Latest / Tech Talks With Kinsoft / Energy Action Breach – SafePay Ransomware Targets an Energy Giant
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. I want you
- 0:02to think for a second about... The kinds of businesses
- 0:06that operate almost entirely in the background.
- 0:09Right. The ones without the flashy consumer commercials.
- 0:11Exactly. I mean, they don't sell retail products,
- 0:14but they work quietly behind the scenes to save
- 0:16other businesses money or, you know, optimize
- 0:19their operations. And those exact companies,
- 0:22the ones meant to be these quiet custodians of
- 0:24corporate efficiency, they are increasingly finding
- 0:27themselves staring down the barrel of massive
- 0:30digital extortion attempts. Yeah. Which brings
- 0:32us to today's analysis. Right now, one of those
- 0:35exact background custodians, an Australian energy
- 0:38management firm called Energy Action, is caught
- 0:41in a developing cyber incident. Right. With a
- 0:44highly sophisticated ransomware group known as
- 0:46SafePay. And it highlights one of the most critical
- 0:48vulnerabilities in our modern digital landscape.
- 0:51I mean, the more interconnected and vital a B2B
- 0:54service becomes to its clients, the larger the
- 0:57bullseye on its back. Definitely. And the information
- 1:00we are analyzing today comes from a recent exclusive
- 1:02report by Daniel Croft at Cyber Daily. And it
- 1:06provides a pretty stark look at how these threats
- 1:09are evolving. So mapping out the immediate situation
- 1:11based on Croft's reporting from early May 2026,
- 1:15energy action actually appeared on the dark web
- 1:18leak site belonging to the SafePay ransomware
- 1:21gang. Right. And to understand the stakes here,
- 1:24we really have to look at what Energy Action
- 1:25actually does. I mean, they aren't a power plant.
- 1:28No, they're a consulting firm. Right. Their mandate
- 1:30is to highlight energy usage inefficiencies for
- 1:33other businesses, you know, helping companies
- 1:35avoid what they term bill shock. And guiding
- 1:38them toward net zero emissions, which is actually
- 1:41a benchmark the company's already achieved internally.
- 1:44Oh, wow. So they actually practice what they
- 1:45preach. Exactly. They function essentially as
- 1:48an optimization engine for corporate Australia's
- 1:50energy consumption. I mean, they manage a very
- 1:53significant share of the country's commercial
- 1:55business energy spend. But before we examine
- 2:00the broader implications, we really need to underscore
- 2:02that these claims are currently alleged. Yes,
- 2:05that is a very important distinction to make.
- 2:07Because the timing and the confirmation are both
- 2:09critical factors here. At the time Cyber Daily
- 2:13published their report, SafePay hadn't actually
- 2:15disclosed specific details of the incident. No,
- 2:18and they hadn't confirmed the actual volume of
- 2:21data they claimed to possess either. Right. Instead,
- 2:23they just initiated a countdown. They threatened
- 2:26to leak the alleged... stolen data in just over
- 2:29two days from the article's publication. And
- 2:31at that exact moment, Energy Action had not publicly
- 2:34disclosed any incident and Cyber Daily was just
- 2:37waiting on a formal response. Which creates this
- 2:40really volatile holding pattern. It does. Threat
- 2:43actors frequently use that ticking clock on a
- 2:46public leak site to force a victim's hand. Just
- 2:48dialing up the pressure. Exactly. They operate
- 2:51on the assumption that public pressure and, you
- 2:54know, the fear of the unknown will expedite a
- 2:56ransom payment. Wait, I'm trying to score the
- 2:59target with the threat here, though. If energy
- 3:01action's primary function is just managing power
- 3:03usage to prevent corporate bill shock, why is
- 3:07a highly organized ransomware group wasting their
- 3:09time on them? I mean, utility blueprints and
- 3:12efficiency metrics don't exactly sound like the
- 3:15kind of high -dollar corporate secrets that trigger
- 3:17massive payouts. Well, on the surface, an energy
- 3:20bill doesn't really sound like a goldmine. But
- 3:23the value to the attacker isn't in a single company's
- 3:26energy usage. Where is it, then? The value lies
- 3:29entirely in the aggregation. You have to think
- 3:32of a consulting firm not as a single target,
- 3:34but as the central nervous system for hundreds
- 3:37of other businesses. Ah, so by compromising the
- 3:40consultancy, they are accessing the shared circulatory
- 3:42system of all their corporate clients. Precisely.
