Marks & Spencer Hack Confirmed as DragonForce Claims Responsibility and Sends Ransom Email to CEO
The BBC has confirmed that Marks & Spencer (M&S) suffered a ransomware attack by the hacker group DragonForce. The breach, initially unacknowledged by M&S, was confirmed when the attackers sent a threatening and abusive email to CEO Stuart Machin and other executives, claiming to have encrypted company servers and stolen customer data. The message was sent from a compromised account belonging to an employee of Tata Consultancy Services (TCS), M&S’s long-time IT service provider. TCS denies that its systems were the point of entry for the hackers.
The attackers also shared a link to their darknet portal for ransom negotiation and referred to details of M&S’s cyber insurance policy, implying insider knowledge. The group suggested a quick resolution if contacted and hinted at their global presence. The hack disrupted M&S operations, with recovery expected to last until July. DragonForce is also responsible for a similar attack on Co-op, which suffered major supply disruptions. Although DragonForce operates via a ransomware-as-a-service model, the identities of the affiliates remain uncertain. Speculation points to a group known as Scattered Spider, a decentralized network of young hackers in the West. The UK’s National Crime Agency is investigating the connection.
