Latest / Tech Talks With Kinsoft / 447GB Exposed: The Kelly Legal Breach and Emerging November Threats
Transcript
- 0:00Hello and welcome to Tech Talks with Kinsoft.
- 0:02It is Thursday, the 5th of February, 2026. I'm
- 0:06your host and, uh... I have to say what we're
- 0:09unpacking today has me sort of nervously double
- 0:12checking my own passwords. It has that effect
- 0:14on people. It really does. We're looking at a
- 0:17series of events from late last year that have
- 0:18just sent shockwaves through the Australian professional
- 0:21services industry. But before we get into the,
- 0:25you know, the nitty gritty, I want you to imagine
- 0:27something. Imagine you walk into your office.
- 0:29It's a Tuesday morning. You've got your coffee.
- 0:32You sit down. You wiggle the mouse and just.
- 0:35Black screen, nothing. So you pick up your desk
- 0:37phone to call IT. Dead air. Dead air. You check
- 0:39the Wi -Fi on your mobile. Connection refused.
- 0:42The only way you can tell your clients you even
- 0:44still exist is to post on your personal Facebook
- 0:46page. Which is, I mean, that is the exact nightmare
- 0:48that played out for a Queensland law firm just
- 0:51a few months ago. Exactly. That's our starting
- 0:53point today. The Kelly legal data breach from
- 0:56late 2025. But I want to be really clear. This
- 0:59is not just a story about one law firm. If you're
- 1:02listening and thinking, oh, well, I don't run
- 1:04a law firm in Queensland. I'm fine. You are missing
- 1:06the bigger picture here. You absolutely are.
- 1:09This is a story about a tactical shift. What
- 1:11we're seeing. and the data backs this up, is
- 1:14a targeted campaign. We're not talking about
- 1:16random attacks anymore. We're talking about snipers.
- 1:19Snipers. I like that analogy. So, OK, let's get
- 1:21into the anatomy of this thing. Yeah. Take us
- 1:23back to October 2025. How does a disaster like
- 1:27this actually begin? It began with that silence
- 1:29you described. On October 10th, Kelly Legal posted
- 1:32on Facebook calling it an IT and phone system
- 1:35blackout. A blackout. See, that sounds almost
- 1:38manageable, like a power outage. Right. It sounds
- 1:40technical, maybe fixable. That's often the denial
- 1:43phase. But later that day, the story changed.
- 1:45They confirmed it was a hacking incident. But
- 1:48there was one line in their warning to clients
- 1:50that was just a massive red flag. I've got it
- 1:52here. They told clients to, quote, verify bank
- 1:55account details by phone before acting on any
- 1:58requests for funds. Exactly. Now, stop and think
- 2:02about that. If your system is just encrypted
- 2:04or offline, why are you so worried about bank
- 2:07details? Well, they're worried about fraud, I
- 2:09assume? Someone tricking their clients? It's
- 2:12more specific. It screams business email compromise.
- 2:16It means they feared the hackers weren't just
- 2:18outside the walls locking the doors. They were
- 2:21inside. Inside the email system. So what does
- 2:23that mean exactly? Payment redirection. It's
- 2:25like a thief standing at your mailbox, steaming
- 2:28open your invoices, changing the bank account
- 2:30details to their own, and then sealing it back
- 2:32up. The client pays what looks like a legitimate
- 2:34bill. And the money just vanishes. So Kelly Legal
- 2:37was fighting a war on two fronts. Get their systems
- 2:40back and stop their clients from accidentally
- 2:42wiring money to criminals. And that's a terrifying
- 2:45position to be in. But the really big shoe didn't
- 2:48drop for another month. November 13th. That's
- 2:51when the group behind it all, INC Ransom, listed
- 2:54Kelly Legal on their Darknet leak site. Listed?
- 2:57That sounds so clinical. It's a trophy wall.
- 2:59It's where they post the proof. And they claim
- 3:01to have exfiltrated 447 gigabytes of data. Okay,
- 3:06let's drill down on that. 447 gigs. To some people
- 3:09listening, that might not sound like a lot in
- 3:11a world of 4K movies. But for a law firm, what
- 3:15is that? It is colossal. We're talking about
- 3:18documents, PDFs, Word files. They're tiny. To
- 3:21get to 447 gigs, you're talking about hundreds
- 3:24of thousands of files. It's the entire firm.
