Latest / Tech Talks With Kinsoft / How many VETtrak customers were affected by the October cyberattack?
Transcript
- 0:00Hello and welcome to Tech Talks with Kinsoft.
- 0:02It's great to have you with us. Great to be here.
- 0:04Today we're going to strip back the headlines
- 0:06a bit and look at the operational reality of
- 0:09running a business in a digital world. We spend
- 0:12so much time talking about tech as this magical
- 0:14enabler. The thing that speeds you up connects
- 0:17you to everyone. Exactly. But today we need to
- 0:21look at the flip side. What happens when the
- 0:23tech just stops you dead in your tracks? It's
- 0:26the side of the coin we all hope to avoid, but...
- 0:29Statistically, it's the one we're most likely
- 0:31to encounter at some point. We aren't talking
- 0:33shiny new gadgets today. We're looking at that
- 0:36that stomach dropping moment when the screen
- 0:39goes dark, the data vanishes and suddenly the
- 0:41clock is ticking on your legal obligations. Precisely.
- 0:45And usually when we talk about cyber incidents,
- 0:47it's always the big one. Right. You know, state
- 0:49sponsored actors, global banks. It feels like
- 0:52a movie. A bit abstract. Yeah, a bit abstract.
- 0:54So I wanted to shift the lens today. We've got
- 0:57a stack of sources here about a really significant
- 0:59incident from late 2025 involving a company called
- 1:03ReadyTech and their platform V -Track. And this
- 1:06is such a crucial case study because V -Track,
- 1:08I mean, it's not some abstract cloud thing. It
- 1:10is the engine room for a massive chunk of Australia's
- 1:13vocational education and training sector. Right.
- 1:16If you've done a TAFI course, a certificate,
- 1:18any kind of trade up skilling in Australia. there
- 1:22is a very, very high chance your data has passed
- 1:25through this system. So our mission today is
- 1:28to use this specific incident, the VT track breach,
- 1:30as a kind of a live autopsy. We're going to break
- 1:34down the timeline of a supply chain attack to
- 1:36see how it actually unfolds day by day. But then,
- 1:39and this is the important part, we need to answer
- 1:40the so what question. We're going to pivot to
- 1:42the Australian regulatory landscape, specifically
- 1:44the Notifiable Data Breaches Scheme, or NDB.
- 1:47Because when things go wrong, The law has a very
- 1:51specific script you have to follow. There's not
- 1:53a free -for -all. Not at all. There is a playbook,
- 1:55and if you don't follow that script, the consequences,
- 1:58legal, financial, reputational, can actually
- 2:01be worse than the hack itself. Okay, so let's
- 2:04start with the anatomy of the breach itself.
- 2:06I was reading through the timeline, and what
- 2:08really struck me was that fog -of -war phase
- 2:11at the beginning. We think a hack is instant,
- 2:14you know, skull and crossbones on the screen.
- 2:16But it's almost never like that. This began on
- 2:19October 16th, 2025. VT -Track customers experienced
- 2:23what was just labeled an outage. An outage. And
- 2:27for anyone in IT, outage is such a loaded word.
- 2:30It covers a multitude of sins. It could be a
- 2:32failed router, or it could mean someone is, you
- 2:35know, actively encrypting your entire database.
- 2:37And that ambiguity, it lasted for a painfully
- 2:40long time. It wasn't until November 3rd, that's
- 2:42over two weeks later, that ReadyTech confirmed
- 2:44it was a cyber attack. That gap must have been
- 2:46just excruciating for their customers, the training
- 2:49colleges, the organizations. They're flying blind.
- 2:51Totally flying blind. You can't tell your students
- 2:54what's happening because you don't even know.
- 2:56But while everyone was waiting in that limbo,
- 2:59things were escalating behind the scenes. The
- 3:02sources say that on October 31st, Halloween,
- 3:05at 9 p .m. AEDT, the threat actors stopped playing
- 3:09games. That's the escalation point. They published
- 3:1213 ,866 files on the dark web. And that's the
- 3:16pivot. Right. We move from a business continuity
- 3:20problem software not working to a full -blown
- 3:23privacy crisis. Precisely. And we need to look
- 3:26at the collateral damage here. ReadyTech identified
- 3:28that 23 specific customers were caught up in
- 3:31that data dump. Now, seeing that number, 23,
- 3:34my first reaction was, only 23? That seems low.
