Latest / Tech Talks With Kinsoft / DragonForce Hits Australian Health Software Vendor HMS
Transcript
- 0:00Welcome to Check Talks with Kinsoft. It is our
- 0:02absolute priority to take a massive stack of
- 0:05sources, you know, the latest articles, the raw
- 0:08incident reports, and really just extract the
- 0:10critical insights from them. Yeah, exactly. Our
- 0:13whole mission is to do that heavy analytical
- 0:15lifting for you. Right, just connecting the dots
- 0:17so that you can stay well -informed and, more
- 0:19importantly, secure in a digital landscape that
- 0:22is honestly just constantly shifting under your
- 0:24feet. It never stops moving, that's for sure.
- 0:26No, it really doesn't. And today... We are setting
- 0:29our sights on a singular, really high stakes
- 0:33event. We need to rewind the clock just slightly
- 0:36to around March 19th, 2026. Yeah, this was a
- 0:40major wake up call. It really was. So a notorious
- 0:42ransomware group known as Dragon Force stepped
- 0:45out of the shadows and they claimed a massive
- 0:47cyber attack on a company called Health Management
- 0:49Systems. Right. Operating at HMS .com .au. Exactly.
- 0:53And they are a major Australian provider of health
- 0:55care software. And, you know. The implications
- 0:58of that specific target are just monumental.
- 1:01Health management systems, I mean, they are not
- 1:02a hospital themselves, right? They are a software
- 1:04provider. Which changes everything. It does.
- 1:07We are currently watching the entire industry
- 1:09try to calculate the ripple effects of this compromise.
- 1:12And that is the core issue for you listening
- 1:14right now. This is not just, you know, a localized
- 1:16story about one unfortunate company dealing with
- 1:18a network intrusion. But far from it. Yeah, this
- 1:21is a blaring wake up call regarding the fragile
- 1:24nature of digital supply chains, specifically
- 1:26within the health care sector. When a single
- 1:29vendor experiences a breach. The blast radius
- 1:33extends way beyond their own internal IT department.
- 1:36Oh, absolutely. The downstream effects are terrifying.
- 1:38Right. It places countless downstream hospitals,
- 1:41local health clinics, and ultimately vulnerable
- 1:43patient data directly in the crosshairs. So to
- 1:47really understand the threat to your own organization's
- 1:50infrastructure, we first have to dissect exactly
- 1:53what happened to health management systems and,
- 1:55well, Look at the adversary pulling the strings.
- 1:58Yeah, because you cannot defend against an attack
- 2:01if you don't understand the mechanics of the
- 2:03weapon being used against you. The adversary's
- 2:06playbook tells us exactly where our structural
- 2:08vulnerabilities lie. Okay, let's unpack this.
- 2:12Dragonforce didn't just quietly lock up some
- 2:14servers and send a private email demanding cash,
- 2:17did they? No, not at all. They went completely
- 2:19public. Late last week, they listed health management
- 2:22systems directly on their leak site. Wow. Just
- 2:26openly claiming to hold highly sensitive data
- 2:29from this health care software provider. Yeah.
- 2:31And they issued a very direct threat. Negotiate
- 2:34a ransom or we release everything. And as of
- 2:37the initial reporting. We don't really have full
- 2:40confirmation from the company about the exact
- 2:42volume of data exfiltrated. Right. Or even the
- 2:44scale of the service disruptions. Right. The
- 2:46details are still coming together. But honestly,
- 2:48in this scenario, the threat alone is a ticking
- 2:50clock. It's terrifying. I mean, targeting the
- 2:53software vendor instead of a single clinic, it's
- 2:55like a thief stealing the master key from an
- 2:57apartment building's management office, rather
- 3:00than painstakingly trying to pick the locks of
- 3:02individual apartments one by one. That's a perfect
- 3:04way to look at it. And what's fascinating here
- 3:07is how this incident perfectly aligns with Dragon
- 3:10Force's established operational pattern. Right.
- 3:13They have a very specific M .O. They do. They
- 3:16are specialists and their chosen specialty is
- 3:19targeting the health care sector for what the
- 3:21cybersecurity community refers to as quick extortion.
- 3:25Quick extortion. I mean, that sounds highly predatory.
