Latest / Tech Talks With Kinsoft / Metricon Homes Ransomware Attack and Orange France System Breach
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Great to
- 0:02be here. Today we're going to unpack some, well,
- 0:04pretty significant cybersecurity incidents that
- 0:07have happened recently. Yeah, things that offer
- 0:09some really crucial lessons for, you know, pretty
- 0:11much everyone navigating the digital world. Exactly.
- 0:14We want to look beyond just the headlines. Right.
- 0:16Try to understand the patterns, maybe the broader
- 0:19implications of these threats, especially for
- 0:21industries going through rapid digital changes.
- 0:25Okay, so let's jump straight into a big one.
- 0:27The Metricon Homes ransomware attack. Ah, yes,
- 0:31Metricon, Australia's largest home builder. They
- 0:34confirmed they were hit by the Quillen ransomware
- 0:37group. This was discovered around July 24th,
- 0:402025. Though the attack itself probably started
- 0:43a few days earlier, maybe July 21st. And the
- 0:46scale of this breach. Yeah. What did we find
- 0:49out? Well, it was quite alarming actually. The
- 0:51attackers, Quillen, claim they took about 128
- 0:54gigabytes of sensitive data. Wow, 128 gigs, that's
- 0:58a lot. It really is, over 98 ,000 files. And
- 1:00it wasn't just random data either. No, what kind
- 1:03of stuff? We're talking confidential financial
- 1:05documents, proprietary architectural plans. Think
- 1:08about the IP value there. Huge. Internal marketing
- 1:11strategies, company credits, even employee details,
- 1:14credit card receipts, finance and HR info, profit
- 1:18and loss statements, staff salaries, commission
- 1:21rates. So really sensitive internal information.
- 1:24Extremely. And the hackers gave them a deadline,
- 1:26right? Seven days to meet demands or they'd publish
- 1:29it all. Okay, so that's the threat. How did Metricon
- 1:32reportedly handle it? Well, First Public Statements
- 1:35mentions swift containment, bringing in external
- 1:38experts. They claimed no impact on safety or
- 1:41construction, that internal systems were back
- 1:43online, payments going through normally, you
- 1:46know, the standard. response playbook. And they
- 1:48notified the authorities. Yes. The Australian
- 1:50Cybersecurity Center, the ACSC, also the Office
- 1:53of the Australian Information Commissioner, the
- 1:55OAIC and law enforcement. All the right boxes
- 1:57ticked, seemingly. Is there more to it when a
- 2:00company this size gets hit, especially by this
- 2:03Quillen group? Absolutely. While, you know, swift
- 2:06containment is good, it suggests they had some
- 2:08kind of incident response plan. Right. The fact
- 2:11this breach happened and with this much data
- 2:13extracted by Quillen. That's significant. Quillen
- 2:17is apparently the third most active ransomware
- 2:20group globally right now. Third most active.
- 2:23Wow. Yeah, something like 625 claimed victims
- 2:26since August 2022. They're a Russian speaking
- 2:29group operating what's called Ransomware as a
- 2:32Service or RAIS. RAIS, Ransomware as a Service.
- 2:34So they build the tools and let others carry
- 2:36out the attacks. Exactly. Like a franchise model
- 2:39for cybercrime. They provide the malware, the
- 2:41infrastructure, and affiliates lease it to launch
- 2:43attacks. itself was first spotted back in July
- 2:462022. So pretty sophisticated operation then.
- 2:49In terms of impact and organization, yes. But
- 2:51what's really interesting is how they often get
- 2:53in. Okay. Despite the scale of attacks like Metricon,
- 2:56their initial access often relies on pretty,
- 2:59well, basic methods. Phishing, spear phishing.
- 3:02Malicious emails, messages. Yeah. That kind of
- 3:04thing. Exactly. Or exploiting known vulnerabilities
- 3:08in common software like Citrix or remote desktop
- 3:11protocol, RDP. Things that should be patched.
- 3:14So it's not always some super complex zero -day
- 3:17exploit. Often not. It really highlights that
- 3:20even these major threat actors frequently rely
- 3:22on fundamental weaknesses. You know, human error
- 3:25or just basic security hygiene like patching.
