Yazılar

UK Police Arrest Four Suspects Over Cyberattacks on M&S, Co-op, and Harrods

Four individuals under the age of 21 have been arrested in connection with cyberattacks that disrupted operations at major UK retailers Marks & Spencer (M&S), the Co-op, and Harrods, the National Crime Agency (NCA) announced on Thursday. The most severe incident occurred in April when a ransomware attack forced M&S to halt online clothing sales for nearly seven weeks, resulting in an estimated £300 million ($400 million) loss in operating profit.

The arrested suspects include three males aged 17, 19, and 19, and a 20-year-old woman. They were detained at their homes in the West Midlands and London. The NCA said they face allegations including offenses under the Computer Misuse Act, blackmail, money laundering, and involvement in organized crime. Authorities also seized their electronic devices, and the suspects are currently being questioned by the NCA’s National Cyber Crime Unit.

M&S Chairman Archie Norman revealed to lawmakers that the company had engaged with the U.S. FBI regarding the cyberattack. He suggested that loosely connected groups, possibly led by a hacking collective known as DragonForce, were behind the incidents. Norman also advocated for UK businesses to be legally mandated to report significant cyberattacks, noting that some major breaches recently went unreported.

M&S resumed online clothing orders on June 10 after a 46-day suspension, although click-and-collect services remain offline. CEO Stuart Machin expressed confidence that the company would be through the worst of the attack’s impact by August.

Qantas reveals cyber breach exposed personal data of over 5 million customers

Australia’s Qantas Airways confirmed on Wednesday that a major cyberattack compromised the personal data of approximately 5.7 million customers, marking one of the country’s largest data breaches in recent years. Initially, Qantas reported 6 million records affected but later removed duplicates.

More than one million customers had sensitive details like phone numbers, birth dates, or home addresses accessed. An additional four million customers’ data was limited to names and email addresses.

The airline said there is currently no evidence that the stolen data has been publicly released, and it is actively monitoring the situation to protect affected customers.

“Since the incident, we have implemented several new cybersecurity measures to better safeguard our customers’ data and are thoroughly reviewing the breach,” Qantas Group CEO Vanessa Hudson stated.

This breach follows a wave of high-profile cyberattacks in Australia, including those against telecom giant Optus and health insurer Medibank in 2022, which spurred the introduction of mandatory cyber resilience regulations.

Qantas Contacts Cyber Criminal After Data Breach Affecting Six Million Customers

Australia’s Qantas has confirmed that a cyber criminal reached out to the airline one week after a major data breach exposed personal information of six million customers. The breach involved a hacker targeting a call centre and accessing a third-party customer service platform containing sensitive details including names, emails, phone numbers, birth dates, and frequent flyer numbers, a Qantas spokesperson told Reuters on Tuesday.

The airline has engaged the Australian Federal Police in the investigation and declined to provide further details on the contact due to the ongoing criminal matter. While there is currently no evidence that the stolen data has been leaked publicly, Qantas is actively monitoring the situation with cyber security experts.

This breach marks one of the most significant cyber attacks in Australia since the 2022 incidents involving telecommunications provider Optus and health insurer Medibank, which led to the introduction of mandatory cyber resilience laws.

The incident poses a challenge for Qantas as it works to restore public confidence after its reputation suffered during the COVID-19 pandemic due to operational disruptions and criticism.