• Latest
  • Trending
  • All

BBC reporter on talking to the hackers

May 18, 2025

Gang guilty of organised crime in £4m cocaine and dirty money ring

June 15, 2026

Pensioner suffocated neighbour and recorded his dying words, court told

June 15, 2026

Reports nurses told by police to show ID to masked men during trouble – O'Neill

June 15, 2026

World Cup 2026: Nestory Irankunda – the refugee who quit Bayern to make Australia history

June 15, 2026

Trump and thousands of others watch UFC fight on White House lawn

June 15, 2026

South African TV star arrested after allegedly kidnapping man in girlfriend dispute

June 15, 2026

Australia demands answers after girl taken hostage is shot dead by Pakistan police

June 15, 2026

Norwegian crown princess's son found guilty of two counts of rape

June 15, 2026

US musician Oliver Tree dies in helicopter collision in Brazil

June 15, 2026

US and Iran agree deal to end war as Trump says Strait of Hormuz to reopen

June 15, 2026

'Boyfriend duties call,' Trudeau says after skipping Canada match to watch Perry

June 15, 2026

Taboo subjects on the table at women's health event

June 15, 2026
News
  • Login
  • Home
  • News
  • Sports
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Monday, June 15, 2026
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    World Cup 2026: Nestory Irankunda – the refugee who quit Bayern to make Australia history

    Trump and thousands of others watch UFC fight on White House lawn

    South African TV star arrested after allegedly kidnapping man in girlfriend dispute

    Australia demands answers after girl taken hostage is shot dead by Pakistan police

    Norwegian crown princess's son found guilty of two counts of rape

    US musician Oliver Tree dies in helicopter collision in Brazil

    US and Iran agree deal to end war as Trump says Strait of Hormuz to reopen

    'Boyfriend duties call,' Trudeau says after skipping Canada match to watch Perry

    Clinical Australia upset Turkey in World Cup opener

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Gang guilty of organised crime in £4m cocaine and dirty money ring

    Pensioner suffocated neighbour and recorded his dying words, court told

    Reports nurses told by police to show ID to masked men during trouble – O'Neill

    Starmer set to ban under-16s from major social media platforms

    Hamilton says Barcelona win beyond wildest dreams

    Sinkholes near Purley bridge halt Gatwick trains

    Glasgow race attacks a 'mark against the reputation of the city'

    Jade Jones could face Sheena Bathory after dominant second boxing win

    Days of violence 'a stain on NI's international reputation'

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    Oil prices slide after Pakistan announces deal between US and Iran

    UK electric car sales target set to be weakened

    Why the US economy keeps defying the odds

    Teen plans to leave uni 'debt free' after making £35,000 selling vintage football shirts

    Beauty Pie LED mask ad banned over misleading anti-wrinkle claim

    Elon Musk becomes world's first trillionaire as SpaceX soars in stock market debut

    'I was employee number one at SpaceX'

    Reporter Reads

    Elon Musk’s SpaceX raises $75bn ahead of record stock market debut

  • Tech
  • Entertainment & Arts

    Meghan hits red carpet at Power of Women in Hollywood

    Margot Robbie unable to speak at Saltburn premiere

    Barbra Streisand: Siri can now pronounce my name

    Wes Anderson’s The Grand Budapest Hotel inspires cinema’s look

    Taylor Swift/ Travis Kelce romance reaches White House

    The Killers booed at Georgia concert after inviting Russian fan on stage

    Watch: Memorable moments from Parkinson's star-studded show

    Tom Jones: Neighbour surprised to find singer in flat below

    Black Country Folk Festival showcases local musicians

    Watch: Australians set new world record with Tina Turner dance

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Business

BBC reporter on talking to the hackers

May 18, 2025
in Business
9 min read
236 17
0
493
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Joe Tidy

Cyber correspondent

BBC A man with brown hair and wearing a light blue shirt looks in contemplation.BBC

Joe Tidy interacted with hackers who claimed to have done the M&S and Co-op hack

Almost daily, my phone pings with messages from hackers of all stripes.

The good, the bad, the not-so-sure.

I’ve been reporting on cyber security for more than a decade, so I know that many of them like to talk about their hacks, findings and escapades.

