Latest / Tech Talks With Kinsoft / Australian Court Files Sent Offshore – A Data-Sovereignty Failure
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Glad to be
- 0:02here for this one. Yeah. So usually when an organization
- 0:05builds a system to protect something incredibly
- 0:08valuable, the instinct is just to obsess over
- 0:11the physical boundaries. Right. The geography
- 0:14of it all. Exactly. The boardroom questions are
- 0:17always, you know, where are our servers located?
- 0:19Which data center is this in? Do we have a primary
- 0:23and secondary site within our own borders? It
- 0:25makes sense, right? I mean, humans are wired
- 0:27to understand physical geography. A data center
- 0:31in Sydney. It feels tangible. It feels safe.
- 0:35You can point to it. Right. You can point to
- 0:37it. And the assumption is that if the data is
- 0:39physically sitting within the walls of our country,
- 0:42well, it's inherently protected by our legal
- 0:44frameworks. But the danger there, of course,
- 0:46is that a fortified physical location means absolutely
- 0:50nothing if you casually hand out a master key
- 0:53to an unvetted third party. Oh, absolutely. Especially
- 0:56one operating in a totally different jurisdiction.
- 0:58Right. And that is exactly what we are getting
- 1:00into today. In this exploration, we are taking
- 1:03a massive stack of sources reports, investigative
- 1:06articles, corporate statements, and extracting
- 1:09the absolute most crucial insights. You don't
- 1:12have to sift through all that raw reporting yourself.
- 1:15Exactly. Our mission today is analyzing a massive
- 1:18real world failure in data sovereignty, security
- 1:21governance, and third party contracting. Now,
- 1:24if you are listening to this analysis, you're
- 1:26likely already managing these conversations.
- 1:28complex risks in your own environment. Which
- 1:30is why this is so relevant. Right. But I do want
- 1:33to set a firm ground rule for you right at the
- 1:35top. We are keeping this strictly professional.
- 1:37No sensationalism. None. We are not here to dramatize
- 1:41the situation. We're not speculating about individual
- 1:43court cases or the people involved. We are simply
- 1:47looking at the architectural IT and the security
- 1:49failures. Because the core tension we're unpacking
- 1:52here, it represents a really fundamental misunderstanding
- 1:55in modern enterprise IT. It's the classic trap.
- 1:59Yeah, the trap of confusing where data is stored
- 2:01with who actually has access to it. So let's
- 2:04start with the mechanics of the incident to understand
- 2:07how the breach actually occurred. This helps
- 2:09map out the attack surface before we dissect
- 2:11why the governance failed. Good place to start.
- 2:14So in February 2026, this was actually broken
- 2:17by ABC News on February 16th. And then we saw
- 2:20a company statement follow up on February 2024.
- 2:24It emerged that a Canadian transcription provider,
- 2:27VIQ Solutions, had breached its Commonwealth
- 2:30contracts. Right. They were contracted to do
- 2:32Australian court transcriptions, but they subcontracted
- 2:36that Australian work to E24 Technologies, which
- 2:39is a firm based out in India. And that is the
- 2:41crux of it, because this resulted in highly sensitive
- 2:43federal court, federal circuit, and family court
- 2:46files being actively accessed offshore. I try
- 2:49to think about it like this. It's like renting
- 2:51a highly secure bank vault in Sydney, right?
- 2:54But then leaving a live webcam feed of the open
- 2:57vault just completely accessible to someone in
- 2:59another country. If they can see the feed, does
- 3:01it really matter that the physical paper is technically
- 3:03in Australia? It doesn't matter at all. That
- 3:06analogy is spot on. And this brings us to the
- 3:09difference between data residency and data sovereignty.
- 3:12Which people mix up all the time. Constantly.
- 3:15Notice the defense from VIQ's CEO, Larry Taylor.
- 3:19He stated, and I quote, Right. Stored. Exactly.
- 3:28Stored. That defense misses the point entirely.
- 3:31Data residency is just where the data sits. It's
- 3:34the geographic location of the hard drive. But
- 3:36sovereignty is the access part. Right. Sovereignty
- 3:39is about who is legally and operationally able
- 3:42to view and process that data. So Larry Taylor
- 3:46saying the data is stored in Australia, well,
- 3:48that's practically useless if offshore staff
- 3:50with Indian IP addresses are actively accessing
- 3:52those files. Right. If you have remote read and
- 3:54write privileges, the physical location of the
- 3:56server rack is totally relevant. Exactly. The
- 3:58physical layer was secure, sure, but the application
- 4:01layer was completely porous. Okay. So the technical
- 4:03mechanism makes sense, storage versus access.
- 4:06But this brings us to the human element, which
- 4:07is honestly wild to me. The internal governance
- 4:10failures. Yeah. Why didn't internal governance
- 4:12catch this or stop it? Because you don't just
- 4:14set up an offshore pipeline without some alarms
- 4:16going off. And the alarms did go off. Loudly.
