Latest / Tech Talks With Kinsoft / Gregory Jewellers Data Breach – Kairos Ransomware Claims 574GB
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. I want you
- 0:03to imagine, just for a second, walking into a
- 0:06really high -end Sydney boutique. Oh, like one
- 0:09of those places with the armed guards at the
- 0:10door? Yeah, exactly. Heavy glass, marble floors,
- 0:13the whole thing. And you've just selected a luxury
- 0:17watch or maybe a piece of fine jewelry to celebrate
- 0:20a milestone. Right. And to process the transaction,
- 0:23maybe you're claiming an international tax refund.
- 0:26So you hand over your passport to the person
- 0:28behind the counter. Which feels pretty standard
- 0:30in that environment. Right. They scan it, the
- 0:32paperwork clears, and you just walk out into
- 0:34the sunshine with your new watch. But imagine
- 0:37a few weeks later, a Russian -speaking cyber
- 0:39syndicate sends you an email. Oh, wow. And it
- 0:42contains a high -resolution scan of that exact
- 0:45passport right alongside an itemized receipt
- 0:47of your purchase. And they are demanding a ransom.
- 0:51It's I mean, it's a completely terrifying scenario.
- 0:53It really is. And our mission today is to pull
- 0:56back the curtain on a story where this highly
- 0:59polished, fortified world of physical luxury
- 1:02just, you know, collides head on with the messy,
- 1:07invisible vulnerabilities of the digital landscape.
- 1:10Yeah, the contrast is huge. We are unpacking
- 1:12the recent cyber incident hitting a really prominent
- 1:15Australian brand. Gregory Jewelers. And, you
- 1:18know, it's a situation that fundamentally challenges
- 1:20how we even perceive security. Because when we
- 1:23look at this, we have a highly respected family
- 1:26owned legacy brand and they're suddenly dealing
- 1:29with a really sophisticated ransomware operator.
- 1:32Which has resulted in the theft of an absolutely
- 1:35massive trove of sensitive data, both corporate
- 1:38and consumer data. Yeah. And for you listening,
- 1:40whether you are an IT professional architecting
- 1:44network defenses or just, you know, someone who
- 1:46occasionally hands over personal details or retail
- 1:48register, this is really a masterclass in modern
- 1:50digital risk. It absolutely is. We're going to
- 1:52examine the mechanics of this breach. Map out
- 1:55the threat group. claiming responsibility this
- 1:58syndicate known as Kairos, and analyzed the real
- 2:01-world fallout of the data they stole. Mmm. Okay,
- 2:05let's unpack this by looking at the Target itself.
- 2:07Yeah, let's start there. Because the physical
- 2:09reality of Gregory Jewelers contrasts so sharply
- 2:13with what happened digitally. I mean, they're
- 2:15an Australian -owned retailer with, what, over
- 2:1745 years of heritage? Yeah, 45 years. They specialize
- 2:20in fine jewelry, watches, all of that. And their
- 2:24production is based right in the heart of Sydney's
- 2:26CBD. Right. And when you walk into one of their
- 2:29physical storefronts, the security is overt.
- 2:32It's, frankly, intimidating. Oh, for sure. You've
- 2:35got armed guards, reinforced glass cases, heavy
- 2:37steel vaults. High def cameras everywhere. You're
- 2:40essentially stepping into a fortress. Exactly.
- 2:42But to operate a modern retail business, especially
- 2:45one dealing with global supply chains and high
- 2:48net worth clients, that physical fortress has
- 2:50to connect to a digital infrastructure. And that
- 2:53is exactly where the Cairo's ransomware gang
- 2:55found their entry point. Yeah, they did. And
- 2:58they're claiming to have stolen a staggering
- 3:01574 gigabytes of data. Which is just an immense
- 3:05amount of data. It really is. And, you know,
- 3:08574 gigabytes might sound abstract to some people.
- 3:11If we were talking about raw 4K video files,
- 3:13maybe it wouldn't sound so catastrophic. Right,
- 3:15because video files are huge. Yeah. But when
- 3:18we are talking about text -heavy files, you know,
- 3:21spreadsheets, PDF scans, email archives, customer
- 3:25records. That's not just a few digital filing
- 3:28cabinets. No, not at all. That is essentially
- 3:30digital tractor trailers full of filing cabinets.
