Latest / Tech Talks With Kinsoft / Reynella East College – Interlock's First Australian Victim Dumps 600GB of School Data
Transcript
- 0:00Imagine logging into your school portal on a
- 0:02Tuesday morning. You just want to like check
- 0:04a schedule or maybe look at a lunch menu. And
- 0:06instead you are staring down a ransom note from
- 0:09an international extortion syndicate. Yeah, it's
- 0:12completely jarring image. Right. It sounds like
- 0:14the plot of a bad cyber thriller. But on June
- 0:179th, 2026, that was the exact reality for a community
- 0:21in South Australia. And that perfectly encapsulates
- 0:24why we are looking so closely at this today.
- 0:27I mean, we are dissecting the breach at Raynella
- 0:29East College, which was executed by the ransomware
- 0:32cartel known as Interlock. A completely massive
- 0:34incident. Huge. And our mission for this deep
- 0:37dive is to extract the actual operational reality
- 0:40from this crisis. We are going to look at how
- 0:43threat actors bypass million -dollar defenses,
- 0:46how they hoard data, and ultimately... how they
- 0:49weaponize the very systems designed to protect
- 0:51us. OK, let's unpack this, because the timeline
- 0:53of how this attack unfolded is just so deceptive.
- 0:56It really is. Ground zero for the public is early
- 0:58June. So Ronella East College is a massive P
- 1:02-12 public school down in Adelaide. We are talking
- 1:05preschool all the way up to year 12, over 1 ,900
- 1:08students, including international enrollees.
- 1:11So a really huge administrative footprint. Massive
- 1:14amounts of data. Exactly. So on June 9th, Parents
- 1:17get a notification about a, quote, cybersecurity
- 1:20breach. All ICT systems are pulled offline. Right.
- 1:24And for about a week, the school and the Department
- 1:26for Education are just in complete blackout mode
- 1:29trying to figure out what actually happened.
- 1:31But reading through the logs and the public statements
- 1:34we have, it seems like the immediate community
- 1:36reaction was essentially just, oh, the servers
- 1:38are acting up again. Yeah, a lot of denial. Right.
- 1:40There's this assumption of a temporary disruption.
- 1:43But honestly, whenever an organization goes dark
- 1:46for days and says cyber incident, I immediately
- 1:49assume the worst. I mean, is it ever just an
- 1:51outage anymore or is that initial quiet period
- 1:54just organizations praying the house wasn't completely
- 1:57robbed? Honestly, it's almost always the latter.
- 2:01And it stems from a pretty fundamental misunderstanding
- 2:03of how modern network infiltration actually works.
- 2:07How so? Well, when the sisters went offline on
- 2:10June 9th, that was not the beginning of the attack.
- 2:13That was the grand finale. But the grand finale,
- 2:15so they had already been inside for weeks. Yeah,
- 2:18exactly. The industry term for this is dwell
- 2:20time. Attackers don't just, you know, kick down
- 2:23the door, encrypt your files and leave a note
- 2:25in five minutes. Right. It's much more like a
- 2:27burglar getting a job as the night janitor in
- 2:30your building. They spend weeks, sometimes months,
- 2:33just walking the halls with their mop and bucket.
- 2:35It's quietly looking around. Exactly. Yeah. They
- 2:38are quietly mapping the network topology, figuring
- 2:42out where the domain controllers are, locating
- 2:44the digital vaults, and critically, hunting down
- 2:47the network backups so they can destroy them
- 2:49first. Wow. So they take out the safety net before
- 2:51they even strike. Right. And they exfiltrate
- 2:54the data slowly. So they don't trigger any bandwidth
- 2:56alarms. Deploying the ransomware that actually
- 2:59locks everyone out is literally the last button
- 3:01they press on their way out the door. So by the
- 3:03time the parents got that email on June 9th,
- 3:05the ghost was already out of the machine. The
- 3:08data was gone. It was long gone. Which is why
- 3:10exactly 14 days later on June 23rd, the whole
- 3:14facade of a mere disruption completely evaporated.
- 3:17Right. Because Interlock listed the school on
- 3:20its dark web leak site and just started publishing
- 3:23the stolen data. Yeah. They made it incredibly
- 3:25public. And this is where I have to like call
- 3:28a timeout and look at the actual claims being
- 3:30made because the numbers Interlock threw out
- 3:31there made me immediately skeptical. The file
- 3:34sizes. Yeah. They claimed they stole 610. gigabytes
- 3:38of data for a single public school. I mean, over
- 3:42473 ,000 files across 68 ,000 folders. That just
- 3:47sounds completely absurd. Is that even physically
- 3:49plausible or are they just making up terrifying
- 3:51numbers to trigger a panic? What's fascinating
- 3:53here is that you are picking up on the exact
- 3:56psychological warfare tactic these cartels rely
- 3:59on. So it is fake. Well, it's asymmetric information.
