{"id":11803,"date":"2025-06-06T10:23:44","date_gmt":"2025-06-06T14:23:44","guid":{"rendered":"https:\/\/sharewatch.com\/wp\/2025\/06\/06\/ms-hackers-sent-abuse-and-ransom-demand-directly-to-ceo\/"},"modified":"2025-06-06T10:23:44","modified_gmt":"2025-06-06T14:23:44","slug":"ms-hackers-sent-abuse-and-ransom-demand-directly-to-ceo","status":"publish","type":"post","link":"https:\/\/sharewatch.com\/wp\/2025\/06\/06\/ms-hackers-sent-abuse-and-ransom-demand-directly-to-ceo\/","title":{"rendered":"M&#038;S hackers sent abuse and ransom demand directly to CEO"},"content":{"rendered":"<div data-testid=\"byline-new\" data-component=\"byline-block\">\n<p><span>Joe Tidy<\/span><\/p>\n<p><span>Cyber correspondent, BBC World Service<\/span><\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\">\n<p><span>Bloomberg via Getty Images<\/span><\/p>\n<\/div>\n<\/figure>\n<div data-component=\"text-block\">\n<p>The Marks &#038; Spencer hackers sent an abuse-filled email directly to the retailer&#8217;s boss gloating about what they had done and demanding payment, BBC News has learnt.<\/p>\n<p>The message to M&#038;S CEO Stuart Machin &#8211; which was in broken English &#8211; was sent on the 23 April from the hacker group DragonForce using an employee email account.<\/p>\n<p>The email confirms for the first time that M&#038;S has been hacked by the ransomware group \u2013 something that M&#038;S has so far refused to acknowledge.<\/p>\n<p>&#8220;We have marched the ways from China all the way to the UK and have mercilessly raped your company and encrypted all the servers,&#8221; the hackers wrote.<\/p>\n<p>&#8220;The dragon wants to speak to you so please head over to [our darknet website].&#8221;<\/p>\n<\/div>\n<div data-component=\"text-block\">\n<p>The cyber attack has been hugely damaging for M&#038;S, costing it an estimated \u00a3300m. More than six weeks on, it is still unable to take online orders<\/p>\n<p>The extortion email was shown to the BBC by a cyber-security expert.<\/p>\n<p>The message, which includes a racist term, was sent to the M&#038;S CEO and seven other executives.<\/p>\n<p>As well as bragging about installing ransomware across the M&#038;S IT system to render it useless, the hackers say they have stolen the private data of millions of customers.<\/p>\n<p>Nearly three weeks later customers were informed by the company that their data may have been stolen.<\/p>\n<p>The email was sent apparently using the account of an employee from the Indian IT giant Tata Consultancy Services (TCS) &#8211; which has provided IT services to M&#038;S for over a decade.<\/p>\n<p>The Indian IT worker based in London has an M&#038;S email address but is a paid TCS employee.<\/p>\n<p>It appears as though he himself was hacked in the attack.<\/p>\n<p>TCS has previously said it is investigating whether it was the gateway for the cyber-attack.<\/p>\n<p>The company has told the BBC that the email was not sent from its system and that it has nothing to do with the breach at M&#038;S.<\/p>\n<p>M&#038;S has declined to comment entirely.<\/p>\n<\/div>\n<p data-component=\"subheadline-block\">\n<h2>&#8216;We can both help each other&#8217;<\/h2>\n<\/p>\n<div data-component=\"text-block\">\n<p>A darknet link shared in the extortion email connects to a portal for DragonForce victims to begin negotiating the ransom fee.  This is further indication that the email is authentic.<\/p>\n<p>Sharing the link \u2013 the hackers wrote: &#8220;let&#8217;s get the party started. Message us, we will make this fast and easy for us.&#8221;<\/p>\n<p>The criminals also appear to have details about the company&#8217;s cyber-insurance policy too saying &#8220;we know we can both help each other handsomely : ))&#8221;.<\/p>\n<p>The M&#038;S CEO has refused to say if the company has paid a ransom to the hackers.<\/p>\n<p>DragonForce ended the email with an image of a dragon breathing fire.<\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\">\n<\/div>\n<p data-component=\"caption-block\"><figcaption>This dragon image was appended to the hackers email, seen by the BBC<\/figcaption><\/p>\n<\/figure>\n<div data-component=\"text-block\">\n<p>The email confirms for the first time the link between M&#038;S&#8217;s hack and the ongoing Co-op cyber-attack, which DragonForce have also claimed responsibility for.