- 3:45If a threat actor breaches a single retail store,
- 3:48they acquire that one store's data. But if they
- 3:52breach a management firm that services hundreds
- 3:53of diverse businesses. They get everything. Right.
- 3:56they potentially gain access to a staggering
- 3:59trove of aggregated corporate intelligence. We
- 4:02are talking about highly sensitive procurement
- 4:04records, detailed energy account data, and vast
- 4:09cross -industry directories of corporate contacts.
- 4:12Which drastically changes the leverage. Absolutely.
- 4:15Because the attackers aren't just holding Energy
- 4:17Action's internal memos hostage, they are threatening
- 4:19to expose the sensitive operational data of every
- 4:22single company that trusted Energy Action with
- 4:25their business. And that threat is existential
- 4:27for a B2B service provider. The reputational
- 4:30damage for a consultancy that fails to protect
- 4:33client data is, well, it's often catastrophic.
- 4:36Yeah. And the attackers obviously know that.
- 4:39Oh, they are acutely aware that these firms are
- 4:41under immense pressure from their own clients
- 4:43to resolve breaches quietly and quickly. So they
- 4:46just calculate their ransom demands based on
- 4:48that cascading pressure. Exactly. They're basically
- 4:50monetizing the target's foundation of trust.
- 4:53Man. To really grasp the severity of this alleged
- 4:56threat, though, we have to look closely at the
- 4:58group making the claims. Right. SafePay is a
- 5:01relatively new name in the broader timeline of
- 5:03cybercrime, but they have escalated their operations
- 5:06at a terrifying speed. Yeah, they have. According
- 5:09to the reporting, they first emerged in October
- 5:112024. And in roughly a year and a half, they
- 5:14have claimed more than 450 victims. Which is
- 5:17an incredible volume. Claiming 450 victims in
- 5:20an 18 month window requires an immense, highly
- 5:23sophisticated operational infrastructure. Yeah,
- 5:25that is not the work of a few rogue hackers in
- 5:28a basement. No, it is the footprint of a major
- 5:30digital enterprise. And their geographic reach
- 5:33confirms that enterprise scale. I mean, they've
- 5:36targeted organizations in Australia, the UK,
- 5:38the US, Italy, New Zealand, Canada, Belgium,
- 5:42Brazil, Germany. Barbados, Argentina. It is a
- 5:46completely global dragnet. But the detail that
- 5:48truly separates SafePay from the rest of the
- 5:50pack is their business model. Yes, this is the
- 5:53really fascinating part. They explicitly state
- 5:55on their dark web leak site, and this is a direct
- 5:57quote, SafePay ransomware has never provided
- 6:00and does not provide the Reyes. And that public
- 6:03declaration is incredibly significant. In the
- 6:05current cybercrime ecosystem, almost everyone
- 6:08operates on the Reyes model. Right. And for anyone
- 6:11listening who isn't entrenched in threat intelligence,
- 6:13Reyes stands for ransomware as a service. Right.
- 6:17It operates remarkably similarly to franchising
- 6:20a fast food chain. You have top tier developers
- 6:23who sit at the top of the pyramid. They write
- 6:25the complex malicious code, the actual encryption
- 6:27software, and they maintain the extortion leak
- 6:31sites. But they don't actually break into companies
- 6:33themselves. No, they rent their software out
- 6:36to affiliates. And these affiliates are essentially
- 6:38independent contractors who do the dirty work
- 6:41of fishing employees, bypassing firewalls, and
- 6:45deploying the locker. And when a ransom is paid,
- 6:48the affiliate and the developer just split the
- 6:50profits. Exactly. It is an incredibly successful
- 6:53model because it allows for rapid scaling. The
- 6:56developers avoid the operational risk of network
- 6:59intrusion. And the affiliates don't need the
- 7:01advanced coding skills required to build unbreakable
- 7:04encryption algorithms. They just buy the toolkit
- 7:06and start hunting. But let me push back a bit
- 7:08here. OK, sure. If you or I are sitting at a
- 7:10compromised corporate terminal staring at a red
- 7:13screen demanding cryptocurrency, does it actually
- 7:16matter to us how the criminals organize their
- 7:18HR department? I mean, the files are locked,
- 7:21whether the attacker is an independent affiliate
- 7:23or a salaried employee of the syndicate. Well.