- 4:02You have to remember, neither the school's forensic
- 4:05teams nor independent security analysts have
- 4:08been able to verify that 610 gigabyte figure.
- 4:11Okay, so it's unconfirmed. Highly unconfirmed.
- 4:13In fact, third -party reviewers explicitly stated
- 4:17they couldn't validate the total volume. Interlock
- 4:20throws out a massive, terrifying number because
- 4:22they know the school's IT department is still
- 4:25scrambling to figure out what was even touched.
- 4:27It's a pure negotiation tactic. I mean, they
- 4:29want the school board in a blind panic, thinking
- 4:32everything from the last 20 years is out there
- 4:34just so they pay the ransom faster. Precisely.
- 4:37We have to treat that 610 gigabyte claim as a
- 4:40weaponized bluff. Both things can be true simultaneously,
- 4:43right? The breach is catastrophic and real, but
- 4:47the criminal's specific claims are highly inflated
- 4:49for leverage. Okay, so if we table their inflated
- 4:52marketing numbers, let's talk about what the
- 4:54independent reviewers did find in the initial
- 4:56data dumps. Because frankly, the verified reality
- 4:59is plenty horrifying on its own. It really is.
- 5:02I mean, the security journalists who analyzed
- 5:03the leaked materials confirmed the presence of
- 5:06highly sensitive files. We are talking about
- 5:08school budgets, teaching documents, extensive
- 5:11contact details for students and their families.
- 5:14And the passports. Yeah, they found high -resolution
- 5:16passport scans belonging to international students
- 5:19and teaching staff. And then there's the technical
- 5:21failure that completely blew my mind, the plain
- 5:23text password. Yes, just lists of network passwords
- 5:26stored right next to their corresponding usernames.
- 5:29Completely unincre - I genuinely cannot comprehend
- 5:32that. We are talking about a major institution
- 5:34in 2026. No hashing, no salting, no secure credential
- 5:39management whatsoever. Just raw text sitting
- 5:43in a directory. Yeah, it's bad. I mean, storing
- 5:45passwords in plain text next to usernames is
- 5:48literally like taping your ATM PI in the front
- 5:51of your debit card and leaving it on a park bench.
- 5:53It completely invalidates the entire concept
- 5:55of network security. It does. And when attackers
- 5:57uncover a spreadsheet or a directory of plain
- 6:00text credentials, the infiltrate. phase is essentially
- 6:03over. Because they just have the keys to the
- 6:05castle. Exactly. They don't have to exploit software
- 6:08vulnerabilities or write custom malware to move
- 6:10laterally through the system anymore. They just
- 6:12log in. They use those valid credentials to open
- 6:15every other door in the network. It turns a localized
- 6:18compromise into a total systemic collapse. And
- 6:21think about your own digital footprint right
- 6:23now for everyone listening. How many former employers
- 6:27or how many gyms, travel agencies, landlords
- 6:30currently have a scan of your passport or your
- 6:33driver's license just sitting on some forgotten
- 6:35server? It's a scary thought. Because once it's
- 6:38on a shared drive, it is just waiting for someone
- 6:40to find it. And if we connect this to the bigger
- 6:42picture, it really forces us to look at the gap
- 6:44between our assumptions of safety and the operational
- 6:47reality of how data is handled. We're living
- 6:50in an ecosystem that inherently encourages data
- 6:53hoarding. Because storage is basically free now.
- 6:55Exactly. Organizations collect massive amounts
- 6:58of identity metrics because storage is cheap,
- 7:00but they completely lack the administrative discipline
- 7:03to ever purge it. Which brings us to the threat
- 7:05actors who are exploiting that exact lack of
- 7:08discipline. For a long time, there was this prevailing
- 7:11idea, a sort of naive optimism, that hackers
- 7:15had boundaries. Right. That places like schools,
- 7:18hospitals, charities were largely off limits
- 7:21because there was no financial upside. Or maybe
- 7:23just a baseline level of human decency. Yeah,
- 7:26the lazy comfort of assumed immunity. Yes. That
- 7:29assumption is definitively dead. The reality
- 7:32is that ransomware operators like Interlock have
- 7:35absolutely zero moral compass. They are hyper
- 7:38rational opportunists. They just want the money.
- 7:41They do not care about the societal value of
- 7:43the institution at all. They only care about
- 7:45the intersection of vulnerability and leverage.
- 7:47And a school sits perfectly at that intersection.
- 7:50They are notoriously underfunded when it comes
- 7:52to enterprise grade IT infrastructure, but they
- 7:54hold incredibly rich, heavily regulated data.
- 7:57Right. The leverage is huge. The leverage to
- 7:59pay the ransom to protect the kids is. astronomical.
