Latest / Tech Talks With Kinsoft / Benedict Industries: Quarry Operations and 2025 Cyber Security Incident
Transcript
- 0:00Hello and welcome back. It is so good to have
- 0:02you with us again for Tech Talks with Kinsoft.
- 0:04It's great to be back. Today we're trying to
- 0:05make sense of the, well, the pretty complex and
- 0:09sometimes frankly scary world of technology.
- 0:12And looking at what we're covering today, scary
- 0:14might be the right word, though hopefully we
- 0:17can steer it towards empowering by the end. I
- 0:20hope so. You know, usually I like to ease into
- 0:22these discussions. A fun fact, a bit of history,
- 0:25something relatable. But looking at the sheer
- 0:27volume of reports from late... 2025 and early
- 0:302026 i just don't think we have that luxury we
- 0:34kind of need to just rip the band -aid off it
- 0:36is looking pretty severe out there isn't it i
- 0:38was just reviewing the data for october 2025
- 0:41just one month yeah globally we saw over 193
- 0:46million records compromised wow 193 million.
- 0:50It's hard to even visualize that. And I think
- 0:52especially for our listeners here in Australia,
- 0:54there can be this sort of island mentality. You
- 0:57know, oh, that's a U .S. problem. That's a European
- 0:59problem. We're tucked away down here. But we
- 1:02are squarely in the crosshairs. And what's really
- 1:04alarming about this wave of breaches is just
- 1:07the diversity of the targets. We're not just
- 1:10talking big banks anymore. We're seeing recycling
- 1:12plants, universities. It creates this sense that
- 1:16the threat landscape, to use the jargon. is well
- 1:20it's everywhere and that's our mission for today
- 1:22isn't it yeah we're not here to just list off
- 1:24scary stats and make you want to throw your phone
- 1:26away we want to unpack the who the how and maybe
- 1:30most importantly the why because if you can understand
- 1:33the mechanics you can move from panic to strategy
- 1:36exactly panic paralyzes awareness empowers that's
- 1:40the goal So let's get into it. I want to start
- 1:42with a case that really it really challenged
- 1:44my own assumptions about who gets hacked. It
- 1:46wasn't a bank. It wasn't a tech company. It was
- 1:48a company called Benedict Industries. Yes. The
- 1:51Benedict Industries breach. That one surfaced
- 1:53around October 10th, 2025. So for anyone who
- 1:56doesn't know the name, Benedict is a recycling,
- 1:59landscaping and civil construction company in
- 2:01New South Wales. Based in Belrose. They deal
- 2:03in sand, soil, gravel. I mean, it feels like
- 2:06the most physical analog business you could possibly
- 2:09imagine. And yet this hacking group, INC Ransom,
- 2:13claim they stole 270 gigabytes of their data.
- 2:16This is the perfect example to dismantle a really
- 2:19dangerous myth. Which is? The myth that my business
- 2:22is too boring to hack. I hear it all the time
- 2:24from business owners. You know, I sell dirt.
- 2:26Why would an international cyber gang care about
- 2:28me? Well, it seems logical on the surface, doesn't
- 2:31it? If I'm a hacker, I want credit card numbers
- 2:33or state secrets, not invoices for gravel. That's
- 2:36the movie version of hacking. In reality, these
- 2:39groups run like businesses. They want leverage.
- 2:41And while Benedict Industries might sell sand,
- 2:44they employ people. And that means they have
- 2:46HR data. Exactly. When you look at what was stolen,
- 2:50it wasn't blueprints for a quarry. It was payroll
- 2:52data, workers' compensation records. And there
- 2:55was one detail in the report that really just,
- 2:57it turned my stomach. They access details of
- 3:01employees' child support deductions. That's the
- 3:03detail that changes the whole conversation. It
- 3:05shows the granularity of the extortion. It's
- 3:08what we call PII, personally identifiable information,
- 3:12to a cyber criminal that is liquid gold. But
- 3:17why is that gold specifically? Is it just to
- 3:19embarrass people? Embarrassment is part of it.
- 3:22Sure. But it's more about utility. You can change
- 3:24a credit card number. You can change a password.
- 3:26You can't change your child support history or
- 3:28a worker's comp claim. That data is permanent.
- 3:31It's immutable. It allows for identity theft
- 3:33that can last for years. So it doesn't matter
- 3:35if you run a local bakery or a billion dollar
- 3:38tech firm. If you employ people, you hold high
- 3:42value data. So INC Ransom gets this data. What's
- 3:45their play? Do they just sell it on the dark
- 3:47web or is it a more direct squeeze on the company?
