Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Australia news live: Ben Roberts-Smith awaits appeal verdict | Australia news

    ‘Aggressive, creative’ hackers behind UK breaches now eyeing US retailers

    Drunk driver who killed 2 when she crashed into birthday party at boat yard will head to prison for at least 25 years

    Facebook X (Twitter) Instagram
    Trending
    • Australia news live: Ben Roberts-Smith awaits appeal verdict | Australia news
    • ‘Aggressive, creative’ hackers behind UK breaches now eyeing US retailers
    • Drunk driver who killed 2 when she crashed into birthday party at boat yard will head to prison for at least 25 years
    • US Supreme Court grills Trump administration over birthright citizenship | Donald Trump News
    • An authentic Magna Carta has been discovered in Harvard’s archives : NPR
    • PM’s Albania trip shows tricky path on migration
    • Rising Food Prices Deepen Nigeria’s Poverty Crisis
    • Lawyers for US Mayor Ras Baraka argue he was targeted for arrest at protest | Donald Trump News
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»Cybercrims attacking UK retailers turn to US stores • The Register
    Cyber

    Cybercrims attacking UK retailers turn to US stores • The Register

    mediamillion1000@gmail.comBy [email protected]May 15, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    Cybercrims attacking UK retailers turn to US stores • The Register
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Interview The same miscreants behind recent cyberattacks on British retailers are now trying to dig their claws into major American retailers’ IT environments – and in some cases possibly even deploying ransomware, according to Google.

    The cloud giant’s threat-intel nerve-center Mandiant suspects the Scattered Spider (aka UNC3944) gang is behind these recent digital intrusions following a long hiatus and multiple arrests.

    Scattered Spider had been relatively quiet until mid-April when it launched a series of attacks that claimed victims including retailers Marks & Spencer, Co-op, and Harrods. 

    “About a week ago, we saw the expansion of the targeting to US-based retailers,” Charles Carmakal, chief technology officer of Mandiant Consulting, told The Register.

    A lot of the disruption is caused by the company making changes to prevent Scattered Spider from being able to move across the network

    “Now a number of organizations are actively defending against Scattered Spider intrusions, or they’re trying to recover environments because they had some level of impact,” Carmakal continued, putting the number of US retailers that have been targeted by the group at “under 10.”

    Carmakal won’t say which companies have been affected, but noted that they are “bigger-name retail organizations,” not mom-and-pop stores.

    “That impact could have been directly caused by the threat actor deploying across the environment, or it could just be self-inflicted because the company is taking actions to prevent the actors from stealing data or deploying encryptors, so they had to break things themselves,” he added.

    That might mean companies have frozen authentication servers or taken down virtual private networks to keep intruders out — in the process preventing employees from authenticating or remotely accessing IT systems.

    “Not all the downtime that’s caused by these incidents is directly related to Scattered Spider,” Carmakal said. “A lot of the disruption is caused by the company making changes to prevent Scattered Spider from being able to move across the network.”

    Ransomware du jour: DragonForce

    Carmakal confirmed the criminals deployed DragonForce ransomware in some of the UK and US attacks.

    “I’ve never seen them develop their own encryptor and deploy it across enterprises,” he noted. 

    Previously, Scattered Spider members used ALPHV/BlackCat extortionware, until that group disbanded. Then they moved on to RansomHub, “and now we see them using DragonForce,” Carmakal said.

    The loosely knit gang of cybercriminals, whose members are thought to include males in their teens and early 20s located primarily in the US and UK, scattered into the shadows following at least seven arrests last year.

    “That spooked some core members of Scattered Spider, and they went on a hiatus for many months,” Carmakal said. “And then all of a sudden, about a month ago we started seeing this uptick in attacks against UK retailers. The trade craft looked very similar to what we’d seen in the past by previous Scattered Spider intrusion activity.”

    The gang tends to focus their intrusions on a single sector at a time — remember the casino and resort capers in 2023? — and now retailers are taking the brunt. But, according to Carmakal, “the important thing to note about these folks is they’ve got shiny object syndrome. My guess is this adversary will pivot to the next sector in a few weeks, once they feel like they’ve gotten all they needed out of retail.”

    In the meantime, the criminals have put another big target on their backs. 

    “Anytime you have high profile cyber security events that are attributed to known groups, you could expect that there will be law enforcement action,” Carmakal said. “I can’t comment on the timing, but threat actors really do need to take note that there’s a good chance that more actions will be taken.” ®

    attacking Cybercrims Register retailers stores turn
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleObtaining Compensation for Russia’s Ukraine Invasion in US Court
    Next Article Trump State Dept. Leaned on African Nations to Help Musk’s Starlink — ProPublica
    [email protected]
    • Website

    Related Posts

    ‘Aggressive, creative’ hackers behind UK breaches now eyeing US retailers

    May 15, 2025

    US officials targeted in voice deepfake attacks since April

    May 15, 2025

    Alternatives to Microsoft Outlook webmail come under attack in Europe

    May 15, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Australia news live: Ben Roberts-Smith awaits appeal verdict | Australia news

    ‘Aggressive, creative’ hackers behind UK breaches now eyeing US retailers

    Drunk driver who killed 2 when she crashed into birthday party at boat yard will head to prison for at least 25 years

    US Supreme Court grills Trump administration over birthright citizenship | Donald Trump News

    Trending Posts

    Australia news live: Ben Roberts-Smith awaits appeal verdict | Australia news

    May 15, 2025

    ‘Aggressive, creative’ hackers behind UK breaches now eyeing US retailers

    May 15, 2025

    Drunk driver who killed 2 when she crashed into birthday party at boat yard will head to prison for at least 25 years

    May 15, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Australia news live: Ben Roberts-Smith awaits appeal verdict | Australia news
    • ‘Aggressive, creative’ hackers behind UK breaches now eyeing US retailers

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.