Latest / Tech Talks With Kinsoft / Ransomware Attack on United Australia Party and Trumpet of Patriots
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. We're your
- 0:01guide for, well, cutting through the tech noise
- 0:04and getting to the insights that really matter.
- 0:06That's right. Making sense of the complex stuff.
- 0:08And today we're looking at something that, frankly,
- 0:11impacts all of us, cybersecurity, especially
- 0:13right here in Australia. There's been a real
- 0:15uptick in incidents lately. A worrying trend,
- 0:19definitely. Yeah. And one particular case involving
- 0:21a political party really highlights some unique
- 0:24risks. So today we'll unpack what went down.
- 0:28why it's, well, significant for you, and what
- 0:30it tells us about staying safe online. OK, let's
- 0:34dive into that specific incident first. The ransomware
- 0:37attack on Clive Palmer's Trumpet of Patriots
- 0:39and the United Australia Party, UAP. Yeah. This
- 0:42wasn't just, you know, another corporate hack.
- 0:45No, definitely not. The attack itself happened
- 0:47back on June 23rd, 2025, but it wasn't actually
- 0:51announced until mid -July, July 17th. OK, quite
- 0:54a delay there. Yes. And what happened was attackers
- 0:57got into their servers and, crucially, copied
- 0:59a lot of data. The potential scope here is, well,
- 1:02it's pretty vast. What kind of data are we talking
- 1:04about? It's a wide range and much of it deeply
- 1:06personal. Think banking records, emails, phone
- 1:09numbers, ID documents, employment history. Basically,
- 1:15all emails and documents they held on that server,
- 1:18everything. Wow. And here's a really concerning
- 1:21part. The parties themselves admitted they didn't
- 1:24comprehensively know what information was actually
- 1:26on the server. They didn't know what data they
- 1:27had. Apparently not comprehensively. And because
- 1:29of that, they said it was impracticable to notify
- 1:32individuals directly. Impracticable. Yeah. Instead
- 1:35of telling people their data might be out there.
- 1:37Exactly. They just posted a notice on their website.
- 1:40Now, they did take steps. They secured systems,
- 1:42restored from backups, reported it to the OAIC,
- 1:45that's the information commissioner, and the
- 1:47ASD, the signals directorate. Right, the standard
- 1:50incident response steps. Mostly, yes. And they
- 1:52gave the usual advice, monitor bank accounts,
- 1:55change passwords, use MFA, watch out for scams.
- 1:57But that lack of direct notification, that really
- 2:00stood out. Especially given whose data it was.
- 2:03Yeah. That notification piece or lack of it really
- 2:07hits differently with a political party, doesn't
- 2:09it? It feels bigger than just a company losing
- 2:12customer details. Absolutely. It's not just about
- 2:14financial risk, though, that's there. It's about,
- 2:17well. political affiliations, personal beliefs,
- 2:20maybe even private messages about democratic
- 2:22activities. That kind of information getting
- 2:25out, it's potentially weaponizable. Weaponizable.
- 2:28Yeah. That's a chilling thought. It strikes at
- 2:30the heart of privacy and, you know, even democratic
- 2:33processes. Precisely. And this whole situation
- 2:35throws a spotlight on a really significant loophole
- 2:39in Australian law. Which is? The Australian Privacy
- 2:42Act. It has this specific exemption just for
- 2:45political parties. An exemption. Meaning unlike
- 2:48almost every other organization handling your
- 2:50data, political parties aren't legally required
- 2:53to report data breaches under the notifiable
- 2:55data breaches scheme. They also don't have to
- 2:57follow many of the basic rules about handling
- 2:59personal information. So the UAP telling anyone
- 3:02about this breach was entirely voluntary. Entirely
- 3:06voluntary. They had no legal obligation under
- 3:08the Privacy Act to do so. That seems odd. Hasn't
- 3:11this been raised before? Oh, yes. For years.
- 3:14The Attorney General's Department did a big review
- 3:16of the Privacy Act report back in 2022. They
- 3:19explicitly called this exemption a significant
- 3:22risk. A significant risk. So the government knew.
- 3:25They were certainly told. The report noted that
- 3:27almost all submissions they got argued the exemption
- 3:30couldn't be justified. They said there was basically
- 3:33no clear reason why parties should not be accountable
- 3:37like everyone else. So if the parties holding
- 3:40data about our political views, our voting intentions
- 3:43are exempt. from rules everyone else follows.
- 3:46What does that mean for us, for the average person?
- 3:49It means they have privileged access to the electoral
- 3:52roll and they can build these huge databases
- 3:55on voters, demographics, beliefs, you name it.
