• Latest
  • Trending
  • All

Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre

May 5, 2025

Polls open on Thursday for the Makerfield by-election

June 16, 2026

Social media ban – bold and blunt, but no silver bullet

June 16, 2026

Alessio Dionisi: Watford appoint Italian as new head coach

June 15, 2026

Fox to buy Roku streaming firm in $22bn deal

June 15, 2026

Why I sold my business to my staff

June 15, 2026

The costs and challenges facing the 2026 World Cup

June 15, 2026

New microplastics research examines River Thames pollution

June 15, 2026

Reform pledges new tax on hiring foreign workers

June 15, 2026

Gang guilty of organised crime in £4m cocaine and dirty money ring

June 15, 2026

Pensioner suffocated neighbour and recorded his dying words, court told

June 15, 2026

Reports nurses told by police to show ID to masked men during trouble – O'Neill

June 15, 2026

World Cup 2026: Nestory Irankunda – the refugee who quit Bayern to make Australia history

June 15, 2026
News
  • Login
  • Home
  • News
  • Sports
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Tuesday, June 16, 2026
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    World Cup 2026: Nestory Irankunda – the refugee who quit Bayern to make Australia history

    Trump and thousands of others watch UFC fight on White House lawn

    South African TV star arrested after allegedly kidnapping man in girlfriend dispute

    Australia demands answers after girl taken hostage is shot dead by Pakistan police

    Norwegian crown princess's son found guilty of two counts of rape

    US musician Oliver Tree dies in helicopter collision in Brazil

    US and Iran agree deal to end war as Trump says Strait of Hormuz to reopen

    'Boyfriend duties call,' Trudeau says after skipping Canada match to watch Perry

    Clinical Australia upset Turkey in World Cup opener

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Polls open on Thursday for the Makerfield by-election

    Alessio Dionisi: Watford appoint Italian as new head coach

    Reform pledges new tax on hiring foreign workers

    Gang guilty of organised crime in £4m cocaine and dirty money ring

    Pensioner suffocated neighbour and recorded his dying words, court told

    Reports nurses told by police to show ID to masked men during trouble – O'Neill

    Starmer set to ban under-16s from major social media platforms

    Hamilton says Barcelona win beyond wildest dreams

    Sinkholes near Purley bridge halt Gatwick trains

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    Fox to buy Roku streaming firm in $22bn deal

    Why I sold my business to my staff

    Oil prices slide after Pakistan announces deal between US and Iran

    UK electric car sales target set to be weakened

    Why the US economy keeps defying the odds

    Teen plans to leave uni 'debt free' after making £35,000 selling vintage football shirts

    Beauty Pie LED mask ad banned over misleading anti-wrinkle claim

    Elon Musk becomes world's first trillionaire as SpaceX soars in stock market debut

    'I was employee number one at SpaceX'

  • Tech
  • Entertainment & Arts

    Meghan hits red carpet at Power of Women in Hollywood

    Margot Robbie unable to speak at Saltburn premiere

    Barbra Streisand: Siri can now pronounce my name

    Wes Anderson’s The Grand Budapest Hotel inspires cinema’s look

    Taylor Swift/ Travis Kelce romance reaches White House

    The Killers booed at Georgia concert after inviting Russian fan on stage

    Watch: Memorable moments from Parkinson's star-studded show

    Tom Jones: Neighbour surprised to find singer in flat below

    Black Country Folk Festival showcases local musicians

    Watch: Australians set new world record with Tina Turner dance

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre

May 5, 2025
in Tech
5 min read
238 15
0
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Joe Tidy

Cyber correspondent, BBC World Service

Getty Images People walking in front of Marks and Spencer store front.Getty Images

The National Cyber Security Centre (NCSC) has warned that criminals launching cyber attacks at British retailers are impersonating IT help desks to break into organisations.

Hackers have targeted Marks & Spencer, Co-op and Harrods in the last two weeks, and on Friday the anonymous group told the BBC there will be more attacks soon.

Now the NCSC, the government agency responsible for cyber security, has issued guidance to organisations urging them to review their IT help desk “password reset processes” to reduce their chances of getting hacked.

“We believe by following best practice, all companies and organisations can minimise the chances of falling victim to actors like this,” it said.

It said firms should reassess how their IT help desk “authenticates staff members” before resetting passwords, especially senior employees with access to high-level parts of an IT network.

It highlighted press speculation around “social engineering” as a way hackers may have gained access to accounts.

Criminals use social engineering techniques to get people to trust them when they email, text or call pretending to be from a company’s IT help desk – ultimately tricking employees into handing over their log in passwords and security codes.

This also works the other way – calling people who work on the help desk and pretending to be an employee locked out of their account.

Cyber security experts now recommend further layers of security to deal with these sorts of attacks.