- 8:02Exactly. But how they actually break in is what
- 8:05organizations really need to understand because
- 8:07it completely shatters the Hollywood myth of
- 8:10the hacker. Right. It's not green code raining
- 8:13down a screen. No, not at all. Interlock didn't
- 8:16burn a million dollar zero day exploit to get
- 8:19into Brunella East College. They used social
- 8:22engineering, specifically a fake. verify your
- 8:26human pop -up. I saw that in the sources, and
- 8:29I need you to explain the mechanics of this,
- 8:30because I think a lot of people hear fake CapyCHA
- 8:33and assume it just steals your password if you
- 8:35type it in. Right, like a phishing page. Yeah.
- 8:37But this bypassed modern endpoint security, how
- 8:41does clicking a fake CapyCHA give an attacker
- 8:45a permanent foothold? It's brilliantly insidious
- 8:48because it weaponizes our daily friction. You
- 8:51land on a compromised website or maybe open a
- 8:53malicious HTML attachment and you get a pop -up
- 8:55that looks exactly like a standard Cloudflare
- 8:58or Google Cappy CCHA. Just a normal, annoying
- 9:01internet hurdle. Exactly. It says verify you
- 9:04are human to view this document, but instead
- 9:06of clicking a traffic light or a crosswalk, it
- 9:08gives you a sequence of keyboard commands to
- 9:10prove you aren't a bot. Like pressing Windows
- 9:12plus R, pasting something, and hitting enter.
- 9:15Exactly. When you click the initial verify button,
- 9:18the malicious site silently copies a heavily
- 9:21obfuscated PowerShell script directly to your
- 9:23computer's clipboard. Oh, wow. The subsequent
- 9:26instructions, pressing Windows and R and hitting
- 9:28enter, that basically tricks the user into opening
- 9:31their own terminal and executing the malicious
- 9:34code directly from their own clipboard. Here's
- 9:36where it gets really interesting. So it's not
- 9:38even a software exploit. It is entirely exploiting
- 9:41muscle memory and human fatigue. That is the
- 9:44core of it. And this is exactly why it bypasses
- 9:47millions of dollars in enterprise security. Your
- 9:50endpoint detection and response software, your
- 9:52firewalls, they don't see an external threat
- 9:55trying to force its way in. Because it's coming
- 9:57from inside the house. Precisely. They see a
- 9:59legitimately authenticated user sitting at their
- 10:02authorized workstation, actively executing a
- 10:05command. The security tools inherently trust
- 10:08the human, and the human has been tricked into
- 10:10opening the door from the inside. So if perimeter
- 10:13defense is essentially failing because it's so
- 10:15easy to engineer human error, the fallback strategy
- 10:18has to be what's actually sitting on the servers
- 10:21when they inevitably get in. Absolutely. Which
- 10:24pivots us from just admiring the problem to actually
- 10:27fixing it. Looking at this specific disaster.
- 10:30What are the concrete operational lessons you
- 10:33can take back to your own teams? There are three
- 10:35non -negotiable lessons we can extract from this.
- 10:38The first is accepting your status as a target.
- 10:41Right. If anyone in your organization is still
- 10:43saying, oh, we're a small firm or we just do
- 10:45public administration, no one wants our data,
- 10:47you have to kill that culture immediately. Because
- 10:50it's not a guy in a hoodie specifically choosing
- 10:52to target your local school. It's just automated
- 10:54scanning, right? Precisely. Interlock operates
- 10:57on scale. They deploy automated scripts that
- 10:59just scour the global internet 24 -7 looking
- 11:02for an unpatched VPN, a misconfigured remote
- 11:05desktop protocol, or a susceptible user. I don't
- 11:09care who you are. They don't even know who you
- 11:10are until the script alerts them that a door
- 11:13just opened. If you have an internet connection,
- 11:16you are on the target list. Okay, so target acceptance
- 11:19is lesson one. Lesson two seems to be the one
- 11:22that Rinella East College failed most catastrophically,
- 11:25which is data hygiene is your actual defense.
- 11:28Yes, data minimization is the only true defense
- 11:32against extortion. Think about the passports
- 11:35found in this leak. Yeah, that's the scariest
- 11:37part. You can reset a compromised password in
- 11:4030 seconds. You can issue a new credit card in
- 11:42a week. But a passport scan. That contains your
- 11:46legal name, your date of birth, your place of
- 11:49birth, your biometric photo. You cannot rotate
- 11:51a birth certificate. No, it's permanent infrastructure
- 11:53for your identity. I mean, if that leaks, you
- 11:56are exposed to synthetic identity fraud for the
- 11:59rest of your life. Which is exactly why organizations
- 12:01have to stop treating server space like a digital
- 12:03attic. Every listener should literally walk into
- 12:06their next management meeting and ask, do we
- 12:08actually need to retain these passport scans?
