Ransomware victim disclosure
← All victimsBT Group plc (British Telecom)
listed as btci.com · Claimed by Black Basta · listed 2 years ago
Status timeline
- ListedDec 4, 2024
- Data leakeddate unknown
At a glance
- Group
- Black Basta
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Technology
- Listed on leak site
- Dec 4, 2024
- Data size
- 500 GB
- Records
- 3. Users
About the victim
AI dossier — public-source company profileBT Group plc, formerly British Telecommunications plc, is one of Europe's leading providers of telecommunications services. The company operates multiple conferencing and communication platforms serving enterprise and consumer markets across the United Kingdom and beyond.
- Industry
- Telecommunications
Attack summary
Severity: critical — BT Group is a major European telecommunications provider. Confirmed exfiltration of 500 GB including financial data, user personal information, and confidential business documents represents large-scale exposure of sensitive and regulated data affecting a critical infrastructure operator.BlackBasta claims to have exfiltrated approximately 500 GB of data from BT Group, including financial records, organizational data, user information, and confidential documentation subject to NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Financial data
- Organizational data
- User data and personal documents
- NDAs and confidential agreements
What the group claims
BT Group plc (formerly British Telecommunications plc, abbreviated to British Telecom) is one of Europe’s leading providers of telecommunications services.SITE: www.btci.com | www.btconferencing.comALL DATA SIZE: ≈500gb 1. Finacial data 2. Organisation data 3. Users data and personal docs 4. NDA’s, Confidential data & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

