Street newspaper appears to have Big Issue with Qilin ransomware gang
- Reference: 1711537208
- News link: https://www.theregister.co.uk/2024/03/27/big_issue_qilin_cyberattack/
- Source link:
In a post made to the gang's leak site, the miscreants claim to have stolen 550 GB of company data and, according to what they've released already, the haul appears vast and damaging.
In a 12-photo leak, it looks as though the driving license and salary information for Paul Cheal, CEO at Big Issue Group, The Big Issue's parent company, may have been exposed.
[1]
Danyal Sattar, CEO of Big Issue Invest, the Group's social impact investment arm, also appears to have had his passport and bank details leaked.
[2]
[3]
Sattar's passport is just one of many that are seemingly in the hands of Qilin's affiliates, which posted a screenshot of a file explorer page filled with what it claims to be employee passport scans.
Other images show swathes of employee data, including full names, work emails, and home addresses included in [4]Excel spreadsheets.
[5]
Other leaked spreadsheets included data such as personal email addresses and bank details, including account numbers, names, and sort codes - all alongside other information like full names and home addresses.
Financials were also posted online, which the company does not publicly share.
The Big Issue is a publication that serves to offer homeless people, those at risk of homelessness, or those experiencing poverty a lifeline by giving them a chance to earn money and reintegrate into society.
[6]
In 2022, it was working with 3,637 vendors – 899 of which were working for the company for the first time.
Started in 1991, The Big Issue is published across four continents and is one of the UK's leading social enterprises. An attack on the group will be viewed by many as no different from one on a hospital or charity, and these are generally seen as morally abhorrent, even for cybercriminals.
Cheal said in a statement: "Last week, the Big Issue Group experienced a cyber incident. On becoming aware of this, we took immediate steps to restrict access to our systems, working with external IT security experts, and the investigation into the incident is ongoing. Thanks to the proactive steps taken, we have been able to begin restoring our systems and are operating with limited disruption. The publication and distribution of the Big Issue magazine is not impacted by this incident.
"As part of our investigation, we've identified that certain data related to our organisation has been posted to the dark web by the perpetrators of this incident. We're working with our external IT expert to complete our investigation as a matter of priority alongside the NCSC, the National Crime Agency, and the Metropolitan Police. In addition, we have notified relevant regulators and would like to thank our staff, partners, and suppliers for their patience whilst our investigation continues.
"This is a criminal act against our social activities and the causes we work to promote. We exist to support those living at the sharp end of poverty, who are facing barriers to opportunity. Critically our staff are continuing to support our vendors to earn a living by selling the Big Issue magazine, whilst also providing frontline support for vendors with access to advice and services, alongside making social impact lending available to social enterprises and other organizations we work with. Ensuring we continue to deliver against our mission to change lives through enterprise."
The Big Issue told us it has no evidence that points to a compromise of subscriber data.
[7]Court hearings become ransomware concern after justice system breach
[8]Cyber sleuths reveal how they infiltrate the biggest ransomware gangs
[9]LockBit suspect's arrest sheds more light on 'trustworthy' gang
[10]Ransomware-as-a-service groups rain money on their affiliates
The Information Commissioner's Office (ICO), the UK's data protection watchdog, said it has been notified.
"People have the right to expect that organizations will handle their personal information securely and responsibly," an ICO spokesperson told The Register .
"If an individual has concerns about how their data has been handled, they should raise it with the organization first, then report them to us if they are not satisfied with the response.
"The Big Issue has made us aware of an incident and we are assessing the information provided."
According to security expert Kevin Beaumont, the company has been dealing with the incident, which it hasn't yet linked to ransomware, "for about a week."
"Pretty messed up target as homeless people sell the magazine, which makes next to no money in profit," he [11]said .
The Qilin ransomware-as-a-service (RaaS) gang, sometimes tracked by its founding name Agenda, claims it's behind the attack. Its payload is written in Russian using [12]Rust and [13]Go , and the criminals behind it are also thought to be Russian.
Qilin is the name of a creature in Chinese mythology. However, it wouldn't be the first time a ransomware group has used a moniker that attempts to confuse onlookers about their country of origin. [14]Akira , for example, is a name of Japanese origin, but it too is also thought to be staffed by Russians.