- 3:27Contracts, financial data, HR files, customer
- 3:30data. The HR files. That's the part that makes
- 3:33my skin crawl. It's not just rich clients. It's
- 3:35the staff, their personal information. It's the
- 3:37crown jewels of confidentiality. And this is
- 3:40the core of INC Ransom's business model. It's
- 3:43what we call double extortion. Walk us through
- 3:44that. Okay, so step one, encrypt all the data.
- 3:47The firm grinds to a halt. You can't work. That's
- 3:50operational panic. Right. Step two, steal a copy
- 3:53of all that data and threaten to leak it publicly.
- 3:55Now you have reputational panic. Because for
- 3:57a law firm, your reputation is everything. If
- 3:59I can't trust you with my secrets, I can't hire
- 4:01you. You've hit the nail on the head. INC Ransom
- 4:03knows this. They are leverage experts. They know
- 4:07a firm can probably survive a week of downtime.
- 4:10They absolutely cannot survive a total breach
- 4:12of client confidentiality. So who are these people?
- 4:15Who is INC Ransom? They seem to have just exploded
- 4:18onto the scene. They're relatively new, yeah.
- 4:20First seen around August 2023. But they are very,
- 4:25very good at what they do. They hit North America,
- 4:27Europe. but they have developed a real taste
- 4:31for Australian organizations. So we're not just
- 4:33a sideshow for them. Not at all. Remember early
- 4:36last year, early 2025, the attack on Spectrum
- 4:39Medical Imaging in Sydney? Vaguely. That was
- 4:42the one with patient records. That was them.
- 4:44That was INC Ransom. So you see the pattern.
- 4:46First medical records, now sensitive legal files.
- 4:48They're systematically targeting sectors with
- 4:51high -value, high -leverage data. And how are
- 4:53they getting in? Is it some brute force, Mission
- 4:55Impossible -style hack? It's usually much quieter.
- 4:58Their signature is spear phishing. Okay, so spear
- 5:00phishing. Different from the normal phishing
- 5:03emails we all get about a Nigerian prince. Very
- 5:06different. Normal phishing is like casting a
- 5:08wide net. Spearfishing is hunting with a sniper
- 5:11rifle. It's not a generic email. It's an email
- 5:13that says, hi, Sarah, just following up on the
- 5:15Johnson settlement. Attached is the revised contract.
- 5:18So it knows her name. It knows a file she's working
- 5:20on. Exactly. They do their homework. They look
- 5:23at LinkedIn. They read your website. Maybe they've
- 5:25already compromised a vendor you work with. The
- 5:27emails are targeted. They're researched. And
- 5:29they are incredibly hard to spot. That is genuinely
- 5:32unnerving. And it brings us to the next point,
- 5:34because Kelly Legal. As bad as it was, it wasn't
- 5:37an isolated case, was it? Not even close. If
- 5:40you zoom out and look at that whole period in
- 5:42late 2025, it was. Well, it was open season on
- 5:46Australian professional services. Yeah, you sent
- 5:48me the list. It wasn't just them. Far from it.
- 5:50You had Bryden's lawyers in Sydney. Hackers claimed
- 5:53600 gigs of data from them. You had Skeggs Goldstein,
- 5:57a financial services firm in NSW, hit by a different
- 6:00group, Kwylan. For 500 gigs. So why? Why these
- 6:04mid -sized Australian firms? Why not go for the
- 6:07big banks, you know, Telstra? Because a big bank
- 6:10is like Fort Knox. They have billion -dollar
- 6:12security budgets. A mid -sized law firm, on the
- 6:15other hand, is the Goldilocks target. The Goldilocks.
