Yazılar

Cyberattacks on M&S and Co-op Originated from Help Desk Deception, Says Report

Cybercriminals launched recent attacks on British retailers Marks & Spencer (M&S) and Co-op Group by impersonating employees to trick IT help desks into resetting passwords, according to a report by BleepingComputer. This social engineering tactic allowed hackers to gain initial access to internal systems.

The UK’s National Cyber Security Centre (NCSC) responded by urging all organisations to re-evaluate their help desk protocols, warning that online criminal activity like ransomware and data extortion is on the rise and that even large enterprises are vulnerable to such basic forms of manipulation.

While both M&S and Co-op declined to comment, the consequences of the M&S breach are already being felt. Shares dropped 4% on Tuesday and are down 12% since the cyber incident was disclosed on April 22. The company halted online orders for clothing and home products via its website and app on April 25, with no timeline for resumption. Some food product availability has also been disrupted.

Deutsche Bank analysts estimate the incident has cost M&S around £30 million ($40 million) so far, with an ongoing weekly impact of approximately £15 million. Though cyber insurance may offset part of the loss, it typically covers a limited time period. The broader risks include loss of consumer trust, data breach fines, and long-term reputational damage.

Ciaran Martin, former CEO of the NCSC, noted that the recovery time for such attacks is often lengthy due to the need to completely rebuild compromised IT networks.

Meanwhile, a group identifying as DragonForce claimed responsibility for attacking both M&S and Co-op, as well as stealing staff and potential customer data from the latter. The same group also claims responsibility for attacking Harrods. The report also links the cyberattack on M&S to the Scattered Spider” hacking collective, known for using DragonForce ransomware, although the NCSC said it could not confirm the connection.

FBI Investigating Cyberattack at Oracle Involving Patient Data Theft

The FBI is currently investigating a cyberattack at Oracle that resulted in the theft of patient data, according to a Bloomberg News report. The attack, which occurred after January 22, compromised Oracle’s servers, where hackers copied patient data to an external location. The breach is believed to have been an attempt to extort multiple medical providers in the United States.

Oracle, which acquired Cerner Corp. in 2022 for $28 billion, notified its healthcare customers about the breach earlier this month. However, it remains unclear how many patient records were affected and which healthcare providers were targeted. The breach involved older Cerner servers, where data had not yet been transferred to Oracle’s cloud storage.

While the FBI has declined to comment, Oracle confirmed it became aware of the breach on February 20. Oracle has not yet responded to further inquiries. The company’s involvement in healthcare IT through its Cerner acquisition has likely increased its exposure to cybersecurity risks in the healthcare sector.

Baidu Denies Data Breach Amid Controversy Over Executive’s Daughter

Baidu, one of China’s largest search and cloud service providers, has denied allegations of an internal data breach after the teenage daughter of a senior executive was accused of posting personal information online. The controversy erupted when social media users alleged that the daughter of Baidu vice president Xie Guangjun had leaked private details, including phone numbers, during an online dispute.

In response, Baidu stated that neither employees nor executives have access to user data and that the leaked information originated from illegally obtained databases hosted on foreign platforms. The company also announced that it had filed a police report to counter misinformation, including claims that Xie’s daughter had access to Baidu’s databases.

Xie, a member of Baidu’s cloud division, apologized for his daughter’s actions, asserting that she had acquired the data from overseas social media sites. His statement, reported by Chinese media, was shared on his personal WeChat account.

The incident comes as China tightens data security laws to curb the sale of private information, an issue exacerbated by illicit data brokers. The controversy has impacted Baidu’s stock performance, with shares dropping over 4% in Hong Kong trading on Thursday morning.