
DragonForce and Scattered Spider: Inside the hacker groups linked to M&S cyberattack
Marks & Spencer has finally reopened its online orders, months after a cyber attack which is set to cost the British high street retailer £300 million in profits this year.
This comes as a new hacking group has been connected with the incident, after it was revealed the DragonForce group sent M&S CEO Stuart Machin an email days after it faced a major cyberattack gloating about the hack and demanding ransom payment.
The email, seen and reported by the BBC, said: 'We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers.'
DragonForce aren't the only group that have been connected with the attack on the retailer, as the Scattered Spider network had previously been named as the enactors of the social engineering attack.
According to Sergey Shyekevich, a researcher from cybersecurity company Checkpoint, more hacker groups are forming alliances on the dark web.
'Co-operation between two powerful groups is very interesting,' he says. 'It's one outcome we see on the dark web more and more, alliances between big groups.'
Here's all we know about the two hacker groups
What is DragonForce?
DragonForce is a hacker organisation that offers Ransomware to cyber-criminal affiliates for a 20 per cent cut of any ransoms collected. This means that for a fee, they lease out their malware through dark web marketplaces to cyber-criminals.
While the organisation originally started working in 2023, they've had a massive re-marketing of their business model in the past couple of months.
'In the last two months, they started to become very active in one of the biggest dark web forums,' says Sergey, who says they have marketed themselves as a 'Ransomware Cartel', cornering that market on the dark web in the past month.
'They started being more aggressive I think a few weeks before all the attacks in the UK,' he adds.
Researchers have claimed they operate out of Malaysia, with some disputing this and saying they are located in Russia. As well as the M&S hack, DragonForce has been linked to the Co-op cyberattack.
What is Scattered Spider?
Scattered Spider is a community of hackers that targets huge organisations across different sectors using social engineering tactics.
'They're very good at social engineering of different types,' Sergey says, adding that in the past they have used SIM swapping and impersonated IT staff to trick people into letting them use their systems.
Believed to be a community of young adults across the US and UK, the group gained notoriety for their involvement in hacking and extorting two of the largest casino and gambling companies in the United States.
'They understand human nature and how big corporations work,' says Sergey. 'They're very successful.'
In 2023 they were linked to the hacking and extortion of Caesars Entertainment and MGM Resorts International, which led the former to pay a ransom of approximately £11 million ($15 million). They were able to access a significant number of driver's licence numbers and possibly even Social Security numbers of the casino customers through the ransomware demand.
A 17-year-old hacker from the United Kingdom was arrested in connection with the hack and attempted ransom in July 2024.
How did the cyberattack happen?
M&S first disclosed they had experienced a cyberattack on 22 April, which had disrupted their online operations and even halted contactless payments. Hundreds of agency workers at the company were told not to come into work as the retailer dealt with the fallout of the cyberattack.
Customer personal data – which could have included names, email addresses, postal addresses and dates of birth – was also taken by hackers in the attack.
M&S revealed last month that the attack was caused by 'human error', as Mr Machin said in an annual figures report in May that the hackers gained access to the company's IT systems through a third party.
He said at the time: 'We didn't leave the door open, this wasn't anything to do with under-investment. Everyone is vulnerable. For us, we were unlucky on this particular day through some human error.'
Responding to attacks on the retail sector, the NCSC put out advice to the industry and responded to speculation that the Scattered Spider group had used social engineering to target IT help desks and perform password and MFA (multi-factor authentication) resets.
'Criminal activity online – including, but not limited to, ransomware and data extortion – is rampant,' their blog post wrote. 'Attacks like this are becoming more and more common. And all organisations, of all sizes, need to be prepared.'
Deputy Director Paul Foster, head of the NCA's National Cyber Crime Unit, said: 'Specialist NCA cybercrime officers are working closely with law enforcement partners to investigate the recent cyber incidents affecting the retail sector. Identifying the criminals responsible and bringing them to justice is a top priority.
'We are considering the incidents individually, but have a range of hypotheses and are mindful they may be linked.
'The impact of these incidents has been significant and businesses will understandably be concerned. I'd encourage all organisations to follow advice on the NCSC's website to ensure they have effective cyber security measures in place to help prevent attacks.
'I'd also urge those that do unfortunately fall victim to an attack to engage with law enforcement as part of the reporting process. The NCA and policing will investigate covertly and discreetly, as well as support the recovery of systems and data.'
How much money has M&S lost?
The fallout from the cyberattack saw the company lose £650 million of value in a matter of days. M&S said it expected to take an estimated £300 million hit to profits this year, as they predicted disruption to its online business to last into July.
What has M&S said in response?
As M&S reopened its online operations, they put out a statement which said: 'You can now place online orders with standard delivery to England, Scotland and Wales. Delivery to Northern Ireland will resume in the coming weeks.
'We will resume click and collect, next-day delivery, nominated-day delivery and international ordering in the coming weeks.'
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


