Search This Blog

Powered by Blogger.

Blog Archive

Labels

Showing posts with label British Telecommunication attacked. Show all posts

BT Group Confirms Cyberattack by Black Basta Ransomware Group

British telecommunications giant BT Group has confirmed it was targeted by the notorious ransomware group Black Basta in a cyberattack on its Conferencing division. The breach forced BT to isolate and shut down parts of its infrastructure to limit the damage. While BT has minimized the reported impact, Black Basta claims otherwise, alleging they exfiltrated 500GB of sensitive data during the attack. The group asserts that the stolen data includes:

  • Financial records,
  • Organizational details,
  • Non-disclosure agreements,
  • Confidential files, and
  • Personal documents.
To substantiate these claims, the group has shared screenshots, folder listings, and other materials online, threatening to leak the data unless their ransom demands are met. The exact ransom amount remains undisclosed. 
  
BT’s Response 
 
In a statement to BleepingComputer, BT emphasized its swift action to contain the breach: "We identified an attempt to compromise our BT Conferencing platform. This incident was restricted to specific elements of the platform, which were rapidly taken offline and isolated. The impacted servers do not support live BT Conferencing services, which remain fully operational, and no other BT Group or customer services have been affected."

The company is actively investigating the breach and is collaborating with regulatory and law enforcement agencies to address the incident. 
  
Black Basta’s Growing Threat 
 
The FBI and CISA have identified Black Basta as a significant ransomware threat. A joint report earlier this year revealed the group has attacked over 500 organizations globally since its emergence in **2021. Their victims span 12 of the 16 critical infrastructure sectors, including the Healthcare and Public Health (HPH) sector. High-profile targets have included:
  • Hyundai Europe,
  • Capita,
  • The American Dental Association, and
  • Yellow Pages Canada.
Cybersecurity experts speculate that Black Basta originated from the disbanded Conti ransomware group, which dissolved amid geopolitical tensions stemming from the Russian invasion of Ukraine. 
  
Addressing Escalating Cyber Threats 
 
BT’s spokesperson assured the public of ongoing efforts to address the breach: "We are continuing to actively investigate all aspects of this attack and are working closely with the relevant authorities." As ransomware attacks like these continue to rise, organizations are urged to strengthen their cybersecurity defenses to safeguard critical data and operations against evolving threats.