- 6:19They're big enough to have money and be able
- 6:20to pay a hefty ransom. They hold incredibly sensitive
- 6:23data. But they're small enough that their IT
- 6:27security might not be military grade. It's the
- 6:30path of least resistance. for the biggest reward
- 6:32and the most leverage the most leverage is blackmail
- 6:35pure and simple but this is where the story gets
- 6:38even bigger it's not just about who these firms
- 6:40are it's about who they work for it's the supply
- 6:42chain okay so this is where it goes from being
- 6:44a business problem to potentially a national
- 6:47security problem precisely let's talk about icad
- 6:50engineering right the defense supplier an australian
- 6:52defense supplier late 2025 they get listed by
- 6:56a group called j group And we are not talking
- 6:58about divorce settlements anymore. We're talking
- 7:00Hunter class frigates, Collins class submarines.
- 7:04And the hackers claimed they had access to ICAD
- 7:07systems for five months. Wait, what? Five months?
- 7:10Just sitting inside their network? Just sitting
- 7:12there, watching, downloading. And do you know
- 7:16how they allegedly got in? I'm almost afraid
- 7:18to ask. An outdated VPN vulnerability. A VPN.
- 7:22The very thing that's meant to keep you secure.
- 7:24It keeps you secure if you keep it updated. If
- 7:27it has a known hole and you don't patch it, it's
- 7:29not a secure tunnel. It's an open door that you've
- 7:32just left unlocked. So the hackers didn't have
- 7:35to be geniuses. They just had to rattle the doorknobs
- 7:37on the street until one opened. Essentially.
- 7:39But see, the strategy. They didn't attack the
- 7:41Australian Navy. They attacked the engineering
- 7:43firm that works for the Navy. A side door. It's
- 7:45the supply chain attack. We saw it again with
- 7:47the Army's redback program, the armored vehicles.
- 7:50Right. Another group published the designs for
- 7:52those, didn't they? A group called CyberTufan.
- 7:54Link to. Iran. And again, they didn't hack the
- 7:58Australian army. They hacked the contractors
- 8:01in the supply chain. So the lesson here is that
- 8:04you're a target not just for what you have, but
- 8:06for who you know. That is the single most important
- 8:08takeaway. You might think you make boring bolts
- 8:11for a living, but if those bolts go into a submarine,
- 8:14you're not a boring target anymore. You are a
- 8:17stepping stone. Which is a really sobering thought.
- 8:20And the tools they're using to find these stepping
- 8:22stones are getting... Well, scarily smart. Let's
- 8:26talk about the AI. Oh, yeah. This is the real
- 8:28game changer. Those reports from Google and Anthropic
- 8:31late last year were eye opening. For years, the
- 8:34advice for spotting a phishing email was look
- 8:37for bad grammar. Right. Kindly do the needful.
- 8:40That was always the giveaway. That safety net
- 8:42is gone. Yeah. Hackers are now using large language
- 8:45models, AI, to write perfect, persuasive, context
- 8:48-aware business English. So that hyper -targeted
- 8:51spear phishing we talked about. Is now being
- 8:53automated and scaled. An AI can scan your LinkedIn,
- 8:56read your company's last press release, and then
- 8:59draft an email to you that is indistinguishable
- 9:01from one written by a real colleague. It can
- 9:03do it a thousand times a minute. So the barrier
- 9:06to entry for being a sophisticated attacker is
- 9:08just... dropping through the floor. It's dropping
- 9:11fast. And while the big AI companies were trying
- 9:14to build in safety rails, the criminals are just
- 9:17running their own models on what's called bulletproof
- 9:19hosting. Bulletproof hosting? Explain that. It
- 9:21sounds like something out of a spy movie. It's
- 9:23basically a web hosting service that promises
- 9:25not to take your site down no matter what. They're
- 9:28often in jurisdictions that don't cooperate with
- 9:30law enforcement. It's where the ransomware groups
- 9:33host their leak sites and command centers. And
- 9:36the government's trying to fight this. I saw
- 9:37they issued some sanctions. They are, yes. In
- 9:39November, Australia, the U .K. and the U .S.
