
M&S hackers sent abuse and ransom demand directly to CEO
An abusive email sent by the Marks & Spencer hackers to the retailer's boss gloating about the hack and demanding payment has been seen by the BBC.The message to M&S CEO Stuart Machin - which was in broken English - was sent on the 23 April from the hacker group called DragonForce using the email account of an employee.The email confirms for the first time that M&S has been hacked by the ransomware group – something that M&S has so far refused to acknowledge."We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers," the hackers wrote."The dragon wants to speak to you so please head over to [our darknet website]."
The extortion email was shown to the BBC by a cyber security expert.The blackmail message, which includes the n-word, was sent to the M&S CEO and seven other executives.As well as bragging about installing ransomware across the M&S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.Nearly three weeks later customers were informed by the company that their data may have been stolen.The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) - which has provided IT services to M&S for over a decade.The Indian IT worker based in London has an M&S email address but is a paid TCS employee.It appears as though he himself was hacked in the attack.TCS has previously said it is investigating whether it was the gateway for the cyber attack.The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&S.M&S has declined to comment entirely.
'We can both help each other'
A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee. This is further indication that the email is authentic.Sharing the link – the hackers wrote: "let's get the party started. Message us, we will make this fast and easy for us."The criminals also appear to have details about the company's cyber insurance policy too saying "we know we can both help each other handsomely : ))".The M&S CEO has refused to say if the company has paid a ransom to the hackers.DragonForce ended the email with an image of a dragon breathing fire.
The email confirms for the first time the link between M&S's hack and the ongoing Co-op cyber attack, which DragonForce have also claimed responsibility for.The two hacks - which began in late April - have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&S expects its operations to be disrupted until July.Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.DragonForce offers cyber criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.Anyone can sign up and use their malicious software to scramble a victim's data or use their darknet website for their public extortion.Nothing has appeared on the criminal's darknet leak site about either Co-op or M&S but the hackers told the BBC last week that they were having IT issued of their own and would be posting information "very soon."Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&S implies that they are from China.Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.Scattered Spider is not really a group in the normal sense of the word. It's more of a community which organises across sites like Discord, Telegram and forums – hence the description "scattered" which was given to them by cyber security researchers at CrowdStrike.Some Scattered Spider hackers are known to be teenagers in the US and UK.The UK's National Crime Agency said in a BBC documentary about the retail hacks, that they are focusing investigations on the group.The BBC spoke to the Co-op hackers who declined to answer whether or not they were Scattered Spider. "We won't answer that question" is all they said.Two of them said they wanted to be known as "Raymond Reddington" and "Dembe Zuma" after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.In a message to me, they boasted: "We're putting UK retailers on the Blacklist."There have been a series of smaller cyber attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&S and Harrods.
DragonForce offers cyber criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.Anyone can sign up and use their malicious software to scramble a victim's data or use their darknet website for their public extortion.Nothing has appeared on the criminal's darknet leaksite about either Co-op or M&S but the hackers told the BBC they were having IT issues of their own and would be posting information "very soon."Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&S implies that they are from China.In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.The UK's national cyber-crime unit has confirmed to the BBC that the group is one of their key suspects.As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. "We won't answer that question" is all they said.
Sign up for our Tech Decoded newsletter to follow the world's top tech stories and trends. Outside the UK? Sign up here.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


BBC News
15 minutes ago
- BBC News
Pictures reveal secrets of former RAF Neatishead Cold War base
Pictures have revealed the interior of a former Cold War radar station believed to be the country's longest Neatishead in Norfolk was downgraded from an RAF station 20 years ago but is still a military air defence radar of the remaining site, including a nuclear bunker, was sold off to tech entrepreneur William Sachiti, who opened its doors to the media."I've owned this place for about three years, and no, I've actually not explored a lot of it," he admitted. "I think there's about 40% of the bunker I haven't seen yet but what I have done is made sure I've got in touch with people that used to work here to make sure the place is kept alive enough as we slowly refurbish it and bring it back to life."Originally a World War II base, the site was an important part of Britain's air defences during the Cold War. Mr Sachiti said he was using the site to develop technology aimed at covering mobile "notspots" - areas with poor or non-existent phone or data it has emerged that last month the defence secretary issued a High Court writ against Mr Sachiti and his company, Academy of details are not currently available, but Mr Sachiti said: "This is unrelated to any of our current or previous with the MOD, and unrelated to any radar tech which was recently announced."There was a minor dispute which was resolved but I cannot comment on the details."The Ministry of Defence has been asked for comment. Follow Norfolk news on BBC Sounds, Facebook, Instagram and X.