- 3:28That's a really important point. The entry point
- 3:30doesn't always reflect the eventual damage. Precisely.
- 3:34And for you listening, this matters because it
- 3:35goes beyond just Metricon's immediate problems.
- 3:38Think about those stolen architectural plans.
- 3:41Competitors could gain huge strategic advantages.
- 3:44It could undermine their competitive edge for
- 3:46years, long after the breach is supposedly contained.
- 3:49It shows the long -term risks. Definitely. The
- 3:52long tail of a data breach. Which brings us to
- 3:54the construction industry itself. Metricon is
- 3:57a huge player. But why does this sector seem
- 4:01so, well, appealing to cyber criminals? Is it
- 4:04just about ransomware? That's a great question.
- 4:07It's not just ransomware. And construction has
- 4:09this sort of unique mix of factors making it
- 4:11a prime target. Okay, like what? Well, first
- 4:13off, high value transactions. Construction projects
- 4:17involve enormous sums of money. Contracts. Payments.
- 4:21Millions. Easily. Right. So that makes it ripe
- 4:23for ransomware demands, sure. But also phishing
- 4:26aimed at diverting payments, financial fraud.
- 4:29The potential payout is just huge. Makes sense.
- 4:33What else? Second, the sheer amount of sensitive
- 4:35data they handle. Blueprints, designs, bids,
- 4:39contracts, employee details, client information.
- 4:41All valuable on the dark web. Absolutely. For
- 4:44identity theft, corporate espionage, or like
- 4:46we said, giving competitors an edge. Okay. Transactions,
- 4:49data. What's number three? Third, and this is
- 4:53a big one for construction, complex supply chains.
- 4:56Projects involve tons of stakeholders, main contractors,
- 5:00subcontractors, suppliers. Right. Hundreds of
- 5:02different companies potentially involved in one
- 5:04project. Exactly. And they all have different
- 5:06levels of cybersecurity maturity. A hacker might
- 5:09breach a smaller, less secure vendor. Like an
- 5:11HVAC company or something. Yeah, precisely. And
- 5:14use that as a stepping stone into the main contractor's
- 5:16network. It's the classic weakest link problem.
- 5:19That makes the whole ecosystem vulnerable. Very
- 5:21much so. Then fourth, you often find outdated
- 5:25cybersecurity measures. Legacy systems. Old software.
- 5:29Yeah, especially maybe in smaller firms. Systems
- 5:32that just don't have protection against modern
- 5:34threats. Easy targets for hackers scanning for
- 5:37known vulnerabilities. We're not always talking
- 5:40cutting edge attacks here. Just unpatched systems
- 5:43sometimes. Sometimes, yes. And finally, there's
- 5:45the increasing digitalization. Ah, the move towards
- 5:48more tech. BIM software, IoT sensors, cloud platforms.
- 5:53Right. All these things boost efficiency, which
- 5:55is great. But adopting them quickly can mean
- 5:57security sometimes lags behind. Expanding the
- 6:00attack surface. Dramatically. Every connected
- 6:02device, every cloud service, every remote worker
- 6:04is a pinch of entry point if not secured properly
- 6:07from the start. It's a double -edged sword. More
- 6:09efficiency, but also more risk. That paints a
- 6:12really clear picture. High value, rich data,
- 6:15complex chains, maybe lagging security, and rapid
- 6:18tech adoption. A perfect storm almost. It can
- 6:20be, yeah. So ransomware gets the headlines, but
- 6:24you mentioned other threats. What else are we
- 6:26seeing frequently targeting industries like construction
- 6:29and others? Oh, absolutely. Ransomware is visible,
- 6:32but there's a whole toolkit attackers use. Phishing
- 6:35is still huge. We mentioned that as an entry
- 6:37point for Quillen. Exactly. Tricking users into
- 6:40giving up info via email, texts, sometimes even
- 6:44voice calls now. That's called phishing. Voice
- 6:46phishing. Okay. It works well in construction
- 6:48with lots of temporary staff or subcontractors
- 6:50who might not know the usual protocols. It's
- 6:52like getting a fake urgent request from head
- 6:54office. Precisely. And it's not just small companies.
