially downplayed the hack, admitted to employees, customers and the stock market about the significant data breach. Much later, the hackers sent me a long angry and offensive letter about Co-op's response to their hack and subsequent extortion, which revealed that the retailer narrowly dodged a more severe hack by intervening in the chaotic minutes after its computer systems were infiltrated. The letter and conversation with the hackers confirmed what experts in the cyber security world had been saying since this wave of attacks on retailers began – the hackers were from a cyber crime service called DragonForce.
Who are DragonForce, you might be asking? Based on our conversations with the hackers and wider knowledge, we have some clues.DragonForce offers cyber criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected. Anyone can sign up and use their malicious software to scramble a victim's data or use their darknet website for their public extortion.This has become the norm in organised cyber crime; it's known as ransomware-as-a-service.The most infamous of recent times has been a service called LockBit, but this is all but defunct now partly because it was cracked by the police last year.Following the dismantling of such groups, a power vacuum has emerged. Cue a tussle for dominance in this underground world, leading to some rival groups innovating their offerings.
Power struggle ensues
DragonForce recently rebranded itself as a cartel offering even more options to hackers including 24/7 customer support, for example.The group had been advertising its wider offering since at least early 2024 and has been actively targeting organisations since 2023, according to cyber experts like Hannah Baumgaertner, Head of Research at Silobeaker, a cyber risk protection company. "DragonForce's latest model includes features such as administration and client panels, encryption and ransomware negotiation tools, and more," Ms Baumgaertner said.As a stark illustration of the power-struggle, DragonForce's darknet website was recently hacked and defaced by a rival gang called RansomHub, before re-emerging about a week ago."Behind the scenes of the ransomware ecosystem there seems to be some jostling - that might be for prime 'leader' position or just to disrupt other groups in order to take more of the victim share," said Aiden Sinnott, senior threat researcher from the cyber security company Secureworks.
Who is pulling the strings?
DragonForce's prolific modus operandi is to post about its victims, as it has done 168 times since December 2024 - a London accountancy firm, an Illinois steel maker, an Egyptian investment firm are all included. Yet so far, DragonForce has remained silent about the retail attacks.Normally radio silence about attacks indicates that a victim organisation has paid the hackers to keep quiet. As neither DragonForce, Co-op nor M&S have commented on this point, we don't know what might be happening behind the scenes.Establishing who the people are behind DragonForce is tricky, and it's not known where they are located. When I asked their Telegram account about this, I didn't get an answer. Although the hackers didn't tell me explicitly that they were behind the recent hacks on M&S and Harrods, they confirmed a report in Bloomberg that spelt it out.Of course, they are criminals and could be lying.Some researchers say DragonForce are based in Malaysia, while others say Russia, where many of these groups are thought to be located. We do know that DragonForce has no specific targets or agenda other than making money.And if DragonForce is just the service for other criminals to use – who is pulling the strings and choosing to attack UK retailers?In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to a loose collective of cyber criminals known as Scattered Spider - but this has yet to be confirmed by the police.Scattered Spider is not really a group in the normal sense of the word. It's more of a community which organises across sites like Discord, Telegram and forums – hence the description "scattered" which was given to them by cyber security researchers at CrowdStrike.They are known to be English-speaking and probably in the UK and the US and young – in some cases teenagers. We know this from researchers and previous arrests. In November the US charged five men and boys in their twenties and teens for alleged Scattered Spider activity. One of them is 22-year-old Scottish man Tyler Buchanan, who has not made a plea, and the rest are US based.Crackdowns by police seem to have had little effect on the hackers' determination, though. On Thursday, Google's cyber security division issued warnings that it was starting to see Scattered Spider-like attacks on US retailers now too.As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. "We won't answer that question" is all they said.Perhaps in a nod to the immaturity and attention-seeking nature of the hackers, two of them said they wanted to be known as "Raymond Reddington" and "Dembe Zuma" after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.In a message to me, they boasted: "We're putting UK retailers on the Blacklist."