- 3:28Oh, it is. It's incredibly predatory. Break down
- 3:30the mechanics of that strategy for us. Why prioritize
- 3:33health care over, say, a massive financial institution
- 3:37or a global manufacturing plant? It really comes
- 3:40down to the unforgiving economics of the health
- 3:43care industry. I mean, think about it. If a manufacturing
- 3:45plant gets hit with ransomware and their assembly
- 3:48line halts, they lose revenue. It's bad, but...
- 3:52Yeah, it's a terrible situation. Shareholders
- 3:54are angry, but it's ultimately just a financial
- 3:56calculation. But if a hospital network goes offline.
- 4:00Medical staff lose the ability to access patient
- 4:03histories. Exactly. Surgical schedules, medication
- 4:06dosages. The urgency to recover in a health care
- 4:08setting is absolute. It involves human lives,
- 4:11patient safety. So Dragon Force intimately understands
- 4:15this high pressure environment. They bank on
- 4:18it. They know that hospital administrators or
- 4:21critical vendors like HMS will feel completely
- 4:23backed into a corner by the moral and operational
- 4:26imperative to restore services. And that drives
- 4:28them to pay ransoms quickly. Yes. Often bypassing
- 4:31prolonged negotiations entirely just to resolve
- 4:34the immediate crisis. Wow. And that strategy
- 4:37is amplified by the fact that they publicly posted
- 4:39HMS on their leak site. Yeah. I mean, they aren't
- 4:42just encrypting data and halting operations.
- 4:44They are threatening to expose it all. That is
- 4:46the double extortion model at work. The initial
- 4:49phase is locking the systems to halt operations,
- 4:52right? But the second phase is threatening to
- 4:54dump protected health information onto the dark
- 4:56web. Which introduces just severe regulatory
- 5:00terror. Precisely. In Australia, a massive data
- 5:04breach involving medical records triggers intense
- 5:06scrutiny, severe fines, and just irreparable
- 5:10reputational damage. Dragon Force is essentially
- 5:13turning the regulatory environment into a weapon
- 5:16against the victim. To maximize the leverage
- 5:18they have to force a payout. That is so cynical.
- 5:21It's brutal. And their strategy relies heavily
- 5:24on scale. They cannot extort the health care
- 5:26industry efficiently if they have to breach one
- 5:28heavily defended local clinic at a time. Right,
- 5:31which naturally drives them to exploit the digital
- 5:33supply chain. Yeah. Attacking the central nodes
- 5:36that connect to everyone else. Exactly. Here's
- 5:38where it gets really interesting. Let me throw
- 5:39a hypothetical at you. Okay, go for it. So if
- 5:41a local clinic out in the suburbs spends millions
- 5:44securing its own internal network. Right. They
- 5:47deploy top tier firewalls, endpoint detection
- 5:50and response, full zero trust network architecture.
- 5:53Are they still completely exposed simply because
- 5:56they use health management system software? If
- 5:58we connect this to the bigger picture, the uncomfortable
- 6:01reality is yes. Wait, really? Yeah. Even with
- 6:04all that internal security? Yes. They are structurally
- 6:08exposed. Look. 10 or 15 years ago, a hospital
- 6:11security perimeter was tangible. It was the physical
- 6:14building and the servers were sitting in a locked
- 6:17room on premises. Right. You just built a digital
- 6:19moat around that data center. Exactly. But today,
- 6:22that perimeter is entirely porous. The Perona
- 6:25extends to literally every piece of software
- 6:27that hospital purchases and integrates. I see.
- 6:30So when a clinic installs software from a vendor
- 6:33like HMS, they are granting that software and
- 6:36by extension, the vendor, a certain level of
- 6:39trusted access to their internal networks. Because
- 6:42it requires that access to actually function.
- 6:44Right. Whether that is pulling patient demographics
- 6:46or updating billing records. So they are essentially
- 6:49provisioning an open. trusted pathway straight
- 6:53through their own million -dollar firewall. Precisely.
- 6:55And hackers are highly opportunistic. Dragonforce
- 6:58realizes there is absolutely no need to spend
- 7:01months attempting to batter down the heavily
- 7:03guarded front door of a major hospital network.