- 3:37We're so used to hearing about millions of accounts.
- 3:39It does sound low, yeah, especially compared
- 3:41to the massive user base of VT -TRAC. They estimated
- 3:44fewer than 3 ,000 individuals were affected.
- 3:46But, and this is so important, in data breaches,
- 3:49we have to stop looking at the volume and start
- 3:50looking at the value. The toxicity of the data.
- 3:52The toxicity, the sensitivity. You have to look
- 3:54at what was actually lost. And one of the victims
- 3:57profiled in the reports really brings this home.
- 4:01Vecho. The Victorian Aboriginal Community Controlled
- 4:04Health Organization. This isn't just a marketing
- 4:07list of email addresses we're talking about.
- 4:09It's student records for Aboriginal health workers.
- 4:12That changes the entire calculation. The sources
- 4:15list Medicare numbers, identity documents, driver's
- 4:19licenses. That's the holy trinity for identity
- 4:21theft. It really is. If you lose that data, you're
- 4:24not just changing a password. You are monitoring
- 4:26your credit report for the next five years. And
- 4:28think about the trust dynamic there. organization.
- 4:32Their students trust them with their entire lives,
- 4:35their careers. The impact of having to tell those
- 4:38students, we lost your ID, is just, it's devastating.
- 4:41It's a huge breach of trust. They had to advise
- 4:44students to contact ID Care, which is the National
- 4:46Support Service for Identity Theft, and verify
- 4:49all their identity documents. It just disrupts
- 4:51that foundational trust. It really does. Now,
- 4:54there's a fascinating legal maneuver in this
- 4:56timeline that I think is worth unpacking. On
- 4:59October 29th, ReadyTech went to the NSW Supreme
- 5:02Court and got an injunction. Right. Basically
- 5:04a court order. Yeah. A court order prohibiting
- 5:07access to or dissemination of the stolen data.
- 5:10Yeah. Now, I have to play devil's advocate here.
- 5:13We're talking about the dark web. It's run by
- 5:15international criminal syndicates who, by definition,
- 5:19do not care about the Supreme Court of New South
- 5:21Wales. So is an injunction just an expensive
- 5:23piece of paper? Does it actually do anything?
- 5:26It's a valid skepticism. And technically, you're
- 5:29right. The hackers aren't going to take the files
- 5:30down because a judge said so. They're beyond
- 5:32the jurisdiction. So what's the point? Strategically,
- 5:35it's actually a very smart move for containing
- 5:38the damage on the surface web. Ah, so it targets
- 5:41the onlookers. Yeah. The people who might share
- 5:43it on Twitter or Reddit. Exactly. It makes it
- 5:46illegal for journalists, for curious onlookers
- 5:49or other bad actors to download or share that
- 5:52data. It puts a big do not enter sign around
- 5:55the toxic spill. It doesn't clean it up, but
- 5:58it stops the average person from walking through
- 6:00it and spreading it further. That's a helpful
- 6:02distinction. It limits the blast radius. Now,
- 6:05before we terrify everyone listening who uses
- 6:07cloud software, there is an important nuance
- 6:09here regarding a group called Signature Training
- 6:12College. Right. also VT track users. But they
- 6:16came out with a very clear statement confirming
- 6:18they were not among the 23 affected customers.
- 6:21Which highlights a key part of modern cloud architecture
- 6:24that business owners really need to get their
- 6:26heads around. It's rarely one giant bucket. Right.
- 6:29Just because the platform takes a hit doesn't
- 6:31mean every single tenant, every customer is compromised.
- 6:34It depends on which server your instance was
- 6:36on, which database was accessed. It shows the
- 6:39importance of compartmentalization. But for the
- 6:4123 who were hit. the reality shifted immediately
- 6:44from tech problem to legal problem. And that
- 6:48brings us to the core of our discussion today,
- 6:50the so what moment. When an organization like
- 6:53Vatchogo realizes their data is out there, they
- 6:56can't just fix the firewall and hope nobody notices.
- 7:00No, we operate under a very strict regime here
- 7:03in Australia. The Notifiable Data Breaches Scheme,
- 7:05or NDB, it's part of the Privacy Act, 1988, and
- 7:09when it came in, it fundamentally changed the
- 7:11game. Before the NDB, companies could, and look,
- 7:15they often did, sweep things under the rug. To
- 7:18save face. To save face. Now, that silence is
- 7:21illegal. But I think there's still confusion
- 7:23about the threshold. I mean, if I leave a USB
- 7:26stick with some marketing brochures on the bus,
- 7:28surely I don't have to report that to the government.
- 7:30That seems excessive. You're right, there is
- 7:33a threshold. It's not just any data loss. According
- 7:35to the guidance we have from Invotech, there
- 7:37are three specific triggers that must all be
- 7:39met to force a notification. Okay, walk us through
- 7:41them. What's trigger number one? First, there
- 7:43has to be unauthorized access, disclosure, or
- 7:46loss of personal information. That's the event
- 7:48itself. The hack, the lost laptop, the email
- 7:51sent to the wrong person. Okay, standard. Trigger
- 7:54two. Second, and this is the subjective part
- 7:57that trips people up. A reasonable person would
- 8:00conclude that this is likely to result in serious
- 8:02harm to the individuals involved. OK, I want
- 8:05to pin down serious harm because I feel like
- 8:07a lot of executives hear that and just think
- 8:09financial loss. They think, well, no one's bank
- 8:12account was drained, so it's not serious. That
- 8:14is a very dangerous misconception. The definition
- 8:17of serious harm in the Privacy Act is much, much
- 8:21broader than your bank balance. Yes, it includes
- 8:23financial fraud, of course, but it also includes
- 8:26things like physical harm. A stalker getting
- 8:29a home address. Exactly. It includes reputational
- 8:32damage. That's a huge one. If a medical status
- 8:35or workplace dispute record gets leaked, that
- 8:37could ruin a career. Absolutely. And it also
- 8:40includes emotional distress. If a breach causes
- 8:43significant anxiety, which having your Medicare
- 8:45number stolen definitely does, that counts as
- 8:47serious harm. So the bar for harm is actually
- 8:49quite low. Okay, and the third trigger? The third
- 8:52is the get -out -of -jail -free card, in a way.
- 8:55Notification is only required if the entity has
- 8:58been unable to prevent the likely risk of serious
- 9:00harm through remedial action. So, going back
- 9:03to my USB stick example, if I realize I lost
- 9:06it... But I use a remote management tool to wipe
- 9:09it before anyone can plug it in. Then you have
- 9:11prevented the risk of harm. The data is gone,
- 9:14but the risk is neutralized. No harm, no notification.
- 9:18That's why having remote wipe capabilities isn't
- 9:20just a tech feature. It's a compliance shield.
- 9:22That makes perfect sense. Now, who are we talking
- 9:25about here? Is this just for the big banks and
- 9:27telcos? The general rule is any business with
- 9:30an annual turnover of more than $3 million. So
- 9:33your local cafe is probably exempt? But wait,
- 9:36Vichichow is a nonprofit and a lot of training
- 9:38colleges aren't massive corporations. So why
- 9:41were they on the hook in this Vichachrek incident?
- 9:43Because there are critical exceptions. Regardless
- 9:46of your revenue, if you are a health care provider
- 9:48or an educational institution, you must comply.
- 9:51So if you hold the data, you hold the liability.
- 9:54Correct. The government decides that health and
- 9:56student records are just too sensitive to be
- 9:58unregulated. It also applies to anyone handling
- 10:02tax file numbers. So basically... If you employ
- 10:05staff in Australia, you're almost certainly caught
- 10:08in this net. OK, so we've established the triggers.
- 10:11Now I want to put our listener in the hot seat.
- 10:13Imagine it's Tuesday morning. You get an email
- 10:16from your IT manager or maybe a ransom note just
- 10:18pops up on your screen. You've been breached.
- 10:21Panic sets in. What do you actually do? The first
- 10:24thing to do is suppress the urge to just scream.
- 10:27You need to follow the four -step process from
- 10:29the scheme. And step one is purely operational.
- 10:32Contain the breach. Stop the bleeding. Immediately.
- 10:35This isn't about finding out who did it yet.
- 10:36That comes later. This is about shutting down
- 10:38compromised accounts, disconnecting infected
- 10:40servers, changing master passwords. You have
- 10:43to make sure the data loss stops now. Okay. The
- 10:45bleeding is stopped. The server is offline. What's
- 10:48step two? Assessment. And this is where the clock
- 10:51starts ticking. You have a strict 30 -day window
- 10:53to investigate. You need to review logs, interview
- 10:56staff, maybe bring in forensic experts. You are
- 10:59trying to answer one question. Is serious harm
- 11:02likely? 30 days sounds like a long time. But
- 11:06I imagine in a crisis with lawyers and PR teams
- 11:09all involved, that time, just... It evaporates.
- 11:14It vanishes. Especially if your logs are messy
- 11:17or non -existent. If you can't prove what wasn't
- 11:19taken, you often have to assume the worst. So
- 11:21let's say the assessment comes back bad. Harm
- 11:23is likely. Step three. Notification. You have
- 11:27to notify the individuals who are affected. And
- 11:29this is crucial. The guidelines are very specific
- 11:31and must be in plain English. So no hiding behind
- 11:33legal jargon. No unforeseen anomaly in the subnet.
- 11:37No. You have to be transparent. Tell them what
- 11:39information was compromised and, most importantly,
- 11:42what steps they should take to protect themselves.
- 11:44Look at Vic Cho again. They didn't just say,
- 11:45oops. They gave actionable advice. Contact ID
- 11:49care. Watch for these scams. It empowers the
- 11:51victim, which is the whole point. And finally,
- 11:53step four. You have to tell the regulator. You
- 11:56submit a form to the OAIC, the Office of the
- 11:59Australian Information Commissioner. and your
- 12:01story to them has to match your story to your
- 12:04customers. Now, I have to ask the cynical question
- 12:06that I'm sure some business owners are thinking.
- 12:08What if I just don't? What if I roll the dice,
- 12:10hide it, and hope it never comes out? That is
- 12:14a high -stakes gamble with very, very poor odds.
- 12:18If you're caught covering up, the OAIC has teeth.
- 12:21They can issue public reprimands, which are humiliating.
- 12:25They can issue compensation orders and they can
- 12:28pursue civil penalties of up to two point five
- 12:30million dollars. Two and a half million dollars.
- 12:32That's a serious hit to the bottom line for almost
- 12:35any business. It is. But honestly, most experts
- 12:38agree the fine is the lesser evil. The real cost
- 12:40is your reputation. Your trust deficit. Exactly.
- 12:43Customers, they understand that cybercrime happens.
- 12:46It's a fact of life in 2026. They might forgive
- 12:48you for getting hacked. They will very rarely
- 12:51forgive you for lying about it. Right. If you
- 12:53hide it and it leaks later and on the dark web,
- 12:55things always leak eventually. Your credibility
- 12:58is just destroyed. Transparency beats cover -ups
- 13:01every time. OK, so we've covered the horror story
- 13:05of the breach and we've covered the legal rulebook.
- 13:07Let's talk about how to stop this from becoming
- 13:09our reality. Let's talk prevention. Prevention
- 13:12is always, always cheaper than remediation. The
- 13:16InvoTech guide breaks this down into two main
- 13:18pillars, the human factor and the tech essentials.
- 13:22Let's start with the humans, because as much
- 13:24as we love technology, we are usually the problem,
- 13:27aren't we? Unfortunately, yes. Look, sophisticated
- 13:29code is dangerous, but simple human error is
- 13:33often the open door. Someone reusing their Netflix
- 13:36password on their work email. Someone clicking
- 13:38a phishing link because they were in a rush.
- 13:40So what's the fix? Is it just telling people
- 13:42don't do that? It's continuous training. It can't
- 13:45be a boring video once a year that everyone just
- 13:48skips through. It has to be regular. Yeah. Phishing
- 13:50simulations, password hygiene checks. You have
- 13:53to build a security culture where staff aren't
- 13:55afraid to report a mistake. That's a great point.