- 9:43sanctioned some Russian individuals and companies
- 9:45providing these services. It's a good step. It
- 9:47creates friction for the criminals. But it's
- 9:49not a silver bullet. It's a game of whack -a
- 9:51-mole. You shut one down, they pop up under a
- 9:54new name. The criminals are agile. So let's bring
- 9:57this all home. If the government can't stop it
- 9:59overnight and the bad guys have AI, what can
- 10:02the average person or business actually do? What's
- 10:05the actionable advice here? It means we have
- 10:08to change our fundamental behavior. We have to
- 10:11move away from a position of default trust in
- 10:14digital communication. Okay, so let's get specific.
- 10:18I'm a client. My lawyer emails me new bank account
- 10:22details for a house deposit. What do I do? You
- 10:24pick up the phone. And you call a number you
- 10:27know is correct from their website or an old
- 10:30letter, not the number in the email signature.
- 10:32Because the hacker could have changed that too.
- 10:34Of course. You call and you get them to read
- 10:37the BSB and account number to you over the phone.
- 10:40That one single slightly analog step can save
- 10:43you from losing everything. Okay, that's for
- 10:45the client. What about the business owner? Two
- 10:47big things. First, verify your vendors, the supply
- 10:50chain. You have to ask your software providers
- 10:53the hard questions. What are you doing for security?
- 10:55Because if they get hacked, you get hacked. And
- 10:57then the second thing. The boring basics. That
- 10:59ICAD breach. Five months of access from an unpatched
- 11:03VPN. That is an unforced error. It is leaving
- 11:06the front door wide open. Patch your systems.
- 11:08And backups are still a thing, right? They are
- 11:10critical. But not just having them. Testing them.
- 11:14And making sure they are immutable. Immutable,
- 11:17meaning they can't be changed. Exactly. The ransomware
- 11:19is programmed to find and encrypt your backups
- 11:22first. An immutable backup is locked. It can't
- 11:24be deleted or changed, even by an administrator,
- 11:26for a set period. It's your last line of defense.
- 11:29It really feels like we're moving past that old
- 11:31mantra of trust but verify. Trust but verify
- 11:34is dead. The modern philosophy is zero trust.
- 11:38Zero trust sounds a bit intense. It means what
- 11:41it says. Assume the breach has already happened.
- 11:44Assume every user, every device, every connection
- 11:47is hostile until proven otherwise. Verify everything,
- 11:50every time. That sounds exhausting. It adds a
- 11:53little friction, yes. But you have to weigh that
- 11:56friction against the alternative, which is posting
- 11:58on Facebook, because your entire business has
- 12:00been stolen. When you put it that way. A little
- 12:02friction sounds like a bargain. It's just the
- 12:04cost of doing business securely in 2026. You
- 12:07know, that 447 gigabyte number from Kelly Legal.
- 12:10It's just it's not just data, is it? It's lives.
- 12:13It's secrets. That's the core of it. We say data
- 12:17breach and it sounds so sterile. But it's human
- 12:20misery being packaged up and sold. These groups
- 12:23have turned professional confidentiality into
- 12:26a commodity. And they're very, very good at their
- 12:28business. Which means we have to be better at
- 12:30ours. We can't wait for the blackout. No. You
- 12:34have to ask yourself now, if INC Ransom knocked
- 12:37on my door tomorrow, what would they find? That
- 12:39is the question everyone needs to be thinking
- 12:41about. And look, if this conversation has made
- 12:43you a little uneasy, and it should, and you're
- 12:46sitting there wondering if your VPN is patched
- 12:48or if your members are secure, you really shouldn't
- 12:50try to solve this on your own. Absolutely not.
- 12:52This is a full -time job for experts. It is.
- 12:55So for anyone wanting to get ahead of this before
- 12:57you end up as a case study, I would really suggest
- 13:00you head over to www .kinsoft .com .au. Go and
- 13:03have a conversation with them about your security
- 13:05and your IT needs. It's a conversation you want
- 13:07to have on your own terms. Exactly. Better to
- 13:10have it now than with a hacker later. Well, that
- 13:13is all we have time for. A huge thank you for
- 13:16walking us through this terrifying new landscape.
- 13:19My pleasure. Stay safe. And thank you for listening
- 13:22to Tech Talks with Kinsoft. Until next time,
- 13:24update your systems, verify those bank details,
- 13:26and don't click the link. Goodbye.