“Having code words that get used when an employee phones up to change their credentials, such as “BluePenguin”, is one thing being discussed in the cyber community as a way to check that the member of staff is genuine,” said Lisa Forte from cyber security firm Red Goat.

“Ultimately it comes back to the same issue with login credentials as always – we need multiple ways to do it to ensure it isn’t easy to bypass.”

NCSC advice

The NCSC advice is the strongest hint yet the hackers are using tactics most commonly associated with a collective of English-speaking cyber criminals nicknamed Scattered Spider.

The name derives from “spider” being the label given to financially motivated cyber criminals, while “scattered” is because they are not a cohesive, organised gang.

In the past two years these disparate hackers, in their teens or early twenties, have coordinated and planned attacks on Discord and Telegram to breach dozens of companies and steal or scramble data to extort their victims.

The NCSC does not specifically name the group as being responsible for the current wave of attacks, but acknowledges Scattered Spider are known for these types of hacks.

In other NCSC advice, cyber defenders are being urged to watch out for “Risky Logins”.

This means looking out for when and where employees have logged in from – for example late at night or from strange locations.

Although cyber criminals could be anywhere in the world, young English-speaking hackers in the UK and US have become adept at using social engineering in their attacks.

Scattered Spider hacks

Scattered Spider hackers have been responsible for high profile attacks including the coordinated moves against casinos in Las Vegas in which MGM Grand Casinos and Caesar’s Palace were hit in quick succession.

There have been six arrests in the last year of hackers accused of being from Scattered Spider in the US and UK.

In July 2024 a 17-year-old from Walsall was arrested as part of an FBI investigation into the MGM hack – and months later a person of the same age and location was arrested in connection with another hack on Transport for London.

Police would not say if the alleged hacker was the same person.

On Friday, the hackers responsible for the current wave of attacks spoke to the BBC.

The criminals repeatedly denied they are Scattered Spider hackers and would only call themselves DragonForce – the name of a cyber crime service hackers can use for malicious software and extortion.

The hackers, who were fluent English speakers, revealed to the BBC they had compromised Co-op and stolen a large amount of customer and employee data.

They would not discuss the M&S hacks. But it is thought DragonForce ransomware was used to scrambled the firm’s IT servers.

While the NCSC said it “had insights”, it added it was “not yet in a position to say if these attacks are linked”.

“We are working with the victims and law enforcement colleagues to ascertain that,” it said.



Source link

Tags: BewarecallscentreCoopcyberhacksphony

Related Posts

Social media ban – bold and blunt, but no silver bullet

June 16, 2026
0

The BBC's technology editor Zoe Kleinman on the big changes coming down the line for young people online. ...

Social media on trial: Four important cases to watch

June 15, 2026
0

Social media firms face thousands of lawsuits, the BBC looks at four which could be significant. Source link

Who is Elon Musk and what is his net worth?

June 14, 2026
0

The boss of X, Tesla and SpaceX, already the world's richest person, is now also its first trillionaire. ...

  • Lee McGregor: Scot seeks world title in 2025 & Nathaniel Collins bout

    677 shares
    Share 271 Tweet 169
  • Belgian footballer arrested in cocaine investigation

    533 shares
    Share 213 Tweet 133
  • Next to raise prices to help pay for rising wage costs

    531 shares
    Share 212 Tweet 133
  • South Wales Police officers injured, one arrested

    525 shares
    Share 210 Tweet 131
  • Charities to get £15m fund to save surplus farm food

    516 shares
    Share 206 Tweet 129
  • Trending
  • Comments
  • Latest

Lee McGregor: Scot seeks world title in 2025 & Nathaniel Collins bout

January 16, 2025

Belgian footballer arrested in cocaine investigation

January 27, 2025

Next to raise prices to help pay for rising wage costs

January 7, 2025

World Cup 2022: TikTok brings football fever to millions of fans

0

UK economy will get worse before it gets better, warns chancellor

0

One of Central America’s most active volcanoes erupts again

0

Polls open on Thursday for the Makerfield by-election

June 16, 2026

Social media ban – bold and blunt, but no silver bullet

June 16, 2026

Alessio Dionisi: Watford appoint Italian as new head coach

June 15, 2026

Categories

Politics

Polls open on Thursday for the Makerfield by-election

June 16, 2026
0

Polls open on Thursday for the Makerfield by-election with 14 candidates vying to become the constituency's MP Source...

Read more

Social media ban – bold and blunt, but no silver bullet

June 16, 2026
News

© 2023 GODJ - NEWS CORP - news.godj.com.

Explore NEWS.GODJ.COM

  • Home
  • News
  • Sports
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

© 2023 GODJ - NEWS CORP - news.godj.com.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.