- 7:27From the perspective of the immediate panic,
- 7:29you were absolutely right. The operational disruption
- 7:31feels identical. Right. However, from the perspective
- 7:35of incident response, defense strategy, and negotiation,
- 7:39the distinction between a decentralized Reyes
- 7:43affiliate and a centralized in -house cartel
- 7:46changes everything. Walk us through the mechanics
- 7:49of that. Why does an in -house operation change
- 7:51the defensive playbook? Because Reyes networks,
- 7:54by their very nature, are chaotic. Affiliates
- 7:57have wildly varying levels of skill. You might
- 8:00have a highly sophisticated initial access broker
- 8:02who breaches a network flawlessly, but they hand
- 8:05the access over to an inexperienced affiliate
- 8:07who makes incredibly noisy mistakes. Like what
- 8:09kind of mistakes? Well, they might use off -the
- 8:11-shelf tools that trigger security alerts, or
- 8:14they might fail to cover their tracks, you know,
- 8:17leaving forensic footprints that allow incident
- 8:20responders to figure out exactly how they got
- 8:22in. And then they just close the door. Exactly.
- 8:25So an affiliate model is inherently messier.
- 8:27You have multiple independent actors touching
- 8:30the network, which just increases the surface
- 8:33area for errors. Right. And in addition to the
- 8:35technical errors, the Ray S model introduces
- 8:38immense friction during the negotiation phase.
- 8:41Oh, really? How so? Sometimes an affiliate will
- 8:44successfully extort a company, receive the multi
- 8:47-million dollar payout, and then simply vanish
- 8:50without providing the decryption key. Oh, wow.
- 8:53Or... The affiliate wants to decrypt your files,
- 8:55but the developer's Tor infrastructure gets taken
- 8:57offline by law enforcement, making the decryption
- 9:00tool completely unavailable. So the victim is
- 9:03left entirely helpless even after complying.
- 9:06Yes. That actually makes the in -house claim
- 9:08by SafePay much more intimidating, but paradoxically
- 9:12maybe more reliable. Yes. Reliable is the perfect
- 9:14word for it. Because if they handle everything
- 9:16from the initial breach to the malware development
- 9:18to the negotiation, they control the entire lifecycle
- 9:22of the attack. That is the crucial takeaway.
- 9:24Centralized groups are highly consistent. Because
- 9:28the same internal teams are conducting the breaches,
- 9:30their tactics, techniques, and procedures, their
- 9:33TTPs remain uniform across different attacks.
- 9:36Which means threat intelligence teams can build
- 9:39much more accurate behavioral profiles. Exactly.
- 9:42We know the specific tools they prefer, the types
- 9:45of vulnerabilities they exploit, and how they
- 9:47move laterally through a network. And I guess
- 9:49it also means they have absolute control over
- 9:51their brand reputation on the dark web. Absolutely.
- 9:54Extortion relies entirely on trust. You know,
- 9:57the perverse trust that if a victim pays, the
- 10:00criminal will honor the deal. And in -house syndicate
- 10:03like SafePay relies on future victims believing
- 10:05that paying actually works. Yeah. If they get
- 10:08a reputation for taking the money and refusing
- 10:10to decrypt files, their leverage in future negotiations
- 10:13evaporates instantly. Makes total sense. So when
- 10:16an incident response firm negotiates with a centralized
- 10:19group, they operate with a higher degree of confidence
- 10:22that they are dealing with the actual decision
- 10:25makers who have the power. power to return the
- 10:27data. OK, understanding that SafePay operates
- 10:30as this cohesive, disciplined unit makes their
- 10:33targeting strategy even more perplexing when
- 10:36we look at their past victims. It does seem a
- 10:38bit contradictory at first. Yeah, because Croft's
- 10:41article details a few recent breaches that highlight
- 10:43their operational history. In February 2026,
- 10:46they hit Genealogy Essay. Right, a South Australia
- 10:49-based genealogy nonprofit. dedicated to historical
- 10:53family records and the timeline of that specific
- 10:55incident provides a really great look into how
- 10:58these attacks unfold over time. It definitely
- 11:00does. According to the organization's public
- 11:02statements, they detected the incident, immediately
- 11:05engaged cybersecurity experts, successfully contained
- 11:08the breach on their network, and proactively
- 11:10communicated with their members. From a crisis
- 11:12management perspective, they followed the playbook.