- 3:50Well, INC Ransom is a big fan of what we call
- 3:52double extortion. Okay, let's pause on that.
- 3:54Double extortion. What does that actually look
- 3:56like for a business owner? So step one is the
- 3:58classic ransomware move. They encrypt your systems,
- 4:01your screens go black, you get a scary note,
- 4:03operations stop. Which is bad enough. It shuts
- 4:05the business down. Right. But companies started
- 4:07getting good at backups. They'd say, fine, encrypt
- 4:09it. We'll just restore from yesterday. So the
- 4:11hackers evolved. Step two, the double extortion.
- 4:16is stealing the data before they encrypt it.
- 4:18Then they say, if you don't pay, we won't just
- 4:21keep your files locked. We will publish them
- 4:23to the world. Which they did. In the Benedict
- 4:25case, they actually published it. They did, October
- 4:279th and 10th. And that puts the victim in an
- 4:30impossible position. Even if your IT team is
- 4:33amazing and restores your systems, the privacy
- 4:35of your staff is already gone. It's a checkmate.
- 4:38So the technical fix isn't enough. It's a PR
- 4:40crisis, a legal crisis all at once. Speaking
- 4:44of pressure and vulnerable groups, let's pivot
- 4:47to another sector that was just besieged in late
- 4:502025. Education. Oh, the education sector has
- 4:53become one of the top targets for these groups.
- 4:55Absolutely. We have to talk about Western Sydney
- 4:57University. This story is just wild, not just
- 5:00because of the breach, but the timeline. The
- 5:03access actually happened between June and September
- 5:052025. That's right. A really sustained period
- 5:08of access. But we didn't hear about it until
- 5:10October. Now, usually when a company hides a
- 5:13breach, there's public outrage. But in this case,
- 5:16the delay was requested by the NSW police. Correct.
- 5:20And that's a fascinating wrinkle. The police
- 5:22were actively monitoring the perpetrators inside
- 5:25the system. It wasn't negligence. It was an active
- 5:28law enforcement op. Which makes sense. Right.
- 5:30But... Put yourself in a student's shoes. You
- 5:33find out months later your data was taken. And
- 5:36it's not your grades. It's tax file numbers,
- 5:39passport details, health information. For about
- 5:4210 ,000 students and staff, that's a small town's
- 5:45worth of sensitive data. And this is where it
- 5:47gets really dark. The fallout wasn't just data
- 5:49theft. The hackers used that data to launch a
- 5:52psychological attack. You're talking about the
- 5:54phishing campaign that followed. Yes. Students
- 5:56started getting emails using stolen contact info
- 5:59claiming their degrees had been revoked. Imagine
- 6:01getting that email during exam week. It's incredibly
- 6:04sophisticated social engineering. They used real
- 6:07student IDs, real course names. It just creates
- 6:10chaos. And this raises an important point about
- 6:13why universities are such juicy targets. Think
- 6:15about the demographic. Young people. Exactly.
- 6:1818 to 22 -year -olds. They usually have thin
- 6:21credit files. Their credit history is a blank
- 6:24slate. So they're a blank canvas for fraudsters.
- 6:27Precisely. It's a goldmine for identity theft.
- 6:30You could take out loans in their name for years
- 6:32before they'd even notice because most students
- 6:33aren't checking their credit reports. That's
- 6:35terrifying. And it wasn't just WSU. There was
- 6:38the VTRAC incident around the same time. Correct.
- 6:41And VTRAC shows us a different kind of vulnerability.
- 6:45They're a software provider for student management.
- 6:47When they got hit, it caused a nationwide outage.
- 6:51So this wasn't just one school. No. Hundreds
- 6:53of training organizations across the country
- 6:55couldn't access their own data. They couldn't
- 6:58mark attendance, couldn't issue certificates.