- 7:06Why bother when there's a side door left wide
- 7:08open by a vendor? Exactly. They target the softer,
- 7:12perhaps less heavily defended third -party software
- 7:14vendor that already holds administrative privileges
- 7:17or APITs that grant access to the hospital's
- 7:20internal systems. And if the adversary compromises
- 7:23the vendor, they just use the vendor's existing
- 7:26trusted connections to pivot laterally into the
- 7:29hospital's network. Yeah, the attack actually
- 7:31originates from inside the perimeter. It bypasses
- 7:34traditional external defenses entirely. Which
- 7:37means the blast radius of... supply chain attack
- 7:39is just exponential. One successful breach of
- 7:43a vendor like HMS yields dozens, maybe hundreds
- 7:46of downstream victims. It's a domino effect.
- 7:49And because of that architecture, organizations
- 7:51cannot afford to simply hope their vendors stay
- 7:53secure. Hope is definitely not a strategy. You
- 7:56need actionable, layered defense strategies to
- 7:58ensure you survive when one of your key vendors
- 8:00inevitably gets compromised. Resilience has to
- 8:03be engineered into the architecture from day
- 8:05one. The source reports analyzing the HMS incident
- 8:08layout very specific countermeasures that organizations
- 8:11are urged to adopt immediately. Let's get into
- 8:14those. What are we looking at? We are looking
- 8:15at rigorous vendor security reviews, maintaining
- 8:18isolated offline backups, implementing phishing
- 8:22-resistant staff training, actively monitoring
- 8:24networks for anomalous behavior, and establishing
- 8:27robust incident response plans. So what does
- 8:32this all mean? Now, let's tackle the backup strategy
- 8:33first, because we hear about this all the time.
- 8:36Yeah, it's a critical one. Like, I want to use
- 8:38an analogy here. It's like having a digital fireproof
- 8:41safe, right? If your house, which is the primary
- 8:43network. burns down, the documents in that completely
- 8:47separate, disconnected safe survive perfectly
- 8:51intact. That's a great way to visualize it. For
- 8:54an IT literate audience, we know the basic concept
- 8:57of an error gap, but the reality of implementing
- 8:59it today is incredibly complex. Oh, absolutely.
- 9:01Because you have organizations relying on continuous
- 9:04automated cloud synchronization just to meet
- 9:07these aggressive recovery time objectives. Right.
- 9:10And if your data is constantly syncing to the
- 9:12cloud so you can restore it. in five minutes,
- 9:14you don't actually have a true air gap. Because
- 9:16if it's connected, the ransomware can reach it.
- 9:18That is the central architectural tension right
- 9:20there. Organizations think they are protected
- 9:23because their data replicates to a secondary
- 9:25cloud environment every few minutes. But if that
- 9:28cloud repository is constantly connected to the
- 9:31live production network via active credentials,
- 9:33ransomware will simply travel across that connection
- 9:36and encrypt the backup simultaneously. Wow. So
- 9:39the backups become useless. Completely. True
- 9:42isolated backups require immutable storage. Break
- 9:46down how immutable storage functions as a defense
- 9:49against a supply chain attack. What does that
- 9:51actually look like? Immutability means that once
- 9:53data is written to the backup target, it cannot
- 9:56be altered, encrypted, or deleted by anyone,
- 9:58not even someone possessing the highest level
- 10:00of administrative privileges. Really? For how
- 10:02long? For a predetermined period set by the policy.
- 10:05So if Dragonforce compromises a vendor, uses
- 10:08that trusted connection to gain domain admin
- 10:10rights on your local network, and then attempts
- 10:12to wipe your backups to force a ransom payment,
- 10:15the immutable storage simply rejects the command.
- 10:19That is brilliant. The data just remains locked
- 10:21in a read -only state. Exactly. But implementing
- 10:24this requires separating the control plane of
- 10:27your backups from your primary network's active
- 10:29directory. Right. So if your primary identity
- 10:31provider is compromised, the threat actor still
- 10:34cannot access the backup infrastructure. Yes,
- 10:36because it relies on an entirely different isolated
- 10:39authentication mechanism. Okay, that secures
- 10:42the data payload. But let's look at the human
- 10:44element, because the reports heavily emphasize
- 10:48fishing resistance staff training. This raises
- 10:51an important question. How do you actually execute
- 10:53phishing resistant training in a health care
- 10:56environment where the staff are medical professionals
- 10:58operating under immense stress? Yeah, I mean,
- 11:01they are often fatigued dealing with life or
- 11:04death patient care. You can't just mandate an
- 11:07annual multiple choice cybersecurity quiz and
- 11:10expect a triage nurse at the end of a 12 hour
- 11:12shift to meticulously scrutinize the URL of an
- 11:15urgent portal login email. It's completely unrealistic.