- 11:15They did. And yet, months later, on April 16th,
- 11:18SafePay listed them on their leak site and ultimately
- 11:21published the data. And this illustrates the
- 11:23concept of dwell time. and the separation of
- 11:26exfiltration from encryption. Which means what
- 11:29exactly? In modern extortion, the deployment
- 11:32of the ransomware, you know, the moment the screens
- 11:34turn red and the files lock, is actually the
- 11:37final stage of the attack. Oh, so by the time
- 11:39you know you are under attack, the worst part
- 11:41has already happened. Right. Long before the
- 11:44ransomware is detonated, the attackers have been
- 11:47quietly navigating the network, finding the sensitive
- 11:49file shares, and slowly siphoning that data out
- 11:53to their own servers. So Genealogy SA contained
- 11:56the active threat and stopped the operational
- 11:58disruption, but the data had already left the
- 12:01building. Exactly. And the variety of the data
- 12:03SafePay dumped from that nonprofit is staggering.
- 12:07Yeah, it included business, financial, and insurance
- 12:09documents. It included historic genealogical
- 12:12data and personal details found in correspondence.
- 12:15They even uploaded internal organizational templates
- 12:17and generic labels. Which is just so weird. Generic
- 12:20labels. Well, the inclusion of internal templates
- 12:22suggests they aren't executing surgical, highly
- 12:25targeted data thefts. So they aren't just looking
- 12:28for the high -value stuff. No, they are establishing
- 12:30persistence in the network. finding the primary
- 12:32file servers, and executing a mass exfiltration.
- 12:36They copy the entire directory tree, mundane
- 12:39administrative templates and all, because it
- 12:42is faster and requires less manual sorting while
- 12:45they are inside the victim's environment. Wow.
- 12:47They just take everything that isn't nailed down.
- 12:50Pretty much. Now contrast Genealogy SA with another
- 12:53safe pay victim from July 2025, Ingram Micro.
- 12:57We are talking about an absolute behemoth of
- 13:00a global IT distributor. Right. The fallout there
- 13:03resulted in the compromise of personally identifiable
- 13:07information for more than 42 ,000 individuals.
- 13:10You are looking at two organizations that share
- 13:12absolutely zero structural, financial, or operational
- 13:15similarities. And this is where I struggle to
- 13:17see the strategy. You have Ingram Micro, a multi
- 13:20-billion dollar tech giant. You have Genealogy
- 13:23SA, a regional nonprofit tracking family trees.
- 13:25And now we have Ener - action a corporate energy
- 13:28consultancy how does a highly disciplined in
- 13:31-house cyber syndicate justify deploying their
- 13:34centralized resources against such a random assortment
- 13:37of targets it feels completely scattershot it
- 13:40appears completely random if we assume threat
- 13:42actors operate like traditional bank robbers
- 13:44who carefully select a high value target exactly
- 13:47and then spend weeks figuring out how to break
- 13:49that specific vault but in the digital realm
- 13:52The logic is inverted. This is the reality of
- 13:55opportunistic exploitation. Meaning they aren't
- 13:58picking the target. They are picking the vulnerability.
- 14:01Precisely. They do not decide to attack a genealogy
- 14:04nonprofit. Instead, their automated infrastructure
- 14:07scans the entire Internet. Millions of IP addresses
- 14:11looking for a single specific flaw. OK. They
- 14:15might write a script that searches the globe
- 14:16for an unpatched version of a popular enterprise
- 14:19firewall or a known vulnerability in a remote
- 14:22desktop protocol. So it is the digital equivalent
- 14:25of walking down a street that is 10 ,000 miles
- 14:27long and just jiggling every single doorknob
- 14:30at lightning speed to see which ones happen to
- 14:32be unlocked. That analogy is perfectly accurate.
- 14:34Automated scanners can probe the entire IPv4
- 14:37address space in a matter of hours. That's terrifying.
- 14:40And when the script finds an unlocked door...
- 14:42you know, an unpatched server, it automatically
- 14:45exploits the flaw and establishes a quiet foothold.
- 14:48It is only after the initial access is secured
- 14:50that the human operators log in, look around,
- 14:53and figure out who they just breached. They break
- 14:56in first and ask questions later. Like, we just
- 14:59breached a global IT distributor. Excellent.