- 7:00It really highlights that ripple effect. One
- 7:02provider goes down and an entire industry is
- 7:05in the dark. That's the perfect segue to what
- 7:08I think is the most critical theme of late 2025,
- 7:11the supply chain risk, or as I like to call it,
- 7:14the Trojan horse. The Trojan horse. I like that
- 7:17because when we look at the headlines, we see
- 7:20big names, Qantas. BMW. These are massive corporations
- 7:24with huge security budgets. How are they getting
- 7:27breached? They're not getting breached through
- 7:29the front door. They're getting breached through
- 7:30the service entrance, through the vendors they
- 7:33trust. Let's look at Quantas. The breach in mid
- 7:362025, 5 .7 million customer records. That's the
- 7:40one. But Qantas itself wasn't hacked. Their own
- 7:43servers were secure. It was a third party contact
- 7:46center, a company they hired to handle calls
- 7:48that was compromised. So you hand over the keys
- 7:50to the database and suddenly 5 .7 million frequent
- 7:53flyer numbers are out in the wild. Exactly. It's
- 7:56like installing a bank vault door on your house,
- 7:58but giving the spare key to a dog walker who
- 8:01leaves it on a park bench. The Attackers, a group
- 8:04with the bizarre name Scattered Lapsus Hunters.
- 8:07Sounds like a bad 90s band name. It basically
- 8:09is. It's a mix of members from older groups.
- 8:11They declared a war on Australia, and their method
- 8:14was to hit the supply chain. Qantas can have
- 8:17the best firewall in the world, but if their
- 8:19vendor has a weak password, the data is gone.
- 8:22Same story with BMW, right? Yes. September 2025,
- 8:25600 ,000 lines of audit data leaked. Again, not
- 8:28BMW's servers, but a third -party provider. So
- 8:31what does this mean for a business owner listening?
- 8:33If you can't trust your vendors, who can you
- 8:36trust? It means the whole concept of perimeter
- 8:38security is dead. Your security is only as strong
- 8:41as your least secure vendor. The stats show that
- 8:4560 percent of major breaches in late 2025 involve
- 8:48third parties. 60 percent. That's a clear majority.
- 8:50It is. It means you have to audit your partners
- 8:53as rigorously as you audit yourself. You have
- 8:56to ask the hard questions before you sign the
- 8:57contract. I want to zoom out a bit and look at
- 9:00the who behind this. We mentioned INC Ransom
- 9:02and the Scattered Labs as hunters. It feels like
- 9:04there's a new gang every week. It's a crowded
- 9:06marketplace. We saw activity from Quillen, Medusa,
- 9:09Lynx. They're all competing for market share.
- 9:12And no industry is off limits. We've talked construction,
- 9:14education. But healthcare took a real beating.
- 9:18Genie IVF, 940 gigabytes stolen. That one is
- 9:21particularly distressing. We talked about PII.
- 9:24But IVF treatment data. That's so incredibly
- 9:28private, so emotional. To have that exposed is
- 9:32a violation on a whole different level. It's
- 9:34just cruel. And then the legal sector. Kelly
- 9:37Legal. Brighton's lawyers. Lawyers are a prime
- 9:40target. They hold everyone's secrets, but they
- 9:42also can't afford downtime. Time is literally
- 9:45money for them, so they're statistically more
- 9:47likely to pay a ransom quickly. There was also
- 9:50a really concerning case with Dodo and iPrimus
- 9:52in October. This wasn't just data theft. It was
- 9:55a functional attack on our infrastructure. Yes,
- 9:57the SIM swapping attacks. Can you just explain
- 10:00that? I think people hear SIM swap and think
- 10:01someone physically stole their phone card. It's
- 10:04purely digital. The hackers got into customer
- 10:07email accounts. Then they just contacted the
- 10:09telco, pretended to be the customer, and asked
- 10:12to move the mobile number to a new SIM card that
- 10:14the hacker controlled. So my phone suddenly goes
- 10:16dead, and the hacker's phone lights up with my
- 10:19number. Exactly. And they want your number for
- 10:20one reason, for two -factor authentication codes.
- 10:23Oh, wow. So when my bank sends a code to my mobile,
- 10:28It goes straight to the hacker. Correct. It completely
- 10:30bypasses the security we all rely on. It's a
- 10:33direct attack on identity verification. It's
- 10:35terrifyingly clever. But, you know, as we talk
- 10:38about these sophisticated groups, there's another
- 10:40stat you highlighted that caught my eye. 37 %
- 10:42of notifications to the regulator were just human
- 10:46error. Yes. We cannot forget the human element.
- 10:49We worry about these cyber gangs. But a huge
- 10:51chunk of breaches happen because someone CC'd
- 10:54the wrong person or left a laptop on a train.
- 10:58Or clicked a bad link. The oops factor. It is.
