Qilin ransomware gang leaked data stolen from The Big Issue Group
- Organization
- The Big Issue Group
- Exploit
- Ransomware
- Industry
- Media
The Big Issue Group, the social enterprise that publishes the UK street newspaper sold by homeless and vulnerable vendors, confirmed in late March 2024 that it had been hit by a cyber incident. The confirmation followed the organisation's appearance on the darknet extortion site run by the Qilin ransomware operation.
The Record reported that the listing appeared on Sunday 24 March. It claimed the gang had taken roughly 550GB of data covering commercial and personnel operations. Screenshots published as proof appeared to include employee records with full names, home addresses and bank details, passport and driving licence scans, payroll paperwork, contracts and partner data, and financial and investment material tied to Big Issue Invest, the group's social investment arm. The Register reported that images of chief executive Paul Cheal's driving licence and salary details, and of Big Issue Invest chief executive Danyal Sattar's passport and banking details, were among the material posted.
Cheal said the group restricted access to its systems as soon as it became aware of the intrusion, brought in external IT security specialists and began restoring services with limited disruption. He said publication and distribution of the magazine were unaffected, and the organisation reported no sign that subscriber data had been taken.
The group reported the incident to the Information Commissioner's Office, the National Crime Agency and the Metropolitan Police, and received support from the National Cyber Security Centre. Comparitech reported that the Big Issue had not said whether a ransom was demanded or paid, and the investigation remained open at the end of March 2024.