- 3:57Reset Australia warned this stuff is very valuable
- 4:00and potentially dangerous. Dangerous how? Like
- 4:04for election interference. That's exactly the
- 4:06fear. Malicious actors could exploit this weak
- 4:08spot to mess with democratic processes. Imagine
- 4:11targeted disinformation campaigns based on stolen
- 4:13political profiles. Even the privacy commissioner,
- 4:16Carly Kind, she publicly questioned if the exemption
- 4:20is still appropriate. She said it's out of step
- 4:23with community expectations and the risks we
- 4:25face now, you know, in the digital age. It sounds
- 4:28like there's a strong consensus this needs fixing.
- 4:30What has the government actually done? Well,
- 4:33the current government, when they responded to
- 4:35that big privacy review, they mostly just noted.
- 4:38the recommendations about the political party
- 4:40exemption just noted yep and the first set of
- 4:44privacy law changes they brought in didn't touch
- 4:46the exemption so despite the warnings the loophole
- 4:49remains it does and that brings us back to the
- 4:51uap's response the lack of care critique saying
- 4:54it was impracticable to notify people i mean
- 4:57that's just basic cyber security practice 101
- 4:59especially with sensitive data it really highlights
- 5:02gap okay so the uap incident is a stark example
- 5:06But was July just a bad month for them? Or was
- 5:08it indicative of wider issues across Australia?
- 5:11What else was going on? Oh, July was definitely
- 5:14busy. It wasn't just politics. Look at Qantas,
- 5:16a huge incident affecting, what, six million
- 5:19frequent flyer members? Six million? How did
- 5:23that happen? Interestingly, it wasn't a direct
- 5:26hack on Qantas systems. It was fishing over the
- 5:30phone at a third -party call center they use
- 5:33in the Philippines. Ah, the supply chain risk.
- 5:35Exactly. Social engineering. They got names,
- 5:37emails, phone numbers, birthdates, frequent flyer
- 5:40numbers. Groups like Scattered Spider are known
- 5:43for this kind of sophisticated social engineering
- 5:45against call centers. They've hit big names globally.
- 5:48Right. So third parties are a major vulnerability.
- 5:50What else? We saw Metricon Homes, the big builder,
- 5:53get hit by ransomware. The Quine Group claimed
- 5:56responsibility. Ransomware again. What did they
- 5:59lose? About 128 gigs of data, financial records,
- 6:03employee details, even sensitive architectural
- 6:05plans. That's intellectual property theft right
- 6:08there, plus massive disruption. Ouch. And then
- 6:11there was a Northern Territory government agency.
- 6:13They got caught by a business email compromise
- 6:16scam, a BEC attack. The fake invoice scams. Pretty
- 6:20much. Someone was tricked into transferring over
- 6:22$3 .5 million to a fraudulent account. $3 .5
- 6:25million. Did they get it back? Most of it, thankfully.
- 6:28But it shows how effective and costly these BEC
- 6:31scams can be. Still a massive breach of process.
- 6:34So politics, airlines, construction, government.
- 6:38It's hitting everywhere. Absolutely. And that's
- 6:40not all for July. Louis Vuitton had Australian
- 6:42customer data exposed. Ingram microfaced ransomware.
- 6:46There was an accidental breach at the Migration
- 6:48Agents Authority. Even an Adelaide women's health
- 6:51clinic had sensitive patient data stolen. It
- 6:53was relentless. It shows the sheer scale and
- 6:55variety. Yeah. Any stats on ransomware specifically?
- 6:58Seems to keep cropping up. Yeah. The ASD, the
- 7:00Signals Directorate, they responded to 121 ransomware
- 7:04incidents in the last financial year, 23 -24.
- 7:07That was 11 % of all. the incidents they handled.
- 7:0911%. And the OAIC, the privacy watchdog, reported
- 7:12that ransomware was involved in 26%, so over
- 7:15a quarter of all cyber incidents that actually
- 7:18resulted in a notifiable beta breach during that
- 7:20same period. It's a huge part of the problem.
- 7:22And these threats, they aren't just local, are
- 7:25they? What was happening internationally in July
- 7:27that reflects this bigger picture? Right. It's
- 7:29definitely a global issue. We saw, for example,
- 7:32some very sophisticated state -sponsored activity.
- 7:36Groups linked to China called Linen Typhoon and
- 7:38Violet Typhoon were exploiting brand new flaws
- 7:41zero days in Microsoft SharePoint. Zero days.
- 7:44So flaws nobody knew about. Exactly. They hit
- 7:47over 50 organizations worldwide, including governments.
- 7:50Shows that high -level espionage and disruption
- 7:53campaigns are constantly ongoing. That's the
- 7:55high -tech end. Anything simpler. Oh, absolutely.
- 7:58You won't believe this one. McDonald's. AI hiring
- 8:01site got breached, exposed 64 million records.
- 8:0564 million. How sophisticated AI attack. Nope.
- 8:08The admin password was 123456. You're kidding.
- 8:12Wish I was. Just goes to show you can have all
- 8:15the fancy tech in the world, but if you miss
- 8:17the absolute basics, like a strong password.