In ransomware scenarios, when a victim is posted to a leak blog, it's usually done to hurry up the negotiation process. Making the incident public for the first time could also be a way to pile on the regulatory pressure on the group, potentially forcing it to resolve the matter more quickly.
Ultimately, the criminals behind the attack want to be paid a ransom as quickly as possible and through whatever means necessary. [15]According to research into the gang , affiliates can expect between 80 and 85 percent of the total ransom sum. ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgRQrJ9GxkD4MK0FLsRYxwAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgRQrJ9GxkD4MK0FLsRYxwAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgRQrJ9GxkD4MK0FLsRYxwAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2023/10/23/excel_date_format_feature/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgRQrJ9GxkD4MK0FLsRYxwAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgRQrJ9GxkD4MK0FLsRYxwAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/01/02/victoria_court_system_breach/
[8] https://www.theregister.com/2023/12/22/how_to_infiltrate_ransomware_gangs/
[9] https://www.theregister.com/2023/06/16/lockbit_suspect_arrest/
[10] https://www.theregister.com/2023/05/17/ransomware_affiliates_money/
[11] https://cyberplace.social/@GossiTheDog/112158315581386101
[12] https://www.theregister.com/2022/07/06/hive-ransomware-rust-microsoft/
[13] https://www.theregister.com/2022/03/22/arid-gopher-malware-deep-instinct/
[14] https://www.theregister.com/2024/01/26/akira_lush_ransomware/
[15] https://www.theregister.com/2023/05/17/ransomware_affiliates_money/
[16] https://whitepapers.theregister.com/
Re: What is the purpose?
I suspect that both the CEO's mentioned in the article are on six figure salaries (seems to be the norm these days for charities), but the bigger question is why they are engaging with external IT security experts? Don't they have any internal ones? Or is there no budget for those after paying the CEO salaries?
Yes, attacking a charity is majorly scummy, but if the data was that easily exposed it does raise serious questions about the priorities and management of the charity if their IT is so easily compromised.
Re: What is the purpose?
From the 2020 accounts:
"Key management personnel include the Trustees, the CEO and those reporting to the CEO (namely: National Services Director). Remuneration paid to these individuals amounted to £123,140 (2019: £131,154)."
Which would suggest the CEO was in the lower/mid 5 digit market. I doubt they have a full time IT department. Yes, they may be a sitting duck. Attractive, maybe, to a script kiddie - but to a serious ransom-seeking gang? Doesn't make sense.
The big issue was originally for homeless people to sell. That then changed and it became a job for Roma gangs who pick up the women who are not homeless and drive them to the locations. Whilst the big issue has a charity foundation part it is a for profit business and it no longer helps people off the streets or actual homeless people which was it's original aim. Not condoning the actions of any scummy ransomware gang but I think these facts need to be clear. I wouldn't compare them to hospitals or other legitimate charities.
That's my experience also. I've seen them in Cambridge and they all have similar signs (presumably made by the same person) and they are stationed every few hundred yards. I've spoken to a few of them and they live in houses and take the train every day to sell Big Issue. It's not the same as it used to be, and the articles are mostly drivel now. Used to be an interesting read.
Don't buy it from a Roma then. Solved. They only get half of the price, anyway.
I'm not a regular reader, but I think I bought it last month off the shelf in the Co-operative supermarket. I don't mind supporting Co-operative.
I honestly don't care about the Roma part. I care about the fact they don't get people off the streets and let people not on the streets sell it allowing these gangs to take the piss. They only get half the price, the half they don't have to put up front to get it in the first place. Without getting people of the street it's no better than begging and giving people money to get high (that's if it is actually homeless people). You might as well just give a beggar 1.25 and be done with it. What exactly is the point of it? How is it actually helping people? It's no better than chuggers now.
What is the purpose?
The ability of the Big Issue to pay a meaningful ransom is near zero. That doesn't take a great deal of research to determine. Just emplying "an IT expert" (note the singular) will make a dent in their cashflow. Dealing with ICO will consume considerable management resources. Ransomware gangs are not stupid people. They expect to be paid in either money or favours by someone. Who is this someone?
Don't answer 'cos it would only be a conspiracy theory ... sadly.