Sign up for our Tech Decoded newsletter to follow the world's top tech stories and trends. Outside the UK? Sign up here.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Telegraph
a few seconds ago
- Telegraph
The rapist, paedophiles and terror offender spared prison while Lucy Connolly was jailed
Among the criminals handed shorter sentences than Lucy Connolly are a rapist, terror offender, domestic abuser and paedophiles. Mrs Connolly, 42, a former childminder, was released on Thursday after serving more than 300 days behind bars. She was jailed for 31 months after pleading guilty to one count of inciting racial hatred contrary to section 19(1) of the Public Order Act 1986 over a hastily deleted post on X shared in the aftermath of the Southport killings. In the post, Mrs Connolly called for hotels housing asylum seekers to be set on fire. Mrs Connolly, who lost her son Harry when he was 19 months old and cares for her sick husband, deleted the post fewer than four hours later – but not before it had been viewed 310,000 times. At an appeal hearing in May, Mrs Connolly's lawyers argued that she had not understood fully what she was pleading guilty to, and that the original judge had failed to give enough weight to various mitigating factors including the welfare of her 12-year-old daughter. That appeal was unsuccessful and the three Court of Appeal judges presiding over the case ruled that her sentence had not been 'manifestly excessive'. While serving her sentence, Mrs Connolly has been kept at HMP Peterborough, which houses other high-profile offenders accused of the most egregious crimes. Among them is Virginia McCullough, a 37-year-old woman who murdered her elderly mother and father and then continued to live at the family home for years after hiding their bodies in the property. Also at the prison is Rekha Kumari-Baker, a mother who stabbed her children to death at their home in Cambridgeshire while they slept. Since Mrs Connolly has been behind bars, her sentence has been compared with those of others charged with what many would say are far more serious crimes. Below, The Telegraph highlights some of the criminals apparently deemed less of a threat to society than Mrs Connolly. The BBC presenter who avoided jail over child sex abuse images Huw Edwards avoided an immediate jail sentence in September 2024. The BBC newsreader admitted accessing indecent images of children. It was found that he had paid a paedophile, from whom he received 41 illegal images of child sex abuse, and asked for them to be sent to him even after he was told the people in the pictures 'looked young'. Deeming that Edwards did not need to be jailed to protect the public, the chief magistrate accepted that he understood the gravity of his offence and was responding to therapy. He handed him a six-month sentence, suspended for two years. The paedophile who argued he should get same treatment as Edwards A man who received child abuse images from the same source as Edwards was given a suspended sentence after arguing that he should get the same treatment as the BBC presenter. In December, Jac Davies was given a 12-month sentence, suspended for two years, after pleading guilty to the possession of class A drugs and indecent images of children. The images were sent to him by the same man who sent pictures to Edwards. The child rapist handed a suspended sentence A convicted child rapist avoided jail owing to the prison overcrowding crisis in 2023. Rees Newman was jailed for two years after being convicted of the historic rape of a child under the age of 14. A judge agreed to suspend his sentence for two years. When, months later, he breached the terms of his sentence by flying to Egypt without notifying officers and was hauled back in front of the court, he avoided jail a second time. The judge said: 'The only reason you have escaped immediate custody today is because of the prison overcrowding crisis.' The domestic abuser given fewer than two years A man who was found to have been mentally, physically and emotionally abusive to a woman over a three-year period was given 21 months in prison, suspended for two years. Daniel Ashbrook pleaded guilty to controlling and coercive behaviour in November 2024. He was also handed a 10-year restraining order. In a statement, the woman said she had been affected so badly by his behaviour that she doubted she would 'even be here today' without her family's support. The doctor found with child abuse images Mansoor Khan was a top NHS consultant, a father of four and was deemed a 'pillar of society' before he was found with more than 100 'abhorrent and perverted' images of children on his phone. Khan was spared jail at his sentencing in 2023. He was handed eight months, suspended for two years. The rapist jailed for 18 months A man who pleaded guilty to sexual assault and indecent exposure was given an 18-month sentence, suspended for two years. Nikhil Chopra was arrested after police were alerted to the assault in Swindon in September 2023 by members of the public who were concerned for a woman's safety. Chopra escaped immediate jail and was told to complete 55 days of rehabilitation, 43 days in a sex offending programme and ordered to pay a £187 victim surcharge. The lab technician convicted of terror offences – who avoided a prison sentence A man who was convicted of seven charges of possessing terrorist information was sentenced to 18 months in prison, suspended for two years, in February 2024 – six months before the disorder that followed the Southport killings. Charles Cannon, who was described as having 'a dangerous mindset', collected documents on how to make homemade explosives and weapons. He spoke 'enthusiastically of the stabbing of asylum seekers'. A court heard that he 'repeated on many occasions anti-Semitic tropes' and 'said he would kill, when speaking about people of colour'. A guide to making explosives was found on his mobile phone.