- 8:20Well, you're wide open. It's almost comical if
- 8:22it weren't so serious. Basic cyber hygiene. It
- 8:24always comes back to that, doesn't it? Yeah.
- 8:26OK, so connecting all this local incidents, global
- 8:28trends, simple mistakes, state actors. How are
- 8:31governments and regulators trying to respond?
- 8:34What's changing on the policy front? Well, we're
- 8:36seeing different approaches globally. The UK,
- 8:39for instance, is proposing a ban on ransomware
- 8:42payments, at least for the public sector and
- 8:44critical infrastructure. A complete ban. Trying
- 8:47to cut off the money supply. That's the idea.
- 8:50Australia has gone a different way, though. We
- 8:51have mandatory reporting of ransomware payments
- 8:54within 72 hours, but no actual ban. Why not ban
- 8:57them here? The main argument is about operational
- 9:00risk. The concern is that banning payments might
- 9:03stop a hospital or a key utility from getting
- 9:06back online quickly, potentially causing even
- 9:09more harm. It's a tricky balance. I see. So reporting,
- 9:13but no ban. What about holding companies accountable
- 9:16before they pay or even before they get hit?
- 9:19That's definitely heating up. ASIC, the corporate
- 9:21regulator here, is getting much more active.
- 9:23They've recently filed charges against Fortnum
- 9:25Private Wealth, alleging they failed to manage
- 9:27cybersecurity risks properly. Charges. That sounds
- 9:30serious. It is. And it's not the first time.
- 9:33It's actually ASIC's third cyber -related court
- 9:35action after cases against RI Advice and FIRG
- 9:39Group. The message is clear. Regulators expect
- 9:42companies to take cybersecurity seriously, and
- 9:45there are consequences if they don't show due
- 9:47diligence. It's about accountability. OK, so
- 9:49regulators are stepping up. The threats are constant.
- 9:52This really brings it home for everyone listening.
- 9:55Given everything we've discussed, what are the
- 9:57key lessons? What practical things can people
- 9:59and businesses actually do? Right. Let's get
- 10:02practical. Based on these incidents, especially
- 10:04Qantas, number one has to be review your third
- 10:07party cyber risk. Seriously, scrutinize your
- 10:10suppliers, partners, anyone who touches your
- 10:12data or systems, especially call centers. Don't
- 10:15just trust. Verify. Absolutely. Train their staff,
- 10:18too, if possible, on social engineering. Demand
- 10:21strong identity checks. Your security is only
- 10:24as strong as your weakest link, and often that
- 10:26link is external. Okay. Third -party risk. What
- 10:29else? Second, threat hunting and patching. Don't
- 10:32just wait for alarms. Actively look for signs
- 10:34of trouble in your systems. And patch, patch,
- 10:37patch, especially known exploited vulnerabilities
- 10:40like those SharePoint ones. Patching quickly
- 10:42is critical. Don't leave the door open. Be proactive,
- 10:45not just reactive. And the third. Third, really
- 10:48double down on combating business email compromise,
- 10:52BEC. That NT government scam is a perfect, painful
- 10:56reminder. Training is key. Help your staff spot
- 10:59those fake, urgent emails. But critically, turn
- 11:03on multi -factor authentication MFA. That extra
- 11:06code, that app approval, make it mandatory, especially
- 11:09for financial transactions or sensitive access.
- 11:11MFA everywhere. Everywhere possible. And one
- 11:13more thing for BEC. Check your domain name renewals.
- 11:16Make sure they're set to auto -renew. Attackers
- 11:18sometimes hijack expired domains to send convincing
- 11:21fake emails. It's a simple thing, but it closes
- 11:23another door. Right. Review third parties, hunt
- 11:26threats and patch fasts, and fight BEC with training,
- 11:29MFA, and domain checks. Seems like solid advice.
- 11:32They're foundational steps, really. Covering
- 11:34the basics goes a long, long way. It really makes
- 11:36you think, though. In this era where everything's
- 11:39connected, even our political views seem up for
- 11:41grabs. How much of our data are we just handing
- 11:43over? Without a second thought. And who should
- 11:46really be responsible for protecting it? What
- 11:49level of care do we expect? That's the fundamental
- 11:51question we all need to grapple with, isn't it?
- 11:53What does true digital stewardship look like
- 11:56in the 21st century? Definitely something to
- 11:59mull over. Well, that's all the time we have
- 12:01for this discussion on Tech Talks with Ken Soft.
- 12:03Thanks so much for tuning in. Yeah, thanks for
- 12:05listening. Remember, staying informed and proactive
- 12:08is genuinely your best defense in cybersecurity.
- 12:11It's vital for everyone. Absolutely. And if these
- 12:13issues have you thinking about your own security
- 12:15or IT setup, feel free to reach out. You can
- 12:18visit us at www .kinsoft .com .au to discuss
- 12:22your needs.