About 99% of these conversations stay firmly locked in my chat logs and don’t lead to news stories. But a recent ping was impossible to ignore.

“Hey. This is Joe Tidy from the BBC reporting on this Co-op news, correct?” the hackers messaged me on Telegram.

“We have some news for you,” they teased.

When I cautiously asked what this was, the people behind the Telegram account – which had no name or profile picture – gave me the inside track on what they claimed to have done to M&S and the Co-op, in cyber attacks that caused mass disruption.

Through messages back-and-forth over the next five hours, it became clear to me that these apparent hackers were fluent English speakers and although they claimed to be messengers, it was obvious they were closely linked to – if not intimately involved in – the M&S and Co-op hacks.

They shared evidence proving that they had stolen a huge amount of private customer and employee information.

I checked out a sample of the data they had given me – and then securely deleted it.

A shop fridge with almost empty shelves, and a sign stuck on the window which says "Sorry we are having some availability issues which will be resolved shortly"

Shoppers have been met with empty shelves at some UK Co-op stores in recent weeks

Messages that confirmed suspicions

They were clearly frustrated that Co-op wasn’t giving in to their ransom demands but wouldn’t say how much money in Bitcoin they were demanding of the retailer in exchange for the promise that they wouldn’t sell or give away the stolen data.

After a conversation with the BBC’s Editorial Policy team, we decided that it was in the public interest to report that they had provided us with evidence proving that they were responsible for the hack.

I quickly contacted the press team at the Co-op for comment, and within minutes the firm, who had initially downplayed the hack, admitted to employees, customers and the stock market about the significant data breach.

Much later, the hackers sent me a long angry and offensive letter about Co-op’s response to their hack and subsequent extortion, which revealed that the retailer narrowly dodged a more severe hack by intervening in the chaotic minutes after its computer systems were infiltrated. The letter and conversation with the hackers confirmed what experts in the cyber security world had been saying since this wave of attacks on retailers began – the hackers were from a cyber crime service called DragonForce.

Who are DragonForce, you might be asking? Based on our conversations with the hackers and wider knowledge, we have some clues.

DragonForce offers cyber criminal affiliates various services on their darknet site in exchange for a 20% cut of any ransoms collected. Anyone can sign up and use their malicious software to scramble a victim’s data or use their darknet website for their public extortion.

This has become the norm in organised cyber crime; it’s known as ransomware-as-a-service.

The most infamous of recent times has been a service called LockBit, but this is all but defunct now partly because it was cracked by the police last year.

Following the dismantling of such groups, a power vacuum has emerged. Cue a tussle for dominance in this underground world, leading to some rival groups innovating their offerings.

Power struggle ensues

DragonForce recently rebranded itself as a cartel offering even more options to hackers including 24/7 customer support, for example.

The group had been advertising its wider offering since at least early 2024 and has been actively targeting organisations since 2023, according to cyber experts like Hannah Baumgaertner, Head of Research at Silobreaker, a cyber risk protection company.

“DragonForce’s latest model includes features such as administration and client panels, encryption and ransomware negotiation tools, and more,” Ms Baumgaertner said.

As a stark illustration of the power-struggle, DragonForce’s darknet website was recently hacked and defaced by a rival gang called RansomHub, before re-emerging about a week ago.

“Behind the scenes of the ransomware ecosystem there seems to be some jostling – that might be for prime ‘leader’ position or just to disrupt other groups in order to take more of the victim share,” said Aiden Sinnott, senior threat researcher from the cyber security company Secureworks.

Who is pulling the strings?

DragonForce’s prolific modus operandi is to post about its victims, as it has done 168 times since December 2024 – a London accountancy firm, an Illinois steel maker, an Egyptian investment firm are all included. Yet so far, DragonForce has remained silent about the retail attacks.

Normally radio silence about attacks indicates that a victim organisation has paid the hackers to keep quiet. As neither DragonForce, Co-op nor M&S have commented on this point, we don’t know what might be happening behind the scenes.