- 4:20Right. The reporting shows that internal staff
- 4:22actually raised alarms about this unvetted offshore
- 4:25access as early as August 2025. Months before
- 4:29it broke the news. Months before. And management's
- 4:32response was basically to dismiss them. They
- 4:34told staff the concerns were, quote, not relevant,
- 4:37and told them to stop spreading rumors. Which
- 4:40is just a textbook failure of security culture.
- 4:42Oh, it gets worse. Management even issued an
- 4:44internal memo falsely claiming the E24 resources
- 4:47were based in Sydney. Wow. Yeah. And meanwhile,
- 4:50there is this massive turnover happening. Since
- 4:52July 2025, at least 12 senior staff either quit
- 4:56or were made redundant. And then, the absolute
- 4:59kicker, they fired the entire quality assurance
- 5:02team. That is the part that just screams structural
- 5:04collapse. Right. The remaining contractors were
- 5:07suddenly forced to do unpaid quality control
- 5:09on these E24 transcripts. And these transcripts
- 5:11are coming back at impossible human speeds and
- 5:14were full of major errors. Which heavily implies
- 5:17unvetted automated AI being used in the background.
- 5:20Exactly. But wait, so the automated transcripts
- 5:23are coming back full of errors and their response
- 5:25is to fire the quality assurance team. Isn't
- 5:28that like... Cutting your parachute strings while
- 5:30you're already in free fall? That is exactly
- 5:32what it is. I mean, from a security governance
- 5:34perspective, this is a total collapse. What you're
- 5:37seeing is a culture of silence. Right. When you
- 5:40dismantle internal auditing, like firing the
- 5:42QA team, you are removing the necessary friction
- 5:45that keeps an organization secure. Friction is
- 5:48a good word for it. Yeah. In security, friction
- 5:50is a feature, not a bug. Yeah. QA teams, compliance
- 5:54officers, they purposefully slow things down
- 5:57to ensure safety. But here, they prioritize speed
- 6:01and cost cutting over rigorous internal compliance.
- 6:04They didn't want the friction. Right. And when
- 6:07you remove the people asking the hard questions,
- 6:09you basically unplug your own anomaly detection.
- 6:11Which leads us directly to the national security
- 6:13ripple effect, because we need to look at exactly
- 6:15why where your data is processed matters on a
- 6:18macro scale. The payload itself. The payload.
- 6:21This wasn't just mundane administrative stuff.
- 6:24The compromised files contained incredibly sensitive
- 6:27data. We are talking about evidence from ALSIO
- 6:31and the Australian Federal Police. That is about
- 6:34as sensitive as it gets. Right. The reporting
- 6:36notes this potentially exposed covert operatives,
- 6:39protected witnesses, and international criminal
- 6:42links. And the technical proof was sitting right
- 6:45there in the logs. Access logs showing offshore
- 6:48staff viewing files outside of Australian business
- 6:51hours. Which is a massive red flag. Huge. And
- 6:54ultimately, the matter had to be referred to
- 6:56the Australian Cyber Service. Security Center.
- 6:58Now, the sources also discussed the political
- 7:01reactions specifically from Green Senator David
- 7:04Shoebridge. Right. He was very vocal about this.
- 7:06He was. He called this a national security risk.
- 7:08He urged the termination of the contract and
- 7:10he labeled the situation a failed privatization.
- 7:14Now, I want to be very clear for you listening
- 7:16right now. Yes. An important note here. Yeah.
- 7:18We are neutrally reporting the contents of the
- 7:20sources. We are not endorsing Senator Shoebridge's
- 7:23political viewpoints or taking a side on privatization.
- 7:26We are simply conveying. the perspectives that
- 7:29are present in the material. Our focus is on
- 7:31the architecture. Exactly. But looking at the
- 7:33architecture, the senator did make a point about
- 7:35set and forget contracts. And I have to ask you,
- 7:38how do standard vendor risk assessments completely
- 7:41miss the true sensitivity of a payload like this?
- 7:45Well, that phrase, set and forget. really hits
- 7:48a nail on the head. Standard vendor risk assessments,
- 7:51or VRAs, they usually happen at the very beginning
- 7:54of a contract. Right, during procurement. Yeah.
- 7:56You check their ISO certifications, you look
- 7:58at their data policies, and you approve them.
- 8:00But initial due diligence is completely useless
- 8:03without ongoing continuous auditing. Because
- 8:05environments change. Exactly. Vendors change
- 8:08their software stacks, they change their personnel,
- 8:10or like here, they quietly subcontract the work.
- 8:13If you treat a VRA as a one -time checklist,
- 8:16you are blind to those changes. And the automated
- 8:19systems, why didn't they catch this? Well, they
- 8:21should have. Offshore access outside of local
- 8:24business hours is a glaring anomaly. If you have
- 8:28a properly configured zero trust environment,
- 8:31an automated monitoring system should instantly
- 8:34isolate that session and lock it down. Right.