- 11:18Human fatigue will eventually over. ride training
- 11:20every single time. So what's the alternative?
- 11:23That is exactly why the industry is shifting
- 11:25the definition of phishing resistant. It no longer
- 11:29means training humans to perfectly spot phishing
- 11:32emails. It means deploying authentication technology
- 11:35that resists phishing even if the human makes
- 11:37a mistake. Okay, like what? Give me an example.
- 11:40We are talking about hardware security keys,
- 11:43like FIDO2 tokens. Oh. Right. So if a doctor
- 11:47clicks a malicious link that perfectly spoofs
- 11:50the health management system's login page and
- 11:53they type in their password. The attacker gets
- 11:55the password. But they can't do anything with
- 11:57it. Exactly. The attacker cannot complete the
- 12:00login without physically possessing the doctor's
- 12:02hardware token. The technology provides the safety
- 12:05net that human awareness training simply cannot
- 12:07guarantee. That makes so much sense. Which brings
- 12:10us to the concept of active network monitoring.
- 12:12If a credential does get stolen. or a vendor's
- 12:15trusted connection is hijacked, we need to catch
- 12:18it immediately. We have to operate under the
- 12:20assume breach mentality. We assume Dragon Force
- 12:23is already inside the house. So active monitoring,
- 12:26specifically endpoint detection and response
- 12:28tools combined with behavioral analytics, looks
- 12:31for the anomalies that occur after the initial
- 12:34intrusion. Because ransomware attacks don't usually
- 12:36deploy the encryption payload the millisecond
- 12:39they breach the perimeter, do they? No, rarely.
- 12:41There's a dwell time. The attackers move laterally.
- 12:44They escalate privileges. They map out the network
- 12:46to find the most sensitive patient. data and
- 12:48they slowly exfiltrate it. And active monitoring
- 12:51flags that exact behavior. It does. It alerts
- 12:54the security operations center that, say, a vendor
- 12:57service account, which normally only communicates
- 13:00with the billing server at 2 .00 p .m., is suddenly
- 13:03trying to access the medical imaging database
- 13:05at 3 .00 a .m. That is a massive. behavioral
- 13:09red flag. And it allows the security team to
- 13:11isolate the compromised segment before the extortion
- 13:14cycle even begins. Let's shift to the preventative
- 13:17side of this equation for a second. The reports
- 13:19emphasize conducting rigorous vendor security
- 13:21reviews. But, I mean, a lot of organizations
- 13:24view this as just a compliance checkbox, don't
- 13:26they? Unfortunately, yes. Sending a massive spreadsheet
- 13:30of questions to a vendor and just filing away
- 13:32their answers. How do we make this a functional
- 13:34defense mechanism against something as severe
- 13:37as the HMS breach? A functional vendor security
- 13:40review requires moving beyond self -attestation.
- 13:44You cannot just ask a vendor if they are secure.
- 13:46You have to demand proof. Like actual audits.
- 13:49Exactly. This involves requiring independent
- 13:52third -party audits, like a SOC2 Type 2 report,
- 13:56which verifies that the vendor's security controls
- 13:59have been actively tested and proven effective
- 14:01over a continuous period, usually 6 to 12 months.
- 14:04That's way better than the spreadsheet. It also
- 14:06involves scrutinizing their software bill of
- 14:08materials. That is a critical point. A software
- 14:11bill of materials, or SBOM, basically tells you
- 14:14all the open source and third -party components
- 14:17the vendor used to build their software, right?
- 14:19It is the ingredient list. If a major vulnerability
- 14:22is discovered in a common open source logging
- 14:24library, you need the vendor's SBOM to instantly
- 14:28know if the software you purchased from them
- 14:30contains that vulnerable component. Wow, okay.
- 14:32Furthermore, a rigorous review dictates how you
- 14:35manage the vendor's access to your environment.
- 14:37You have to apply the principle of least privilege.
- 14:40So if the HMS software only needs to read demographic
- 14:43data, you ensure the service account it uses
- 14:46has... Absolutely zero right access. And zero
- 14:49access to other databases. You restrict the vendor's
- 14:52lateral movement before an attack ever occurs.