The Independent
29 minutes ago
- The Independent
Asylum hotels latest: Number of migrants in hotels rises under Labour but deportations up by 25%
The number of asylum seekers being housed temporarily in UK hotels has risen by 8 per cent under Labour on the same point last year, Home Office data shows. However, the number of people returned from the UK has gone up by 25 per cent in the past year, with 9,100 enforced returns in the twelve months to July. With numbers falling in recent months, government spending on asylum in the UK also stood at £4.76 billion in 2024/25, down 12 per cent from a record £5.38 billion in 2023/24. It comes as Labour -run councils are among those considering legal challenges against the use of hotels to house asylum seekers, as the government scrambles to draw up a contingency plan. Carol Dean, leader of Labour-controlled Tamworth Council, said her authority had previously decided against legal action but was now 'carefully assessing' what the decision might mean for the area, adding it was a 'potentially important legal precedent'. Conservative leader Kemi Badenoch has called on Tory local councils to take inspiration from the Epping legal ruling to launch challenges of their own. Labour is boosting returns The number of people returned from the UK has gone up by 25 per cent in the past year, with 9,100 enforced returns in the twelve months to July. The majority of this was under the Labour government. Migrants from Albania, Romania, Brazil and India have faced the highest number of enforced returns. Voluntary returns are also up by 13 per cent. Some 1,000 staff have been reallocated to immigration enforcement, which the Home Office notes may have boosted returns. Alicja Hagopian21 August 2025 09:53 Government spending on asylum down by 12% Home Office spending on asylum in the UK stood at £4.76 billion in 2024/25, down 12 per cent from a record £5.38 billion in 2023/24, Government figures show. The total covers all Home Office costs related to asylum, including direct cash support and accommodation, plus wider staffing and other migration and borders activity. It does not include costs relating to the interception of migrants who travel to the UK across the English Channel in small boats. The figure for 2024/25, £4.76 billion, is more than three times the equivalent amount in 2020/21 (£1.34 billion) and is more than 10 times the total a decade ago in 2014/15 (£0.47 billion). Holly Evans21 August 2025 09:52 Number of asylum claims awaiting decision drops as Labour push through backlog Labour have been making progress in slashing the asylum backlog, with the number of asylum claims awaiting a decision continuing to fall. The total number waiting was 70,532 in June this year, down on more than 90,000 at the end of 2024. The numbers waiting for more than 12 months for a decision are also falling significantly, although some 19,000 people are still in this position. Some 30,637 had been waiting for over a year on their asylum decision in September last year. Holly Bancroft21 August 2025 09:47 Number of asylum seekers in hotels dips in last three months The number of asylum seekers in hotels has gone down very slightly from 32,345 in March this year, to 32,059 in June 2025. Asylum seekers in other forms of accommodation has also dipped, with the number in dispersed accommodation going from 66,683 in March to 66,234 in June this year. There are a total of 106,075 people in receipt of asylum support, a fall of around 600 people in the past three months. The number in hotels in June last year was 29,585 compared to 32,059 this year - a rise of 8 per cent. However the number in hotels has been falling since the end of last year. Holly Bancroft21 August 2025 09:39 Dudley council seeking legal advice for injunction against asylum hotel Patrick Harley, Conservative leader of Dudley council, told The Independent that he had instructed the council's legal team to seek an injunction against an asylum hotel in the borough. He said: "For years now we have taken a robust approach to handling Serco and the Home Office in relation to the placement of asylum seekers in hotels. We have previously threatened legal action against both Serco and individuals. 