- 11:01And in the industrial sector, that oops can stop
- 11:04physical production. Look at Jaguar Land Rover
- 11:07in the UK. Cyber attacks stopped the assembly
- 11:09lines. This is where IT meets OT, operational
- 11:12technology. When the computers go down, the factory
- 11:16stops. OK, I feel like we painted a very grim
- 11:17picture. It feels like the Wild West. Please
- 11:19tell me there's a sheriff coming to town. Is
- 11:20anyone fighting back? There is absolutely pushback.
- 11:23The government and industry are waking up. October
- 11:25was Cybersecurity Awareness Month, and we saw
- 11:27some really significant policy shifts. I saw
- 11:30we have a new Cyber Incident Review Board. What's
- 11:32their job? Just handing out fines. Quite the
- 11:35opposite, actually. Think of them like air crash
- 11:37investigators for cyber attacks. They do no fault
- 11:41reviews. The goal isn't to punish the victim.
- 11:44It's to learn from it so everyone else can be
- 11:46prepared. That's crucial because usually companies
- 11:49just want to hide it so no one learns a lesson.
- 11:51Exactly. We need to share intelligence. We also
- 11:55have a new ambassador for cyber affairs, Jessica
- 11:58Hunter. She comes from an intelligence background,
- 12:01which signals the government sees this as a national
- 12:03security issue. So if I'm listening to this,
- 12:05what's the mindset shift I need to make? What's
- 12:08the strategy? You need to move away from just
- 12:10protecting the perimeter. The old model was building
- 12:13a high wall. The new mentality from the essential
- 12:16eight framework is assume compromise. Assume
- 12:19compromise. Yeah. That sounds pessimistic. It's
- 12:22realistic. It means assume they're already in
- 12:24or they will get in. So do you have the systems
- 12:27to detect them? Can you limit the damage? Are
- 12:29your backups offline so they can't be encrypted
- 12:31to? So it's like having motion detectors inside
- 12:33the house, not just a lock in the front door.
- 12:35Precisely. Because with the rise of AI, that
- 12:38front door is getting a lot harder to defend.
- 12:41How is AI changing the game? Well, generative
- 12:44AI lets hackers scale up phishing attacks. You
- 12:47know those scam emails full of typos? Dear sir,
- 12:51I am a prince ones. The ones that were easy to
- 12:54spot. Yeah. Well, now AI writes perfect, persuasive,
- 12:57context -aware emails. It can scrape your LinkedIn,
- 13:00see you just went to a conference, and write
- 13:02an email saying, great meeting you there. Here's
- 13:04that file we discussed. So that 37 % human error
- 13:07stat could go way up if the scams get better.
- 13:11It absolutely could, which is why training and
- 13:13culture are just as important as firewalls. You
- 13:15need a culture where people aren't afraid to
- 13:17ask. Does this look right? It really is a constant
- 13:20evolution. It is. But I want to emphasize it's
- 13:22a race you can survive. It's about resilience,
- 13:24not invincibility. That's a great way to frame
- 13:27it. Resilience. Whether you're a recycling plant
- 13:29or a university or an airline, the reality is
- 13:32clear. Data is currency. And your supply chain
- 13:35is likely your weakest link. And navigating this
- 13:38isn't something you can just do on the fly. It
- 13:40requires expertise, strategy, and... And honestly,
- 13:44it requires help. Absolutely. You don't want
- 13:46to wait until you're a headline to start thinking
- 13:48about this. The cost of prevention is just a
- 13:50fraction of the cost of recovery. That is the
- 13:53truth. If you're listening and thinking, I don't
- 13:55know if my vendors are secure or I don't know
- 13:57if we could spot an intruder, you need to bring
- 13:59in experts. We highly recommend you head over
- 14:02to www .kinsoft .com .au. That's www .kinsoft
- 14:07.com .au. They can help you discuss your security
- 14:11and IT needs and make sure you don't become the
- 14:13next case study we talk about on this show. Exactly.
- 14:16Don't be the boring business that gets hacked.
- 14:18Be the boring business that stays secure. I like
- 14:21that. Security should be boring. Boring is good.
- 14:24Before we go, here's a thought to leave you with.
- 14:26We've talked about data theft and encryption.
- 14:29But when attackers start messing with SIM cards
- 14:31and launching psychological attacks, we have
- 14:34to ask. What happens when the goal isn't just
- 14:36to steal your data, but to make you doubt the
- 14:39data you still have? That's a chilling thought.
- 14:41The integrity of reality itself becomes the target.
- 14:44Something to mull over. Thank you for joining
- 14:46us. This has been Tech Talks with Kinsoft. Stay
- 14:49safe out there. Goodbye, everyone.