- 8:36It shouldn't just be a line of text in a log
- 8:38file that someone finds months later. No, it
- 8:40should be an active automated trigger. But if
- 8:44you are in a set and forget mindset, nobody's
- 8:46looking at the logs and the automated triggers
- 8:49aren't configured to stop the bleeding. Which
- 8:51brings us to the actual contractual agreements.
- 8:53We really need to bring this down to the listener's
- 8:55own environment. The subcontractor blind spot.
- 8:58Yes. How contractual controls basically fail
- 9:00in the real world. So according to the sources,
- 9:03the VIQ staff in Australia, they had to undergo
- 9:06national security checks. Makes sense. And they
- 9:08had to sign a Commonwealth court's deed of confidentiality.
- 9:11Yeah. Very strict stuff. But it was completely
- 9:13unclear if the E24 staff in India underwent any
- 9:17of the same vetting. Right. A massive discrepancy.
- 9:20Yet the VIQ CEO stated publicly that contractors
- 9:23like E24 are, quote, required to adhere to the
- 9:27same strict privacy guidelines, service delivery
- 9:30standards and confidentiality as all employees.
- 9:33Which is a bold claim to make. Right. It's like
- 9:36hiring a highly vetted security guard for your
- 9:39office building. But then that guard secretly
- 9:41outsources their night shift to a random stranger
- 9:44on the Internet. Yeah, just completely undermining
- 9:46the whole system. So how does a company actually
- 9:49enforce contractual controls down the supply
- 9:51chain? Does a contract even do anything? Well,
- 9:54what you're describing is what we call the illusion
- 9:57of inherited compliance. The illusion. Yeah.
- 10:00It is this false belief that just because you
- 10:03wrote a strict standard into a legal contract
- 10:05that it magically translates into technical security.
- 10:08But it's just paper. Exactly. A legal contract
- 10:11is a remedy for after a breach happens. It does
- 10:14not stop a breach from happening. Saying a subcontractor
- 10:17must adhere to guidelines means absolutely nothing
- 10:20without technical controls to physically enforce
- 10:22it. So what do those technical controls actually
- 10:24look like? Well, it requires strict access management.
- 10:27It requires geofencing. Meaning literally blocking
- 10:30IP addresses outside of Australia. Exactly. The
- 10:34API gateway should just drop any query from an
- 10:36unapproved region. But it also means you have
- 10:39to control the endpoint. If a remote worker needs
- 10:42to transcribe a file, can they download it to
- 10:45their local hard drive? Right. Or can they just
- 10:48copy and paste the text into an email? If the
- 10:50answer is yes, then your contract is useless.
- 10:53To enforce it technologically, you need things
- 10:55like virtual desktop infrastructure or VDI. Where
- 10:59the data never actually leaves the server. Right.
- 11:01The remote worker just sees a secure pixel stream
- 11:04of the application. You disable their local clipboard,
- 11:07you block print screen, you lock it down completely.
- 11:09But companies don't like doing that because it
- 11:11adds that friction we talked about. Exactly.
- 11:13It slows things down. It costs money. Vendors
- 11:16complain. So companies cave. They accept the
- 11:19operational risk and just hope the legal contract
- 11:21will protect them. And as we've seen today, a
- 11:24contract cannot secure a digital perimeter. It
- 11:26absolutely cannot. So we've covered a lot of
- 11:29ground today. The storage versus access trap
- 11:31ignoring the internal alarms. The national security
- 11:35implications and the danger of inherited compliance.
- 11:38A lot of hard lessons here. Very hard lessons.
- 11:41And we want to leave you with a lingering question
- 11:43to think about in your own architecture. Something
- 11:46that builds on all of this. Exactly. If a supposedly
- 11:49mundane administrative task like transcribing
- 11:52court audio can accidentally expose covert operatives
- 11:56and national security secrets. Right. What harmless
- 11:59outsourced services in your own organization
- 12:02secretly hold the keys to your most sensitive
- 12:05data? Is it your marketing analytics vendor?
- 12:07Is it the AI chatbot widget on your website?
- 12:11your payroll processor. It's a terrifying thought,
- 12:14but you have to look at the basement doors, not
- 12:15just the front gate. You really do. You have
- 12:17to evaluate your third party risks constantly.
- 12:20So before you sign off on your next vendor agreement,
- 12:23we want you to take action. You need the right
- 12:25experts to help you build those technical fences.
- 12:27Don't rely on the paper contracts. Right. So
- 12:30please visit www .kinsoft .com .au to discuss
- 12:34your security and IT needs with the team. get
- 12:37those technical controls in place. Thank you
- 12:39so much for joining us on this exploration today.
- 12:41Protect your boundaries, and we'll see you next
- 12:42time.