Cyber Incident Victim: The Big Issue
Date:
Feb 2024
Location:
United Kingdom
Summary
The Big Issue, a UK social enterprise supporting homeless individuals through magazine sales, experienced a ransomware attack by the Qilin gang, which claimed theft of 550 gigabytes of confidential commercial and personnel data. The organization restricted system access, engaged external cybersecurity experts, and initiated restoration efforts, maintaining limited operational disruption and uninterrupted magazine distribution. Certain stolen data was published on the dark web, prompting collaboration with the National Cyber Security Centre, National Crime Agency, and Metropolitan Police, alongside regulatory notifications. Despite the incident, the group continues vendor support services, social impact lending, and frontline assistance for those facing poverty.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The Big Issue Group, a UK-based social enterprise providing income opportunities for homeless individuals through magazine sales, confirmed a cyber incident in late February 2024 after the Qilin ransomware gang listed the organization on its darknet extortion site on February 25. The attackers claimed to have stolen 550 gigabytes of confidential data containing commercial and personnel files. Chief Executive Paul Cheal acknowledged the breach occurred the preceding week, with certain compromised data subsequently published on dark web platforms. Upon detecting the intrusion, the organization immediately restricted system access and engaged external IT security specialists to investigate. Despite operational disruptions, the group maintained magazine publication and distribution—its core revenue stream for vendors—through contingency measures. The incident occurred against a backdrop of rising ransomware attacks against British organizations, as documented by year-on-year increases in Information Commissioner's Office data.

Big Issue's response involved collaboration with the National Cyber Security Centre, National Crime Agency, and Metropolitan Police while notifying relevant regulators. Forensic efforts enabled partial system restoration with limited operational impact, though the investigation remained ongoing. Cheal characterized the attack as a criminal act targeting poverty-alleviation initiatives, emphasizing continued support for vendors' livelihoods and access to social services. Independent research cited in the disclosure highlighted underreported psychological consequences for staff and responders during such incidents. The organization maintained its social impact lending programs for partner enterprises throughout the containment process, prioritizing mission continuity despite infrastructure compromises. No vendor financial arrangements or free magazine allocations were reported as directly affected by the breach.
