Published : 30 Sep 2025, 03:13 AM
A hacking group has made an offer to Joe Tidy, the cyber correspondent for the British news agency BBC, as part of their attempt to hack the media outlet.
They told him that if he helped them hack the BBC, he would receive so much money that "he will never have to work again”.
Essentially, the hackers offered to give Tidy a share of the ransom they planned to extort by hacking the outlet.
Tidy has provided the details of this incident. The BBC published the details extensively in Tidy's own words.
In the BBC report, Tidy said he was given a “unique and worrying experience” of how hackers can leverage insiders. He added that he was recently propositioned by a criminal gang.
“If you are interested, we can offer you 15 percent of any ransom payment if you give us access to your PC,” Tidy was presented with an offer through a message from someone called “Syndicate” who, he said, pinged him in July on the encrypted chat app Signal.
Tidy said he had no idea who this person was, but instantly knew what it was about.
“I was being offered a portion of a potentially large amount of money if I helped cyber criminals access BBC systems through my laptop,” he wrote.
They would steal data or install malicious software and hold his employer to ransom, and he would secretly get a cut, he added.
He decided to play along with Syndicate after taking advice from a senior BBC editor, eager to see how criminals make these shady deals with potentially treacherous employees at a time when cyber-attacks around the world are becoming more impactful and disruptive to everyday life.
He told Syn, as he now referred to them, who had changed their name mid-conversation, that he was potentially interested but needed to know “how it works”.
“They explained that if I gave them my login details and security code, then they would hack the BBC and then extort the corporation for a ransom in bitcoin. I would be in line for a portion of that payout.
They upped their offer,” he wrote.
The offer came through like this: “We aren't sure how much the BBC pays you, but what if you took 25 percent of the final negotiation as we extract 1 percent of the BBC's total revenue?
“You wouldn't need to work ever again,” it added.
Syn estimated that their team could demand a ransom in the tens of millions if they successfully infiltrated the corporation, Tidy said.
The BBC has not publicly taken a position on whether or not it would pay hackers, but advice from the National Crime Agency is not to pay, according to him.
He claimed Syn said he would be in line for “millions”.
“We would delete this chat for you to never be found,” they were quoted as insisting.
Continuing his attempts, the hacker said: “You'd be surprised at the number of employees who would provide us access.”
Tidy said Syn said he was a “reach-out manager” for the cyber-crime group called Medusa. He claimed to be Western and the only English speaker in the gang.
Medusa is a ransomware-as-a-service operation. Any criminal affiliate can sign up to its platform and use it to hack organisations, Tidy elaborated.
He said Syn had sent him a link to a US public warning about Medusa, which was put out in March. US cyber authorities said that in the four years that the group has been active, it has hacked “more than 300 victims”.
During the exchange, Syn told Tidy they were serious about making a deal to secretly sell the keys to my corporation's kingdom in exchange for a hefty payday, according to the report.
When Tidy asked Syn to prove it, they replied with a link to Medusa's darknet address and invited him to contact them through the group's Tox -- a secure messaging service loved by cyber criminals.
Tidy said Syn grew “impatient” and “ramped up the pressure” on him to reply.
“We aren't bluffing or joking -- we don't have a purpose media-wise, we are only for money and money only, and one of our main managers wanted me to reach out to you,” they texted him.
Only a cyber correspondent, not a cyber security or IT employee as Syn had thought he was, they asked Tidy questions about the “BBC IT network” that he claimed he wouldn't have answered “even if he knew”.
Tidy said Syn then sent a complicated jumble of computer code and asked him to run it as a command on his work laptop and report back what it said.
Tidy added that they wanted to know what internal IT access he had to start planning their next steps once inside.
At this point, Tidy said, he had been talking to Syn for three days and decided that he had taken it “far enough” and needed some extra advice from the BBC's information security experts.
As he stalled for time, Syn got annoyed.
“When can you do this? I'm not a patient person,” the hacker was quoted as saying.
“I guess you don't want to live on the beach in the Bahamas?” they pressured.
My phone started pinging with two-factor authentication notifications. The pop-ups were from the BBC's security login app asking him to verify that he was trying to reset the password to my BBC account
The criminals first attempted to breach his account using a technique known as multi-factor authentication (MFA) bombing.
Tidy’s phone screen was flooded with login or password reset requests every minute -- a tactic designed to pressure the victim into mistakenly accepting the pop-up to make them stop, famously used in the 2022 Uber hack.
Tidy described the experience as unsettling and akin to "having criminals aggressively knocking on my front door”.
The hackers moved the "relatively professional conversation" from his chat application to his phone’s home screen, making the device virtually unusable.
Tidy, cautious not to accidentally accept a prompt and give the hackers immediate access to his BBC accounts, he avoided opening their chat. Had he clicked "accept”, the security system would not have flagged it as malicious, allowing the hackers to search for access to sensitive BBC systems.
As a precaution, he called the BBC information security team, and they agreed to disconnect him entirely from the BBC network, removing his access to emails, the intranet, internal tools, and privileges.
Later that evening, the hackers sent a bizarrely calm message: "The team apologises. We were testing your BBC login page and are extremely sorry if this caused you any issues."
Although annoyed as he was locked out of the BBC system, Tidy explained the situation.
Syn insisted that the deal to provide Tidy with money was still on the table.
When Tidy did not respond for a few days, the hackers removed their Signal account and vanished.
Tidy was eventually reinstated to the BBC system with added protections.
He said the incident provided a chilling insight into the ever-evolving tactics of cyber criminals and highlighted an area of insider risk to organisations that he did not fully appreciate until he was personally targeted.