CSIDB logo
Incident

Britain First

Incident posture

Attack window
Apr 2017
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Britain First
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A far-right group experienced a coordinated cyberattack compromising its Twitter accounts, YouTube channel, and official websites. The attackers renamed a leader's Twitter profile, altered deputy-linked web content, and leaked personal addresses of key figures. YouTube removed one video for harassment violations, while all other channel content appeared deleted by user action, affecting 178 videos. The perpetrator's identity remained undisclosed following the disruption of the organization's digital platforms and exposure of sensitive information.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On April 12, 2017, the far-right group Britain First experienced a coordinated cyberattack targeting multiple digital platforms. The incident compromised the Twitter accounts of leader Paul Golding and deputy Jayda Fransen, with Golding’s account renamed to "massive fucking chav." Fransen’s personal website was also defaced with unauthorized modifications. Attackers exfiltrated and publicly disseminated personal information belonging to both individuals, including residential addresses. Concurrently, Britain First’s primary YouTube channel was disabled, with all 178 videos rendered inaccessible. Platform enforcement actions contributed to this disruption, as YouTube removed at least one recent video filmed in Birmingham for violating harassment and bullying policies. The remainder of the channel’s content displayed removal notices indicating deletion "by the user," though attribution for these actions remained unclear.

The attack comprehensively disrupted Britain First’s online operations, eliminating their video archive and impairing official communications via Twitter and web platforms. YouTube’s enforcement decision on the Birmingham video demonstrated platform policy alignment with the harassment takedown rationale, while the mass video deletions suggested either compromised account access or deliberate sabotage. No group claimed responsibility for the intrusions, and technical details regarding initial breach vectors, detection methods, or containment procedures were absent from public reporting. Britain First representatives did not provide commentary when contacted by media outlets following the incident. The leak of personally identifiable information escalated potential physical security risks for the leadership beyond digital disruption.

Sources

Sources available to members: 1 source.

CSIDB