'As a result we only have one hotel in the borough that has been commandeered by Serco for this use." He added: "I have instructed our legal team to seek a similar injunction against Serco and the Home Office in relation to what's happened yesterday at Epping". Holly Evans21 August 2025 09:19 Labour-run councils among those considering legal action Several local authorities, including some run by the Labour Party, said they were looking at their options to take similar action. Carol Dean, leader of Labour-controlled Tamworth Council, said her authority had previously decided against legal action but was now 'carefully assessing' what the decision might mean for the area, adding it was a 'potentially important legal precedent'. A spokesperson for Wirral Council, which has seen protests outside a hotel in Hoylake, said the authority was 'considering the detail' of Tuesday's judgment. Other authorities have ruled out legal action, with the leader of Labour-run Newcastle City Council saying she was 'confident' the council could end the use of hotels without going to court. Karen Kilgour said: 'We recognise that people seeking asylum include families, women, and children, many of whom have faced unimaginable trauma. 'Newcastle has a proud history of offering sanctuary, and we stand ready to play our part – but it must be done in a way that works for our city and supports the dignity and wellbeing of those who come here.' Holly Evans21 August 2025 09:02 Chris Philp defends use of Bibby Stockholm barge The shadow home secretary has defended the Bibby Stockholm barge, as he suggested the government should move asylum seekers being housed in hotels to army barracks or modular accommodation. When asked on Sky News what other options the government had following Epping Council's legal win - with the Bibby Stockholm being highlighted as a failure - Chris Philp said: 'I'm not sure I would say it didn't work. It had some initial issues with I think its water system, but it did get up and running. That would have held 500 people so you could have actually added more of those barges. 'They're used to accommodate works on oil and gas installations so they're not prison ships they're used for workers ordinarily. But Labour decommissioned that so that's no longer an option.' The Bibby Stockholm was a hugely controversial barge that was used to house asylum seekers from 2023-2024. It was plagued with problems, including a discovery of legionella bacteria in the water that forced the temporary evacuation of residents onboard. An asylum seeker, Leonard Farruku, also took his own life on the barge in 2023, and other residents warned the site was unsafe and overcrowded. Holly Evans21 August 2025 08:48 Labour braced for wave of legal action over migrant hotels as immigration crisis deepens Labour is bracing for a wave of legal action that could displace thousands of asylum seekers after councils across England signalled they could seek to ban hotels for migrants. Home Office minister Dan Jarvis has said that the government is working on contingency plans for housing asylum seekers after Epping Forest District Council was granted a temporary High Court injunction, forcing the removal of the 136 migrants who live there, in a landmark ruling on Tuesday. The order blocks asylum seekers from being housed at the Bell Hotel in Epping, Essex, which has been the site of a series of violent protests that have seen police officers injured and multiple people arrested for disorder in recent weeks. Labour braced for wave of legal action over migrant hotels as crisis deepens Reform's deputy leader Richard Tice urged residents to protest outside more migrant hotels to force councils to take legal action to ban asylum seekers Holly Evans21 August 2025 08:37 How many asylum seekers are in hotels across the UK? The most recent Home Office data showed there were 32,345 asylum seekers being housed temporarily in UK hotels at the end of March. This was down 15 per cent from the end of December, when the total was 38,079. New figures – published among the usual quarterly immigration data release – are expected on Thursday, showing numbers in hotels at the end of June. Figures for hotels published by the Home Office date back to December 2022 and showed numbers hit a peak at the end of September 2023 when there were 56,042 asylum seekers in hotels. Holly Evans21 August 2025 08:29 Farage calls for protests following Epping ruling Nigel Farage has called for peaceful protests outside hotels housing asylum seekers to put pressure on local authorities to take the same route as Epping Forest. Writing in The Telegraph, he said: 'Now the good people of Epping must inspire similar protests around Britain. 'Wherever people are concerned about the threat posed by young undocumented males living in local hotels and who are free to walk their streets, they should follow the example of the town in Essex. 'Let's hold peaceful protests outside the migrant hotels, and put pressure on local councils to go to court to try and get the illegal immigrants out; we now know that together we can win.' The Reform UK leader has indicated that councils run by his party will consider their own legal challenges. Holly Evans21 August 2025 08:22


