Quick Summary
AllegedExecutive Summary
On September 5, 2026, qilin ransomware added The Big Table Group to its dark web portal. The United Kingdom-based restaurant and casual-dining operator became the 242nd victim claimed by the group in the preceding 60 days. The Big Table operates a portfolio of casual dining brands across Britain, holding sensitive data such as payment records, loyalty program information, and customer contact details, making it a potentially attractive target for ransomware operators who have frequently targeted the hospitality sector. qilin’s typical victim profile has been concentrated in the United States, Germany, and Italy, with a strong focus on the Manufacturing and Professional Services industries. The inclusion of The Big Table, a UK hospitality operator, represents a geographical departure from the group’s usual targeting patterns. Previous hospitality victims claimed by qilin, such as Cinépolis, iPic, Spoonful of Comfort, and D & J Beverage Service, were all non-UK operations. This listing marks a potential expansion into the British dining market, which is subject to GDPR enforcement and distinct regulatory frameworks compared to the group’s more common targets.
Technical Analysis
SOCRadar’s investigation involved a stealer-log query for the domain bigtablegroup[.]com. The query returned no records, indicating that no compromised credentials associated with this specific domain were found in the queried dataset. However, it is important to note that this result covers a paginated and bounded sample of data. It is possible that credentials could exist under alternate corporate domains, use personal email aliases associated with staff, or reside in feeds not included in this specific query. Therefore, the absence of positive signal in this query does not confirm that the organization is unaffected by compromise. For ransomware groups like qilin, infostealer-harvested credentials are a significant vector for initial access. Threat actors often utilize underground marketplaces to acquire these credentials, which are then validated against corporate accounts, Microsoft 365, or VPN portals before ransomware deployment. The null result from the stealer-log query does not rule out this potential access scenario. Organizations should consider continued dark web monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication review to mitigate risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.