Establishing who the people are behind DragonForce is tricky, and it’s not known where they are located. When I asked their Telegram account about this, I didn’t get an answer. Although the hackers didn’t tell me explicitly that they were behind the recent hacks on M&S and Harrods, they confirmed a report in Bloomberg that spelt it out.

Of course, they are criminals and could be lying.

Some researchers say DragonForce are based in Malaysia, while others say Russia, where many of these groups are thought to be located. We do know that DragonForce has no specific targets or agenda other than making money.

And if DragonForce is just the service for other criminals to use – who is pulling the strings and choosing to attack UK retailers?

In the early stages of the M&S hack, unknown sources told cyber news site Bleeping Computer that evidence is pointing to a loose collective of cyber criminals known as Scattered Spider – but this has yet to be confirmed by the police.

Scattered Spider is not really a group in the normal sense of the word. It’s more of a community which organises across sites like Discord, Telegram and forums – hence the description “scattered” which was given to them by cyber security researchers at CrowdStrike.

They are known to be English-speaking and probably in the UK and the US and young – in some cases teenagers. We know this from researchers and previous arrests. In November the US charged five men and boys in their twenties and teens for alleged Scattered Spider activity. One of them is 22-year-old Scottish man Tyler Buchanan, who has not made a plea, and the rest are US based.

Crackdowns by police seem to have had little effect on the hackers’ determination, though. On Thursday, Google’s cyber security division issued warnings that it was starting to see Scattered Spider-like attacks on US retailers now too.

As for the hackers I spoke to on Telegram, they declined to answer whether or not they were Scattered Spider. “We won’t answer that question” is all they said.

Perhaps in a nod to the immaturity and attention-seeking nature of the hackers, two of them said they wanted to be known as “Raymond Reddington” and “Dembe Zuma” after characters from US crime thriller The Blacklist which involves a wanted criminal helping police take down other criminals on a blacklist.

In a message to me, they boasted: “We’re putting UK retailers on the Blacklist.”

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”



Source link

Tags: BBChackersReportertalking

Related Posts

Oil prices slide after Pakistan announces deal between US and Iran

June 15, 2026
0

Under the agreement, the key Strait of Hormuz waterway will be reopened, US President Donald Trump said. Source...

UK electric car sales target set to be weakened

June 14, 2026
0

The new target hasn't yet been decided, with different numbers under consideration, the BBC understands. Source link

Why the US economy keeps defying the odds

June 14, 2026
0

Why has the American economy continued to outperform so many of its peers, despite facing the same global shocks?...

  • Lee McGregor: Scot seeks world title in 2025 & Nathaniel Collins bout

    677 shares
    Share 271 Tweet 169
  • Belgian footballer arrested in cocaine investigation

    533 shares
    Share 213 Tweet 133
  • Next to raise prices to help pay for rising wage costs

    531 shares
    Share 212 Tweet 133
  • South Wales Police officers injured, one arrested

    525 shares
    Share 210 Tweet 131
  • Charities to get £15m fund to save surplus farm food

    516 shares
    Share 206 Tweet 129
  • Trending
  • Comments
  • Latest

Lee McGregor: Scot seeks world title in 2025 & Nathaniel Collins bout

January 16, 2025

Belgian footballer arrested in cocaine investigation

January 27, 2025

Next to raise prices to help pay for rising wage costs

January 7, 2025

World Cup 2022: TikTok brings football fever to millions of fans

0

UK economy will get worse before it gets better, warns chancellor

0

One of Central America’s most active volcanoes erupts again

0

Gang guilty of organised crime in £4m cocaine and dirty money ring

June 15, 2026

Pensioner suffocated neighbour and recorded his dying words, court told

June 15, 2026

Reports nurses told by police to show ID to masked men during trouble – O'Neill

June 15, 2026

Categories

Scotland

Gang guilty of organised crime in £4m cocaine and dirty money ring

June 15, 2026
0

The five men were caught during a major police investigation called Operation Silhouette. Source link

Read more

Pensioner suffocated neighbour and recorded his dying words, court told

June 15, 2026
News

© 2023 GODJ - NEWS CORP - news.godj.com.

Explore NEWS.GODJ.COM

  • Home
  • News
  • Sports
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

© 2023 GODJ - NEWS CORP - news.godj.com.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.