<\/p>\n<p>The two hacks &#8211; which began in late April &#8211; have wrought havoc on the two retailers. Some Co-op shelves were left bare for weeks, while M&#038;S expects its operations to be disrupted until July.<\/p>\n<p>Although we now know that DragonForce is behind both, it is still not clear who the actual hackers are.<\/p>\n<p>DragonForce offers cyber-criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected.<\/p>\n<p>Anyone can sign up and use their malicious software to scramble a victim&#8217;s data or use their darknet website for their public extortion.<\/p>\n<p>Nothing has appeared on the criminal&#8217;s darknet leak site about either Co-op or M&#038;S but the hackers told the BBC last week that they were having IT issues of their own and would be posting information &#8220;very soon.&#8221;<\/p>\n<p>Some researchers say DragonForce are based in Malaysia, while others say Russia. Their email to M&#038;S implies that they are from China.<\/p>\n<p>Speculation has been mounting that a loose collective of young western hackers known as Scattered Spider might be the affiliates behind the hacks and also one on Harrods.<\/p>\n<p>Scattered Spider is not really a group in the normal sense of the word. It&#8217;s more of a community which organises across sites like Discord, Telegram and forums \u2013 hence the description &#8220;scattered&#8221; which was given to them by cyber-security researchers at CrowdStrike.<\/p>\n<p>Some Scattered Spider hackers are known to be teenagers in the US and UK.<\/p>\n<p>The UK&#8217;s National Crime Agency said in a BBC documentary about the retail hacks, that they are focusing investigations on the group.<\/p>\n<p>The BBC spoke to the Co-op hackers who declined to answer whether or not they were Scattered Spider. &#8220;We won&#8217;t answer that question&#8221; is all they said.<\/p>\n<p>Two of them said they wanted to be known as &#8220;Raymond Reddington&#8221; and &#8220;Dembe Zuma&#8221; after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.<\/p>\n<p>In a message to me, they boasted: &#8220;We&#8217;re putting UK retailers on the Blacklist.&#8221;<\/p>\n<p>There have been a series of smaller cyber-attacks on UK retailers since but none as impactful of disruptive as those on Co-op, M&#038;S and Harrods.<\/p>\n<\/div>\n<div data-component=\"text-block\">\n<p>In the early stages of the M&#038;S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to Scattered Spider.<\/p>\n<p>The UK&#8217;s national cyber-crime unit has confirmed to the BBC that the group is one of their key suspects.<\/p>\n<p>As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. &#8220;We won&#8217;t answer that question&#8221; is all they said.<\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\">\n<\/div>\n<\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Joe Tidy Cyber correspondent, BBC World Service Bloomberg via Getty Images The Marks &#038; Spencer hackers sent an abuse-filled email directly to the retailer&#8217;s boss gloating about what they had done and demanding payment, BBC News has learnt. The message to M&#038;S CEO Stuart Machin &#8211; which was in broken English &#8211; was sent on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":11804,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[19,21,20],"tags":[],"class_list":["post-11803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-market","category-news","entry","has-media"],"_links":{"self":[{"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/posts\/11803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/comments?post=11803"}],"version-history":[{"count":0,"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/posts\/11803\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/media\/11804"}],"wp:attachment":[{"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/media?parent=11803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/categories?post=11803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sharewatch.com\/wp\/wp-json\/wp\/v2\/tags?post=11803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}