- 12:11Right. If we only needed them to verify identity
- 12:13at enrollment, why are they still in the server
- 12:15three years later? Exactly. Is the data encrypted
- 12:18at rest? Who actually has access permissions
- 12:20to that folder? If you don't need it, destroy
- 12:22it. If you reduce the blast radius of a breach,
- 12:26you remove the attacker's leverage entirely.
- 12:28And that leads perfectly into the third lesson,
- 12:30which is about managing the crisis itself when
- 12:33that blast radius is actually realized. How do
- 12:36you navigate the immediate aftermath without
- 12:38completely destroying public trust? It requires
- 12:41a massive amount of operational discipline, really,
- 12:43to manage the gap between criminal claims and
- 12:47forensic reality. We saw this exact same dynamic
- 12:50play out with a regional fire service just two
- 12:52weeks before the school attack. Right. I remember
- 12:54that. The attackers claim they stole a terabyte
- 12:57of sensitive dispatch data. The media picks up
- 12:59the terrifying number and the organization is
- 13:02caught flat footed because their IT team needs
- 13:04like three weeks to do a proper forensic audit.
- 13:07And that three week window is where trust is
- 13:09either maintained or destroyed. The mandate for
- 13:12leadership is to resist panic and equally to
- 13:15resist denial. So you have to be straight with
- 13:17people. You have to investigate methodically.
- 13:20When you communicate with your stakeholders,
- 13:22you state exactly what you know to be true. But
- 13:25more importantly, you must be ruthlessly transparent
- 13:27about what you don't yet know. So no corporate
- 13:31speak. No, we take your privacy seriously while
- 13:35we look into a minor disruption. Never downplay
- 13:37it. If you say it's a minor disruption and then
- 13:40two weeks later passports are on the dark web,
- 13:42you will never regain the trust of that community.
- 13:45You own the uncertainty early so you can own
- 13:48the narrative later. It seems like the overarching
- 13:50theme here is proactive auditing. Getting your
- 13:53house in order before the burglars realize you
- 13:56left the window open? It has to be. And there
- 13:58are entire sectors of the cybersecurity industry
- 14:00dedicated to this now. I know the author of the
- 14:03source material pointed to companies like Kinsoft,
- 14:05who specialize in exactly this. They come in,
- 14:08run automated audits of your shared drives, flag
- 14:11the plain text passwords, find the five -year
- 14:13-old passport scans, and basically force you
- 14:15to clean it up. Because the harsh reality of
- 14:17the current threat landscape is that an audit
- 14:20is going to happen to your network this year.
- 14:22Will you like it or not? Exactly. The only choice
- 14:24you get to make is whether that audit is conducted
- 14:26by a hired security firm or by an international
- 14:29extortion cartel. Once the data leaves your physical
- 14:32building, you have permanently lost control of
- 14:35the safety of the people who trusted you. So
- 14:38let's summarize the domino effect we've mapped
- 14:40out today. It starts with a completely mundane
- 14:42human action, a staff member tiredly clicking
- 14:46through a fake verify your human prompt. That
- 14:49muscle memory mistake hands an attacker a foothold.
- 14:52They quietly map the network, locate the digital
- 14:55gold mine of student passports and unencrypted
- 14:58passwords, pull it all out, and just slam the
- 15:00door shut behind them with ransomware. A nightmare
- 15:02scenario. And suddenly, a week of operational
- 15:06blackout turns into a permanent dark web exposure.
- 15:09It's a stark reminder that being technologically
- 15:12informed isn't just about reading the news. It's
- 15:14about looking critically at your own digital
- 15:16footprint, your own organization's shared drives,
- 15:20and asking, what old scams am I leaving in my
- 15:23forgotten folders? And who are we putting at
- 15:25risk by keeping them? And if I can leave you
- 15:28with one final thought to consider about all
- 15:29of this. Please do. Breaches like this one at
- 15:32Ranella East College are ushering in an entirely
- 15:34unprecedented societal shift. We are now looking
- 15:38at an entire generation of children, Gen Alpha,
- 15:41Gen Z, who will have their permanent, unchangeable
- 15:44identity metrics compromised before they even
- 15:46learn to drive. Passports, detailed medical histories,
- 15:50behavioral records, these are being permanently
- 15:52indexed on the dark web while they are still
- 15:54in primary school. We really need to ask ourselves,
- 15:57what does it mean for our society when the very
- 15:59concept of starting adulthood with a clean slate
- 16:02is technically impossible? That's incredibly
- 16:04bleak. These kids are inheriting pre -compromised
- 16:07digital lives, and it is entirely due to the
- 16:10data hygiene failures of the institutions that
- 16:12were explicitly designed to protect them. That
- 16:15is a deeply unsettling reality and a perfect
- 16:18place to wrap up today's analysis. Thank you
- 16:20for joining us on this deep dive. Stay patched
- 16:22and stay skeptical.