- 14:55And when all those defenses fail, because let's
- 14:57face it, sometimes they do, when the vendor is
- 15:00breached, the attacker bypasses the monitoring
- 15:02and the network is suddenly compromised. Organizations
- 15:06need robust incident response plans. The reports
- 15:09note this is the final backstop to avoid paying
- 15:11ransoms. But an incident response plan cannot
- 15:14just be a dusty PDF. Sitting on an IT director's
- 15:17hard drive. Especially because if the network
- 15:18is encrypted by Dragonforce, you will not even
- 15:21be able to open that PDF. Exactly. A robust incident
- 15:24response plan is a heavily rehearsed operational
- 15:26protocol. It requires conducting regular tabletop
- 15:29exercises that involve not just the IT security
- 15:31team, but executive leadership, legal counsel,
- 15:35and public relations. Walk us through the mechanics
- 15:37of that in the heat of a breach. What does a
- 15:40robust plan actually look like when the screens
- 15:44suddenly go dark? First, it establishes out -of
- 15:47-band communication. If Dragonforce compromises
- 15:50your email servers and internal chat applications,
- 15:53your incident response team cannot use those
- 15:55tools to coordinate the defense. Because the
- 15:58attackers are literally watching the chat. Exactly.
- 16:00You need pre -established secure external communication
- 16:04channels, like a separate secure messaging instance
- 16:07deployed entirely on mobile devices. That makes
- 16:10sense. What's next? Second, the plan defines
- 16:12clear decision matrices and authorities. In the
- 16:15middle of a Friday night cyber attack, who specifically
- 16:17has the legal and operational authority to sever
- 16:20the hospital's connection to the Internet, who
- 16:22has the authority to take critical patient care
- 16:25systems offline to prevent the spread of the
- 16:27infection? You cannot be making those decisions
- 16:29by committee while data is actively being exfiltrated.
- 16:32No, you need predefined playbooks. And crucially,
- 16:36a robust plan details the exact procedure for
- 16:39failing over to manual paper -based operations
- 16:41in a clinical setting. Right. Medical staff need
- 16:43to know exactly how to continue triaging patients,
- 16:46tracking medications, and routing lab results
- 16:48without the software they rely on every single
- 16:51day. The smoother the transition to manual operations,
- 16:55the less pressure the organization faces to pay
- 16:57the ransom to restore digital services. The entire
- 17:00goal of these layered defenses, from immutable
- 17:03backups to vendor reviews to rehearsed incident
- 17:06plans, is to systematically remove the attacker's
- 17:09leverage. This entire situation just forces us
- 17:12to take a hard, critical look at the architecture
- 17:14we are building. The health management system's
- 17:17breach illustrates a profound tension in modern
- 17:19IT. Which honestly brings me to a final thought
- 17:22I want to leave you with today. I'd love to hear
- 17:24it. As we rush headlong to adopt more deeply
- 17:26integrated software, constantly striving to make
- 17:28healthcare, finance, and critical infrastructure
- 17:30faster and more efficient, are the very tools
- 17:34and connections designed to optimize our operations
- 17:36actually becoming our greatest structural vulnerabilities?
- 17:40We are building ecosystems of incredible efficiency,
- 17:43but we are simultaneously centralizing the risk.
- 17:46It's a paradox the industry really must solve.
- 17:49That's very true. The connectivity that grants
- 17:51us operational power is the exact same connectivity
- 17:54that introduces immense shared vulnerability.
- 17:58Navigating the balance between integration and
- 18:00isolation is arguably the defining cybersecurity
- 18:03challenge we face today. If today's conversation
- 18:05got you thinking about your own network architecture.
- 18:08You know, the trusted pathways you have granted
- 18:10to third -party vendors and your organization's
- 18:13readiness to handle a supply chain compromise.
- 18:15Do not wait for a prominent vendor to make headlines
- 18:18before you take action. You really need to be
- 18:20proactive. I highly encourage you to visit www
- 18:23.kinsoft .com .au to discuss your security and
- 18:28IT needs with the experts. You can start engineering
- 18:31resilience into your infrastructure today before
- 18:34the ticking clock ever starts. Thank you for
- 18:36taking the time to explore the mechanics of this
- 18:38threat landscape with us. Stay vigilant. Keep
- 18:40questioning the systems around you, and we will
- 18:42catch you on the next one.