- 3:33We are talking about warehouses of concentrated,
- 3:36searchable, historical data. And that 45 year
- 3:39history of the company is actually a really critical
- 3:41factor in why the volume is so high. How so?
- 3:43Well, when a legacy business transitions through
- 3:46different eras of technology, you know, going
- 3:48from paper records to early databases in the
- 3:5190s to modern cloud environments. They just drag
- 3:54everything with them. Exactly. They carry an
- 3:56immense amount of technical debt. It's kind of
- 3:58like trying to build a state of the art titanium
- 4:01bank vault on top of a decaying wooden foundation.
- 4:04Wow. That's a great way to put it. You've got
- 4:07decades of accumulated customer interactions,
- 4:10old employee records, and just operational data
- 4:13sitting on servers. So the attackers aren't just
- 4:15getting today's transactions. They're getting
- 4:17the historical ledger of the entire business.
- 4:21Precisely. And this shows a real strategic shift
- 4:24in the ransomware economy. Right. Because they
- 4:28used to just go after tech companies. Yeah. Tech
- 4:30companies, big financial institutions, critical
- 4:32infrastructure. But those sectors have spent
- 4:35the last decade really hardening their defenses.
- 4:37So the syndicates are pivoting. Yeah. They are
- 4:40hunting where the money and the high net worth
- 4:42customer data reside in environments that might
- 4:46not have the same level of digital fortification
- 4:48as, say, a global bank. Right, which makes a
- 4:51luxury jeweler an incredibly lucrative target.
- 4:54The data they hold is tailor -made for exploitation.
- 4:58Oh, absolutely. Well, let's talk about that because
- 5:00the sheer volume of the data is just the beginning,
- 5:02right? The real shock comes when you look at
- 5:04what is actually inside those filing cabinets.
- 5:06Yeah, the contents are what matter. The reporting
- 5:09gives us a really clear look at the sample data
- 5:12that Kairos initially leaked. And they publish
- 5:15client personal information, customer purchase
- 5:17histories. Internal documents relating to an
- 5:21investigation. Yeah, that internal investigation
- 5:23stuff is sensitive. Really sensitive. And crucially,
- 5:27identity documents, including a passport. What's
- 5:30fascinating here is the potency of this specific
- 5:32combination. In cybersecurity, we actually refer
- 5:35to this as a data cocktail. A data cocktail.
- 5:38OK, I like that term. Yeah, because a single
- 5:40piece of data in isolation might just be mildly
- 5:44problematic, right? Like if someone steals a
- 5:46list of email addresses, it's a nuisance. more
- 5:48spam sure but when you mix specific high -value
- 5:52data points together the resulting cocktail becomes
- 5:55incredibly lethal for the victim but wait I want
- 5:59to push back on this for a second because I think
- 6:00a lot of people listening might find this part
- 6:02jarring okay it makes complete sense that a company
- 6:04has employee files but a customer's passport
- 6:08alongside their jewelry purchase history. That
- 6:11feels intensely personal. Honestly, it feels
- 6:14like a massive overreach just for buying a necklace.
- 6:17It does feel intrusive. But there are strict
- 6:21mechanical reasons for it in the luxury sector.
- 6:24Really? Like what? Well, first, you have international
- 6:26travelers using the tourist refund scheme. Oh,
- 6:29to claim back taxes. Right. And that legally
- 6:32requires the retailer to process and verify international
- 6:35identity documents. Oh, OK. And secondly, and
- 6:38this is probably more important, are the anti
- 6:40-money laundering regulations, the AML laws.
- 6:43Of course. If an individual walks into a boutique
- 6:45and wants to buy a $100 ,000 watch with cash
- 6:48or even a wiretrap, the jeweler is legally obligated
- 6:52to verify exactly who that person is. So they
- 6:54have to prevent the laundering of illicit funds.
- 6:57Yes. To comply with the law, the retailer has
- 7:00to scan and store the most sensitive identity
- 7:02document a person has. Wow. But then the vulnerability
- 7:06arises once that scan enters the digital ledger.
- 7:09Exactly. If that storage environment isn't heavily
- 7:12segmented and, you know, encrypted, it becomes
- 7:16a major target. And Kairos understands exactly
- 7:18how to weaponize that combination. Because a
- 7:21purchase history alone is bad. But pairing a
- 7:24luxury purchase with a passport creates a really
- 7:28severe extortion threat. It creates a two -pronged
- 7:30extortion model. How does that work? Well, the
- 7:33primary extortion targets the corporate entity,
- 7:36right? Pay us the ransom or we destroy your reputation
- 7:39and you get hit with massive regulatory fines.
- 7:42Right. The standard corporate shakedown. Yeah.
- 7:44But the secondary extortion vector targets the
- 7:47clients directly. Oh, wow. Yeah. The attackers
- 7:49cross -reference the purchase history with the
- 7:52contact details and they reach out to the high
- 7:54net worth individual. They essentially say, we
- 7:56have your passport. We know you bought a $50
- 7:59,000 diamond ring last Tuesday. Pay us in crypto
- 8:02or we publish your identity and your assets to
- 8:05the world. That is just a terrifying level of
- 8:07leverage. It really is. But there's this strange
- 8:10detail in the reporting about this specific leak.
- 8:14At the time of the reporting, the listing for
- 8:17Gregory Jewelers, along with that terrifying
- 8:19sample of passports and purchase histories, it
- 8:22had completely vanished from the Cairo's dark
- 8:24web leak site. Yeah, and that vanishing act is
- 8:26actually a very calculated move. Really? Because
- 8:29from a layman's perspective, if the listing disappears,
- 8:33it kind of looks like the hackers just packed
- 8:34up and gave up. No, they do not walk away from
- 8:37leverage. We have to look at this through the
- 8:40lens of standard ransomware playbooks. When a
- 8:43threat group publicly posts a victim in a sample,
- 8:47it's a demonstration of capability. They are
- 8:49proving they actually breached the network. Right.
- 8:52Showing their hand. Exactly. So when that listing
- 8:54is removed, it's almost always a signaling mechanism.
- 8:57It typically means the victim company has opened
- 8:59a channel of communication. You know, negotiations
- 9:01have begun. Oh, so it's not a retreat. It's a
- 9:03temporary ceasefire. It's a show of conditional
- 9:06compliance. They take it down to prove they control
- 9:09the publication process. The implicit threat
- 9:11is basically, we proved we can publish it. We
- 9:14proved we can take it down. If you pay, it stays
- 9:17down. But if negotiations stall, it goes right
- 9:19back up. And the rest of the 574 gigabytes follows.
- 9:23Yeah. It is pure psychological pressure. That
- 9:27is incredibly manipulative. And if we're dealing
- 9:29with a group... employing these kinds of psychological
- 9:32and extortion tactics, we really need to look
- 9:35at who is pulling the strings. We do. Let's talk
- 9:37about Kairos. According to the threat intelligence
- 9:40firm CYJX, they are a relatively new operator.
- 9:44Very new. Yeah, they only announced their first
- 9:46victim in November 2024, yet they have already
- 9:49claimed over 80 victims. It's a massive scale
- 9:52-up. And apparently they're active on Russian
- 9:54language hacking forums, but they operate seemingly
- 9:57independently. No obvious links to older hacking
- 10:00groups. Right. But here's where it gets really
- 10:03interesting. Kairos has developed this recent
- 10:06fixation on Australia. Yeah, they really have.
- 10:08They targeted at least three Australian victims
- 10:10in April alone. And to really illustrate their
- 10:15ruthlessness, we have to look at their attack
- 10:17on Strata Republic. Yes. The Strata Republic
- 10:19case is a crucial case study here. They're a
- 10:22New South Wales -based property management company,
- 10:25right? And Kairos claimed 441 gigabytes of data
- 10:29from them. And this case strips away the abstract
- 10:33concept of a data breach. Yeah, because it shows
- 10:36the gritty, humiliating reality of their tactics.
- 10:39Exactly. When you look at what Kairos leaked
- 10:41from Strata Republic, it wasn't just boring corporate
- 10:44spreadsheets. No, it was deeply personal. They
- 10:46leaked an employee's letter of reprimand. They
- 10:48leaked tax reports that included tax file numbers.
- 10:51Which is huge. Let's look at why a tax file number,
- 10:55a TFN, is so prized. In Australia, your TFN is
- 10:59a foundational pillar of your financial identity.
