Close Menu
    Trending
    • Implementing IBCS rules in Power BI
    • What comes next for AI copyright lawsuits?
    • Why PDF Extraction Still Feels LikeHack
    • GenAI Will Fuel People’s Jobs, Not Replace Them. Here’s Why
    • Millions of websites to get ‘game-changing’ AI bot blocker
    • I Worked Through Labor, My Wedding and Burnout — For What?
    • Cloudflare will now block AI bots from crawling its clients’ websites by default
    • 🚗 Predicting Car Purchase Amounts with Neural Networks in Keras (with Code & Dataset) | by Smruti Ranjan Nayak | Jul, 2025
    AIBS News
    • Home
    • Artificial Intelligence
    • Machine Learning
    • AI Technology
    • Data Science
    • More
      • Technology
      • Business
    AIBS News
    Home»Technology»Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre
    Technology

    Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre

    Team_AIBS NewsBy Team_AIBS NewsMay 5, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Joe Tidy

    Cyber correspondent, BBC World Service

    Getty Images People walking in front of Marks and Spencer store front.Getty Photographs

    The Nationwide Cyber Safety Centre (NCSC) has warned criminals launching cyber assaults at British retailers are impersonating IT assist desk calls to interrupt into organisations.

    Hackers have focused Marks & Spencer, Co-op and Harrods within the final two weeks, and on Friday the anonymous group told the BBC there will probably be extra assaults quickly.

    Now the NCSC, the federal government company accountable for cyber safety, has issued guidance to organisations urging them to evaluation their IT assist desk “password reset processes” to cut back their probabilities of getting hacked.

    “We consider by following greatest follow, all corporations and organisations can minimise the probabilities of falling sufferer to actors like this,” it stated.

    It stated corporations ought to reassess how their IT assist desk “authenticates employees members” earlier than resetting passwords, particularly senior workers with entry to high-level elements of an IT community.

    It highlighted press hypothesis round “social engineering” as a method hackers could have gained entry to accounts.

    Criminals use social engineering strategies to get individuals to belief them after they e mail, textual content or name pretending to be from an organization’s IT assist desk – in the end tricking workers into handing over their log in passwords and safety codes.

    This additionally works the opposite method – calling individuals who work on the assistance desk and pretending to be an worker locked out of their account.

    Cyber safety consultants now suggest additional layers of safety to take care of these kinds of assaults.

    “Having code phrases that get used when an worker telephones as much as change their credentials, comparable to “BluePenguin”, is one factor being mentioned within the cyber neighborhood as a method to verify that the member of employees is real,” stated Lisa Forte from cyber safety agency Purple Goat.

    “Finally it comes again to the identical difficulty with login credentials as at all times – we’d like a number of methods to do it to make sure it is not simple to bypass.”

    NCSC recommendation

    The NCSC recommendation is the strongest trace but the hackers are utilizing techniques mostly related to a collective of English-speaking cyber criminals nicknamed Scattered Spider.

    The title derives from “spider” being the label given to financially motivated cyber criminals, whereas “scattered” is as a result of they aren’t a cohesive, organised gang.

    Up to now two years these disparate hackers, of their teenagers or early twenties, have coordinated and deliberate assaults on Discord and Telegram to breach dozens of corporations and steal or scramble information to extort their victims.

    The NCSC doesn’t particularly title the group as being accountable for the present wave of assaults, however acknowledges Scattered Spider are recognized for most of these hacks.

    In different NCSC recommendation, cyber defenders are being urged to be careful for “Dangerous Logins”.

    This implies looking for when and the place workers have logged in from – for instance late at evening or from unusual places.

    Though cyber criminals could possibly be anyplace on the planet, younger English-speaking hackers within the UK and US have grow to be adept at utilizing social engineering of their assaults.

    Scattered Spider hacks

    Scattered Spider hackers have been accountable for excessive profile assaults together with the coordinated moves against casinos in Las Vegas through which MGM Grand Casinos and Caesar’s Palace had been hit in fast succession.

    There have been six arrests within the final 12 months of hackers accused of being from Scattered Spider within the US and UK.

    In July 2024 a 17-year-old from Walsall was arrested as a part of an FBI investigation into the MGM hack – and months later a person of the same age and location was arrested in reference to one other hack on Transport for London.

    Police wouldn’t say if the alleged hacker was the identical individual.

    On Friday, the hackers accountable for the present wave of assaults spoke to the BBC.

    The criminals repeatedly denied they’re Scattered Spider hackers and would solely name themselves DragonForce – the title of a cyber crime service hackers can use for malicious software program and extortion.

    The hackers, who had been fluent English audio system, revealed to the BBC that they had compromised Co-op and stolen a considerable amount of buyer and worker information.

    They’d not talk about the M&S hacks. However it’s thought DragonForce ransomware was used to scrambled the agency’s IT servers.

    Whereas the NCSC stated it “had insights”, it added it was “not but ready to say if these assaults are linked”.

    “We’re working with the victims and legislation enforcement colleagues to establish that,” it stated.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCan I Use Credit Cards to Finance My Small Business?
    Next Article I Earned the “Develop GenAI Apps with Gemini and Streamlit” Badge. Here’s What I Built – Misba shaikh
    Team_AIBS News
    • Website

    Related Posts

    Technology

    Millions of websites to get ‘game-changing’ AI bot blocker

    July 1, 2025
    Technology

    Transform Complexity into Opportunity with Digital Engineering

    July 1, 2025
    Technology

    HP’s PCFax: Sustainability Via Re-using Used PCs

    July 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Implementing IBCS rules in Power BI

    July 1, 2025

    I Tried Buying a Car Through Amazon: Here Are the Pros, Cons

    December 10, 2024

    Amazon and eBay to pay ‘fair share’ for e-waste recycling

    December 10, 2024

    Artificial Intelligence Concerns & Predictions For 2025

    December 10, 2024

    Barbara Corcoran: Entrepreneurs Must ‘Embrace Change’

    December 10, 2024
    Categories
    • AI Technology
    • Artificial Intelligence
    • Business
    • Data Science
    • Machine Learning
    • Technology
    Most Popular

    Forget About Cloud Computing. On-Premises Is All the Rage Again

    March 15, 2025

    Your Growth Strategy Won’t Matter if Your Team Drowns — 5 Truths About Crisis Leadership

    February 17, 2025

    Invest in the AI That Will Make Chatbots Obsolete

    March 25, 2025
    Our Picks

    Implementing IBCS rules in Power BI

    July 1, 2025

    What comes next for AI copyright lawsuits?

    July 1, 2025

    Why PDF Extraction Still Feels LikeHack

    July 1, 2025
    Categories
    • AI Technology
    • Artificial Intelligence
    • Business
    • Data Science
    • Machine Learning
    • Technology
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2024 Aibsnews.comAll Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.