HomeSecurityHackers approached BBC journalist for help in hack

Hackers approached BBC journalist for help in hack

The Medusa, known for double-extortion attacks, appears to be expanding its tactics beyond traditional cyberattacks. In July, BBC journalist and cybersecurity expert Joe Tidywas targeted by threat actors who attempted to lure him into becoming an “insider threat.”

Medusa ransomware hackers BBC

The hackers, communicating with him via the Signal app , offered Tidy a large sum of money to give them access to the BBC network. According to the information he published , the initial offer was for 15% of the potential ransom , while an additional 10% was later proposed to “sweeten” the breach. The scenario envisaged the theft of valuable BBC data and the demand for a ransom of tens of millions of dollars.

The Medusa tactic and the dangers of insiders

Medusa has become known for recruiting Initial Access Brokers through cybercrime forums and darknet marketplaces. These “brokers” can provide ransomware groups with access to organizations’ networks without having to technically penetrate them themselves. The attempt to recruit Tidy as an insider is an evolution of this tactic, highlighting the threat of malicious or misguided employees in large organizations.

See also: Asahi: Japan's largest brewery suffered a cyberattack

In practice, Medusa invests in psychological techniques, trying to convince targets with promises of large financial benefits. The hackers are not seeking fame or media coverage – as the group’s spokesperson (“Syn”) told Tidy – they are solely aiming for financial gain. This approach makes persuasion and blackmail attempts particularly dangerous, especially when the target is a professional with access to sensitive systems.

Hackers approached BBC journalist for help in hack

The MFA bombing tactic

When Tidy refused to cooperate, the threat actors used MFA bombing, a technique that creates a barrage of two-factor authentication on his account. This is a modern form of pressure that exploits the user’s psychological fatigue in order to grant access to systems. Despite the pressure, Tidy remained calm and contacted the BBC’s information security team, completely disconnecting his computer from the organization’s infrastructure.

This case highlights the critical importance training of cybersecurityand implementing strong MFA policies. Organizations that rely on critical infrastructure must prepare for threats that combine social engineering and technical exploits.

The threat of ransomware gangs in the era of insider risk

Tidy's story is not an isolated one. Ransomware gangs like LockBit and Conti have documented similar attempts to recruit insiders to facilitate breaches. This trend shows that organizations are not only threatened by external attackers, but also by internal actors, most notably employees who may be disgruntled, underpaid, or simply unethical.

See also: New Spear-Phishing Attack Distributes DarkCloud Malware

Furthermore, the Medusa ransomware group highlights that ransomware threats are no longer simple file encryption attacks. The goal is economic exploitation through specialized tactics such as double attacks, extortion, and insider approaches, creating an environment where businesses must constantly monitor the security of their systems.

Hackers approached BBC journalist for help in hack

Conclusion: The importance of vigilance and education

The Joe Tidy case is a vivid reminder that cyberattacks are not just about technical breaches. Social engineering, insider threats , and the exploitation of human psychological weaknesses are equally serious threats.

Organizations looking to protect their data and infrastructure need to invest not only in technology tools, but also in staff training, access policies, MFA verification, and threat response. Tidy’s experience shows that vigilance, rapid communication with security teams, and staying calm can thwart even sophisticated extortion attempts from modern ransomware gangs.

See also: TamperedChef malware mimics productivity tools

Medusa and similar groups have proven that the world of ransomware is constantly evolving, making prevention and resilience in digital infrastructure more important than ever. Organizations that ignore these threats risk not only their finances, but also their reputation and operational continuity.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS