BT Group confirms attempted attack on conferencing unit claimed by Black Basta
- Organization
- BT Group
- Exploit
- Ransomware
- Industry
- Telecommunications
BT Group confirmed on December 4, 2024 that part of its conferencing business had been targeted, the same day the Black Basta ransomware gang listed the UK telecommunications company on its darknet leak site.
The company said the incident involved an attempt to compromise its BT Conferencing platform and was restricted to specific elements of that platform, which were rapidly taken offline and isolated. BT said live conferencing services continued to operate and that no other BT Group services or customer-facing systems were affected. The Register reported that the unit involved is a legacy division headquartered in Braintree, Massachusetts, and that the servers taken offline did not support live conferencing.
Black Basta claimed to have stolen roughly 500GB of material, listing the btci.com and btconferencing.com domains and describing files that it said included financial and organisational records, user data, personal identity and visa documents, non-disclosure agreements and employee bonus information. It threatened to publish the data unless a ransom was paid.
BT did not confirm the volume or nature of the material the group said it held and said the incident remained under investigation. The Register noted that sample files posted by the gang appeared to date from the previous decade rather than from recent operations. Black Basta, which emerged in 2022, had previously attacked healthcare providers and critical infrastructure operators.