- 13:57If someone clicks a link, you want them to call
- 13:59IT immediately, not hide it because they're afraid
- 14:02of getting in trouble. Make it. safe to fail
- 14:04so you can fix it fast. And on the tech side,
- 14:08I feel like we shout this from the rooftops every
- 14:10week, but let's say it again for the people in
- 14:12the back. Multi -factor authentication, MFA.
- 14:16You do not have MFA turned on for your critical
- 14:19systems. You are, frankly, being negligent at
- 14:22this point. It stops the vast majority of these
- 14:25attacks. It's the seatbelt of the internet. Just
- 14:27click it, takes two seconds. Exactly. Beyond
- 14:30that, it's the unglamorous stuff. Patching your
- 14:32software. Those annoying update tonight prompts.
- 14:35They often contain critical security fixes. If
- 14:38you delay the update, you're leaving the door
- 14:40wide open for hackers. There's one more recommendation
- 14:43in here that I think is the most overlooked but
- 14:45possibly the most valuable. The incident response
- 14:47plan. This is the difference between a crisis
- 14:50and a disaster. You do not want to be making
- 14:52decisions when your hair is on fire. You need
- 14:55a document written now that outlines exactly
- 14:57who does what. Like a fire drill for data. Precisely.
- 15:01Who calls the lawyers? Who has the authority
- 15:03to shut down the e -commerce store? Who drafts
- 15:05the press release? You need these roles defined,
- 15:08and you need to test it. Do a tabletop exercise
- 15:10once a year. Sit around a table and simulate
- 15:13a VT track style breach. Okay, the server's down.
- 15:15What do we do? See if your team actually knows.
- 15:17That is such solid advice. Because when the panic
- 15:20hits, your IQ drops about 20 points. You want
- 15:24to be following a checklist, not improvising.
- 15:26Precisely. Improvisation is great for jazz, terrible
- 15:28for cybersecurity. We have covered a massive
- 15:31amount of ground today. We started with the VDTRAKE
- 15:33incident, seeing how a silent outage morphed
- 15:36into a dark web data dump affecting vulnerable
- 15:38students. We saw how that triggered the legal
- 15:41machinery of the NDB scheme, forcing organizations
- 15:43like VACHO to notify and protect their people.
- 15:46We unpacked that 30 -day ticking clock contain,
- 15:49assess, notify, report, and we... emphasize that
- 15:53serious harm isn't just about bank accounts.
- 15:55It's about reputation and mental well -being.
- 15:59And finally, the pivot to prevention. Train your
- 16:01humans, update your tech, and please, for the
- 16:04love of God, have a plan written down. So I want
- 16:06to leave our listeners with a final thought.
- 16:08We've talked about that sinking feeling when
- 16:10you realize you've been breached, the oh -no
- 16:13moment. It's the moment you realize your business
- 16:15is no longer under your control. If that happened
- 16:18to you in the next hour, if you got that call
- 16:20right now, Would you know who to call? Would
- 16:23your team know which server to isolate? Or would
- 16:26you be sitting there Googling what to do during
- 16:29a data breach? That is the question that should
- 16:31keep directors awake at night. If the answer
- 16:33is, I'd be Googling it, you are already behind
- 16:36the curve. You certainly are. But look, if you're
- 16:39listening to this and thinking, I don't have
- 16:40a plan, or I'm not sure if my backup strategy
- 16:43is actually compliant, you really don't have
- 16:45to figure it out alone in the dark. No, that's
- 16:48what experts are for. Security is complex, but
- 16:51getting good advice is simple. That's why we
- 16:53strongly suggest you head over to www .kinsoft
- 16:57.com .au. Whether you need to audit your security
- 17:00setup, discuss your IT needs, or just want to
- 17:02make sure you're prepared for exactly these kinds
- 17:05of scenarios, they are the team to talk to. Absolutely.
- 17:08Don't wait for the breach to meet your IT partner.
- 17:11Go to www .kinsoft .com .au and get on the front
- 17:15foot. Thank you so much for joining us on this
- 17:17exploration of the VET track incident and the
- 17:20NDB landscape. It's been a heavy topic, but an
- 17:23essential one. Always a pleasure. Stay safe and
- 17:25keep those passwords strong. We'll catch you
- 17:27next time on Tech Talks with Kinsoft. Bye for
- 17:28now.