BBC News
30 minutes ago
- BBC News
Head of Cambridgeshire Police to step down after seven years
The chief constable for Cambridgeshire Police will step down from the position in September. Nick Dean has been in the role for seven years after he became head of the force in Dean previously announced he would retire in 2023, but abandoned the plans when he "realised now is not the right time".The force confirmed the end of his contract and applications for the role remain open until the 11 June. Mr Dean joined Norfolk Constabulary in September 1992, serving in both uniform and criminal investigation has more than three decades of police service under his belt and became head of the Cambridgeshire force in September 2023 he announced his plans to retire, but continued in the role following an extension to his chief constable he was accountable for the Cambridgeshire Constabulary and was responsible for command, leadership, response to crime and critical June 2024, he was recognised in the King's Birthday Honours and was awarded a King's Policing Medal for distinguished service.A spokesperson from the Cambridgeshire force said: "I can confirm that Chief Constable Nick Dean's contract has come to an end and he will be leaving in September." 'Funding boost' The Cambridgeshire force is expected to grow between 2025 to follows a £2m funding boost from the government to help visit to Huntingdon, Cambridgeshire, this year, Sir Keir Starmer said visible policing had fallen dramatically in recent years, with 90% of crime left unsolved. He announced £200m would be spent on hiring police in areas including Derbyshire, Yorkshire, Cambridgeshire and on the funding allocation the Cambridgeshire force could increase by 30 police officers, seven police community support officers and 13 special constables. Follow Cambridgeshire news on BBC Sounds, Facebook, Instagram and X.


BBC News
30 minutes ago
- BBC News
Domino's scraps Manningtree takeaway plan after major backlash
People living in England's smallest town are claiming a victory after Domino's scrapped its plans to open a of residents objected to the pizza chain taking over a former bank in Manningtree, Essex, and one said it felt like "an April Fools gag".In letters seen by the BBC, Tendring District Council warned Domino's there had been intense opposition to the proposed High Street shop.A spokeswoman for the chain said there were "limitations" with its plan. Rowan Hunter, who runs The Stour Store next to the earmarked building, said: "I think it's a small victory for a town that wants to be independent. "We want shops here that support each other and local families, so it's a win in that regard." Manningtree is the smallest town in England when it comes to geographical size, at just 19 hectares (47 acres).Tesco Express is the only big name brand on the High Street and the town has several independent takeaways.A tidal wave of opposition against Domino's included the Conservative MP for Harwich and North Essex, Sir Bernard said the chain would take a significant slice out of Manningtree's "distinct character and charm".It was an argument that held weight with the local authority, who subsequently told Domino's its plan was "heading towards a refusal"."I do draw you attention to the strength of local opposition including from Sir Bernard Jenkin MP," council planning officer Alison Pope told a Domino's planner in an email, seen by the said councillors were concerned about the shop's impact on High Street traffic and its heritage. Sarah Mawkes, who runs The Wholefood Store, also objected to Domino's, claiming it threatened "the identity, values and environmental integrity" of the Stephen Ivell, from Lawford, accused those objecting to the plan of being unable to cope with District Council confirmed the plans, submitted on 8 April, had been withdrawn on Domino's spokeswoman said: "We have withdrawn our application in Manningtree due to limitations with the property we intended for our store."We always seek to make any alterations within planning guidelines and given we are unable to make changes to the property to allow efficient deliveries we have decided to explore other options." Follow Essex news on BBC Sounds, Facebook, Instagram and X.