The Sun
30 minutes ago
- The Sun
Tesco hiking price of popular meal deal from TODAY as furious shoppers threaten to boycott
TESCO is hiking the price of its popular meal deal by 25p TODAY - and shoppers are furious. The supermarket is increasing the price of the lunchtime offer from £3.60 to £3.85 with a Clubcard. 1 The Sun exclusively revealed that Tesco was planning to roll out higher prices earlier this week - and those without the loyalty card will see the cost increase to £4.25, up from £4. The cost of the Premium meal deal will also change to £5.50, up from £5, for those with a Clubcard and £6 for those without. The news broke after an insider said it was now "hardly a deal", and posted a picture of shelf labels showing the new price. Now, shoppers are threatening to boycott the deal. Another user responded to the thread on "Might as well get rid of the meal deal if Tesco keeps upping the price." A second added: "I will be boycotting the meal deal from when this hike occurs." A third moaned: "£3.60 i could still defend, getting a bit mad now tho." Exactly a year ago Tesco put up the price of the meal deal from £3.40 to £3.60, while non-Clubcard holders were charged £4, up from £3.90. And in October 2022, the deal increased for the first time in a decade from £3 to £3.40 for Clubcard members, and from £3.50 to £3.90 for those without a loyalty card. Tesco's lunchtime meal deal is hugely popular for its variety of choices, including sandwiches, wraps and sushi selections for the main options, snacks of crisps, chocolate and fruit, and drinks such as Lucozade and cold coffee. Other supermarkets offer similar deals, and have also sparked fury over price hikes. In June, Sainsbury's raised the cost of its lunchtime meal deal by 20p, from £3.75 to £3.95. And back in April Tesco increased the cost of its popular dinnertime Finest Dine In meal deal. The offer, consisting of a main, side, dessert and drink for two people, previously cost £12 with a Clubcard, but has risen to £15. A Tesco spokesperson said today: 'Our meal deal remains great value and the ideal way to grab lunch on-the-go at just for a main, snack and drink when bought with a Clubcard. 'With more than 20m possible combinations the Tesco meal deal has got something for every taste, from a classic Chicken Club Sandwich to Tesco Korean Style Chicken Dragon Rolls.' It's understood new products will be introduced into the Premium meal deal in the coming days, such as a new Finest Salmon Konbini Roll and Finest Gochujang Konbini Roll. Currently the most popular items in the basic meal deal are the Tesco Chicken Club Sandwich for main, Tesco Egg Protein Pot as the snack, and Coca-Cola 500ml. These would currently cost £6.50 when purchased separately, giving Clubcard members a saving of £2.65. Supermarket prices keep soaring Supermarkets have been forced to hike their prices due to increases in costs. Families have been warned the cost of their weekly shop will spiral this year as it's predicted food inflation will climb to 6 percent by the end of 2025. Food inflation in July was up to 4% after the sixth monthly rise in a row — driven largely by meat and tea. Retailers say they've had to increase prices because of higher wage costs after the rise in National Insurance contributions for employers. How to save money at Tesco EVERY little helps when it comes to saving money at Tesco. The Sun's Head of Consumer Tara Evans explains how you can save money at the UK's biggest supermarket. Clubcard points Tesco first launched it's loyalty scheme back in 1995. You get one point for every £1 you spend in store. If you spend points in store then 100 points is worth £1. You can spend your points via its reward partners and get triple and even sometimes quadruple the value. Extend Clubcard points You can find lost Clubvcard points and find the last two years of unused vouchers by logging into the Tesco Clubcard site. Clubcard prices If you don't have a Clubcard then you will miss out on its cheaper Clubcard prices. However, don't forget to check prices before you shop because it might not be cheaper than elsewhere, especially on big value items like washing powder and loo roll. Yellow stickers Shops do vary the time they reduce groceries with yellow stickers but Tesco tends to be between 7pm and 9pm. Save money if you shop online If you get your Tesco food shop delivered then it might be worth buying a delivery saver pass to help cut the cost of delivery fees. If you live near a Tesco then you can get click and collect slots of as little as 25p, so it might be cheaper than getting your food delivered.