- 15:02Map the network. Extract the PII and demand a
- 15:04massive ransom. Or we just breached a regional
- 15:08nonprofit. Well, the door was open. We are already
- 15:10inside. Exfiltrate the server and demand a smaller
- 15:13sum. Because the automated nature of the initial
- 15:16access means the cost of breaching the nonprofit
- 15:18is effectively zero. They simply monetize whatever
- 15:22falls into the net. And this fundamentally destroys
- 15:25the old concept of security by obscurity. Many
- 15:28organizations assume they are too small or their
- 15:30industry is too niche to attract the attention
- 15:32of an elite cyber cartel. But SafePay's victim
- 15:35list proves that your industry does not dictate
- 15:38your threat level. Your perimeter defense dictates
- 15:40your threat level. If a device is connected to
- 15:42the internet and it is vulnerable, the scanners
- 15:45will find it, regardless of what the company
- 15:47actually does. Wow. Synthesizing all of this
- 15:49brings the situation with energy action into
- 15:51very sharp focus. We are watching a developing
- 15:54standoff involving an alleged breach of an Australian
- 15:57energy consultancy. And the adversary, SafePay,
- 16:01operates with the speed and global reach of a
- 16:04massive enterprise, claiming hundreds of victims
- 16:06in a matter of months. Right. They achieved that
- 16:09scale not through the chaotic, decentralized
- 16:11affiliate model that dominates the industry,
- 16:14but through a tightly controlled in -house operation.
- 16:17And because they rely on opportunistic exploitation,
- 16:20their victim profile ranges from global tech
- 16:23giants to local nonprofits. And when a group
- 16:26with that level of discipline manages to compromise
- 16:28a B2B consultancy like Energy Action, the leverage
- 16:31shifts dramatically. It really does. They aren't
- 16:34just holding one company's data. They are holding
- 16:37the aggregated, sensitive operational data of
- 16:40every corporate client that consultancy serves.
- 16:43Which is a stark reminder to approach early claims
- 16:46on dark web leak sites with a critical eye, right?
- 16:50Because threat actors routinely exaggerate the
- 16:52scope of a breach during the negotiation window.
- 16:55They do. But the underlying mechanism of the
- 16:57threat is very real. Yeah. And the evolution
- 17:00of safe pay. raises a profound question that
- 17:02security professionals and business leaders really
- 17:05need to consider. Over the last several years,
- 17:08the ransomware economy has been defined by ransomware
- 17:11as a service. The decentralized affiliate model
- 17:13won out because it scaled so quickly. Right.
- 17:16But recently, we have seen law enforcement agencies
- 17:18get much better at dismantling grass networks
- 17:20precisely because those networks are noisy. Affiliates
- 17:24make mistakes, servers get seized, and the infrastructure
- 17:27crumbles. So the messiness of the franchise model
- 17:30is actually becoming a liability for the cartels.
- 17:33Exactly. SafePay is succeeding wildly. By doing
- 17:37the exact opposite, they're running a closed
- 17:39-door, highly centralized syndicate. And if the
- 17:42broader cyber underworld observes Safetay's success
- 17:45and realizes that the Reyes model is too vulnerable
- 17:48to law enforcement disruption... We may be on
- 17:50the precipice of a massive shift back to the
- 17:53era of the disciplined cyber cartel. Wow. And
- 17:56if threat actors tighten their operational security
- 17:58and centralize their tactics, the corporate defense
- 18:00playbook, which has spent years calibrating to
- 18:03fight disorganized affiliates, is going to face
- 18:06a very steep, very dangerous learning curve.
- 18:09Yeah, as the adversary is tightening their ranks
- 18:11and becoming more disciplined, our defensive
- 18:13strategies have to evolve to match that precision.
- 18:16Absolutely. And it brings us right back to the
- 18:18premise we started with. The quiet companies
- 18:21operating in the background, you know, managing
- 18:23our energy profiles or maintaining our IT infrastructure,
- 18:26are often the ones holding the master keys to
- 18:28the broader economy. They are the prime targets
- 18:31in a landscape driven by opportunistic scanning
- 18:33and aggregated data. Well, we want to thank you
- 18:36for joining us for this analysis today. And if
- 18:38understanding the mechanics of these threats
- 18:40has sparked any questions about your own network
- 18:42architecture or the security posture of the third
- 18:45-party vendors you rely on, don't wait for a
- 18:48dark web countdown clock to start assessing your
- 18:51risk. Absolutely. We highly encourage you to
- 18:53visit www .kinsoft .com .au to discuss your own
- 18:57security and IT needs and ensure your business
- 18:59has the defenses in place to avoid becoming the
- 19:02next headline. Stay vigilant out there.