BBC News
27 minutes ago
- BBC News
Ex-Leicestershire Police officer barred after accessing confidential information
A police officer has been barred from serving again after covertly recording confidential Ellis, who has since resigned from Leicestershire Police, was found to have deliberately and secretly made six audio recordings on his personal phone, as well as taking pictures on the same device during a drugs raid, a misconduct hearing recordings, made between April and October 2020, captured the personal details of his colleagues and members of the public, including names and addresses, and details concerning criminal offences.A panel heard his colleagues said the former officer had "breached their trust by recording them in secret". Mr Ellis admitted to secretly making four recordings and taking photos without telling denied another three instances were done knowingly, with two of those ruled intentional by hearing chairman Steven Cooper, and the third Cooper accepted Mr Ellis required reasonable adjustments, but said this did not make the use of his personal phone "the correct course of action".He added the former officer had chosen "not to use those devices that were provided and recommended to him" and instead used one that was "insecure and had it been lost, would have contained data that was extremely sensitive".His actions were "clearly in breach of data protection rules" and he should have known this as he had only completed training on this a little more than two months before, the panel chairman Cooper ruled that Mr Ellis's behaviour, while not intended to cause harm to his colleagues or the police, was "inappropriate and inexplicable".He added that Mr Ellis should have "foreseen the risk of harm by storing personal and operational data on his personal phone".


BBC News
27 minutes ago
- BBC News
Layton Carr: Bikers pay tribute to boy killed in Gateshead fire
Bikers have paid tribute to a 14-year-old boy killed in a fire at a disused industrial Carr's body was discovered in a building on Fairfield Industrial Park, in the Bill Quay area of Gateshead, on 2 month, his family described him as a "cheeky, happy lad" with "an absolute heart of gold".Twenty-six children have been arrested and released on bail in connection with the blaze as Northumbria Police continues its investigation. The service was held at South Shields Crematorium before the youngster was laid to rest at Harton Cemetery. In a social media post last week, funeral directors said Layton had "a true passion" for motorcycles and they invited anyone with a bike to ride in tribute and "make some much-loved noise in his honour".They added: "He would've absolutely loved that." 'Bright and beautiful' Layton, a pupil at Hebburn Comprehensive School, "was loved by all that met him, and it showed", his family had said in their tribute."He was a family boy that loved his mam and sisters more than anything in the world."Layton, we love you more than any words can ever explain. You will be missed more than you'll ever know. Our bright and beautiful boy." Firefighters were called to the blaze shortly after 19:50 BST. Crews were met with "a severe fire within a section of one of the buildings".It was brought under control just before midnight having broken out in a large building on the estate, which has largely fallen into disrepair in recent than £21,000 has been raised via a GoFundMe appeal set up for Layton's mother. Follow BBC North East on X, Facebook, Nextdoor and Instagram.


BBC News
38 minutes ago
- BBC News
Cornwall seagull sips man's coffee before stealing his mug
A gull has taken revenge on a man who was installing anti-bird spikes in a Cornish town - by drinking his coffee and pinching his worker Darren Pardoe had been bird proofing houses in Porthleven when he stopped at a pub for a coffee on 3 said he had been talking to someone before he turned around to find the gull helping himself to the hot brew. Before he could take action, the feathered thief flew off with the mug. "I think it had remembered me," he joked. Recalling the coffee heist, Mr Pardoe said: "I turn round and sure enough a seagull's got its beak in my coffee... next minute the bird picks up the coffee cup by its handle and takes off across the harbour with it."It flew round the harbour and then landed on the water, put the cup down, and the cup just sank."Mr Pardoe captured a photo of the bird in flight with his coffee mug.