British telecommunications company BT Group (formerly British Telecom) has confirmed that its BT Conferencing division has shut down some of its servers, following a ransomware attack by the Black Basta gang.

BT Group is a leading fixed and mobile telephony provider in the United Kingdom, but also provides services to customers in 180 countries.
A company spokesperson reportedly told BleepingComputer that the ransomware attack did not affect BT Group operations or BT Conferencing services. This means that there may not have been any encryption of systems. Now, ransomware gangs are very interested in simply stealing data.
See also: Stoli Group declared bankruptcy after ransomware attack
“We detected an attempted breach of the BT Conferencing platform. This incident was limited to specific elements of the platform, which were quickly taken offline and isolated,” the spokesperson told BleepingComputer.
"The affected servers do not support live BT Conferencing services. These services remain fully operational and no other BT Group or customer services have been affected."
BT said it detected only one attempted breach of the platform, but took the affected servers offline. At the same time, the Black Basta ransomware gang claimed to have breached the company’s servers and stolen 500GB of data, including financial and organizational data, “user data and personal documents,” NDA documents, confidential information, and more.
The group also published file listings and screenshots of documents as evidence of its claims.
See also: Spain's tax office was cyberattacked by Trinity Ransomware
The ransomware gang added a countdown to its website, saying that the allegedly stolen data will be leaked next week.
If the hackers' claims are true, we are not just talking about an attempted breach, but a serious breach.
"We continue to actively investigate all aspects of this incident and are working with the relevant regulators and law enforcement authorities as part of our response," the BT Group spokesperson added.
The Black Basta Ransomware-as-a-Service (RaaS) operation has been linked to several significant attacks.
See also: Bologna FC hit by ransomware attack
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Some of the group's most notable victims include: Ascension, British technology outsourcing company Capita, German defense company Rheinmetall, state-owned company ABB, Hyundai's European division, the Toronto Public Library, the American Dental Association, and Yellow Pages Canada.

Ransomware Protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
- Stay up to date on the latest ransomware trends and tactics used by attackers
Source: www.bleepingcomputer.com
