Ransomware victim disclosure
← All victimsBT Group plc
listed as btci.com · Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedDec 4, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Technology
- Listed on leak site
- Dec 4, 2024
About the victim
AI dossier — public-source company profileBT Group plc (British Telecom) is one of Europe's leading telecommunications service providers. The victim identifier btci.com refers to BT Conferencing, a subsidiary or service division offering conferencing solutions.
- Industry
- Telecommunications Services
Attack summary
Severity: critical — Large-scale exfiltration (500 GB) from a major European telecommunications provider affecting financial data, organizational intelligence, and user personal information. Telecommunications infrastructure is critical national infrastructure; data breach at this scale poses significant regulatory and security implications.BlackBasta claims to have exfiltrated approximately 500 GB of data from BT Group including financial records, organizational data, user personal documents, and confidential/NDA-protected materials.
Data the group says was taken
AI dossier — extracted from the leak post- financial data
- organizational data
- user personal documents
- NDAs and confidential agreements
What the group claims
BT Group plc (formerly British Telecommunications plc, abbreviated to British Telecom) is one of Europe’s leading providers of telecommunications services.SITE: www.btci.com | www.btconferencing.comALL DATA SIZE: ≈500gb 1. Finacial data 2. Organisation data 3. Users data and personal docs 4. NDA’s, Confidential data & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