- 11:01Right, you need it for everything. Yeah, if an
- 11:03attacker has your TFN, your full name, and a
- 11:06scanned copy of your driver's license, which
- 11:08Kairos... also leaked, they can impersonate you
- 11:10to the Australian Taxation Office. Oh, man. So
- 11:14they can lodge fraudulent tax returns. Yes, and
- 11:16route the refunds to themselves or open lines
- 11:19of credit. It takes months, sometimes years,
- 11:23to unwind that kind of identity theft. But they
- 11:26went even further than financial damage, right?
- 11:29Because of the most aggressive thing they leaked?
- 11:31was an inappropriate photograph. It was from
- 11:34a Christmas party featuring several men standing
- 11:37around a topless woman. If we connect this to
- 11:39the bigger picture, this is where we see the
- 11:42evolution of ransomware tactics. Kairos is weaponizing
- 11:46embarrassment. They're curating the leaks for
- 11:48maximum reputational damage. Exactly. They aren't
- 11:51just dumping unstructured data. They actively
- 11:54parse through thousands of emails and HR folders
- 11:57looking for the single most damaging reprimand
- 12:00or the most inappropriate photo. They want to
- 12:02inflict chaos. They want to prove to future victims
- 12:05like Gregory Jewelers that they are willing to
- 12:07play dirty. they have absolutely no moral boundaries.
- 12:10Which forces rushed decision making, right? Executives
- 12:13are panicking about what informal messages or
- 12:15photos might be on their servers. And panic usually
- 12:18leads to a ransom payment. Well, knowing this
- 12:21ruthless playbook, how is Gregory Jewelers actually
- 12:23responding to this high stakes pressure? They've
- 12:26issued an official statement. Right. The official
- 12:29line from the company confirms an unauthorized
- 12:31third party accessed part of their IT systems.
- 12:35Standard PR phrasing. Yeah. They say they're
- 12:38engaging independent experts and they've notified
- 12:40the Office of the Australian Information Commissioner,
- 12:43the OAIC, and the Australian Cyber Security Centre,
- 12:46the ACSC. Which means they are doing things by
- 12:49the book. And they also said they are communicating
- 12:51with staff and clients. But the phrase that stands
- 12:54out to me in their statement is, we are operating
- 12:56as usual. Yeah, operating as usual. It's like
- 12:59a duck on a pond, right? How do you mean? Well,
- 13:01gliding calmly on the surface for the customers
- 13:04walking into the boutique, but paddling furiously
- 13:06underwater to figure out the extent of the damage.
- 13:09That's a perfect analogy. So what does this all
- 13:11mean for their response team? It means breaking
- 13:14down the corporate response playbook. By involving
- 13:17the OAIC and ACSC, they are handling the regulatory
- 13:21and threat intelligence side. But the fact that
- 13:24they stated investigations into the type and
- 13:27extent of data impacted are ongoing, that means
- 13:30the true scope of the fallout is still a looming
- 13:33shadow. They don't actually know everything that
- 13:35was taken yet. Exactly. The physical storefront
- 13:38might be operating, but behind the firewall,
- 13:40the IT infrastructure is an active crime scene.
- 13:43The incident response team is trying to reverse
- 13:46engineer the attack while the attackers are holding
- 13:49that dark web listing over their heads. It's
- 13:52a nightmare scenario. It really is. And I think
- 13:54it leaves us with a provocative thought to mull
- 13:56over. What's that? Well, in an era where digital
- 13:59threat actors like Kairos can weaponize everything
- 14:02from a luxury watch receipt to an embarrassing
- 14:05party photo, the concept of a secure purchase
- 14:08extends way beyond the physical security of a
- 14:10jewelry store. Right. The armed guards don't
- 14:13matter if the server is open. Exactly. How much
- 14:15of our physical lives, you know, our identities,
- 14:17our movements, our purchases are inextricably
- 14:20linked to the digital ledgers of the business?
- 14:22as we frequent. Yeah, that is a really unsettling
- 14:25thought and an important one. We want to thank
- 14:27you for joining us to explore this topic. Yeah,
- 14:30thank you for listening. And if listening to
- 14:32this has you thinking about your own digital
- 14:34safety, maybe wondering how secure your own digital
- 14:37ledgers are, we highly encourage you to visit
- 14:39www .kinsoft .com .au to discuss your own security
- 14:44and IT needs. You definitely don't want to wait
- 14:46until a group like Tyrose finds you. Thanks for
- 14:49joining us, and we'll see you next time.