- 6:57Even Google got hit by vishing recently. The
- 7:00shiny hunters group used it back in June to steal
- 7:02business contact info from Google Salesforce.
- 7:05Google. Wow. Shows anyone can be vulnerable to
- 7:09that social engineering side. It really does.
- 7:10Then there's business email compromise or BEC.
- 7:14That's the one where they impersonate the CEO
- 7:16or someone. Exactly. Pretending to be a senior
- 7:19person to request a fraudulent wire transfer
- 7:21or sensitive data. Very totent in construction
- 7:24because of the large sums changing hands constantly.
- 7:27Fake invoices, requests to change bank details
- 7:30happens all the time. Scary stuff. Then supply
- 7:33chain attacks, which we touched on. Getting into
- 7:36your network via a less secure partner. Right.
- 7:38Emphasizing the need to. Vet vendors. Definitely.
- 7:41And distributed denial of service, DDoS attacks,
- 7:45flooding a network to knock it offline. Disrupting
- 7:48operations. Maybe demanding a ransom to stop.
- 7:51Correct. We saw a big example just recently with
- 7:53Orange, France. The big mobile provider. Yeah,
- 7:55huge. Serves like 290 million customers across
- 7:58Europe and Africa. They detected an attack on
- 8:01an internal system around July 25th. What happened?
- 8:03Caused significant service disruptions, mainly
- 8:05in France, for both business and consumer customers.
- 8:08And it happened amid worries about state -sponsored
- 8:11threats and telecoms, so it raised questions
- 8:13about espionage, too. So disruption and potentially
- 8:17something more sinister. Potentially. And just
- 8:21quickly, other recent things. Over 200 ,000 New
- 8:25Zealand government and health credentials found
- 8:27on the dark web. Massive personal data exposure.
- 8:31Huge. But on a brighter note, there was the global
- 8:34takedown of the Black Suit ransomware group.
- 8:37Ah, good news for a change. Yeah. They'd apparently
- 8:39extorted over half a billion dollars from about
- 8:42184 victims. So law enforcement is fighting back,
- 8:46but the threats are relentless. Wow. OK, that's
- 8:49quite a landscape of threats. So putting it all
- 8:52together for businesses listening, especially
- 8:53those in vulnerable sectors like construction,
- 8:56what are the absolute must do cybersecurity practices?
- 9:00What's non -negotiable? Right. How do you build
- 9:02resilience? It really comes down to a layered
- 9:04approach. Several key things. First, and maybe
- 9:07the most fundamental, employee training and awareness.
- 9:11Continuously. Not just a once a year thing. Absolutely
- 9:13not. Regular training on spotting, phishing,
- 9:15social engineering, understanding company policies.
- 9:18Your people are your first line of defense, but
- 9:20they need the knowledge. Makes sense. What's
- 9:22next? Multi -factor authentication. MFA. It's
- 9:25not optional anymore. The code to your phone
- 9:27thing. Yeah, adding that extra layer beyond just
- 9:29a password. But you also need to guard against
- 9:32ways attackers try to bypass it, like MFA fatigue
- 9:35attacks, where they spam you with requests. It
- 9:38needs to be everywhere. Okay, MFA is critical,
- 9:40then. Regular software updates and patch management
- 9:42keep everything current. Operating systems, applications.
- 9:46Close those known security holes. Exactly. So
- 9:50many breaches exploit known, unpatched flaws.
- 9:53It's basic hygiene, but crucial. Got it. Patching.
- 9:57What else? Network segmentation. This is about
- 10:00dividing your network into smaller isolated zones.
- 10:03So if one part gets breached. It doesn't automatically
- 10:06give the attacker access to everything. It contains
- 10:09the damage, limits their ability to move laterally.
- 10:12It's part of a zero trust mindset. Smart. Slows
- 10:14them down. Right. Then strict access controls.
- 10:17The principle of least privilege. Only give people
- 10:19access to what they absolutely need for their
- 10:21job. Precisely. Limit who can see or touch sensitive
- 10:25data. Okay. And protecting the data itself. Data
- 10:27encryption, both when it's stored and when it's
- 10:30being transmitted, makes it unreadable even if
- 10:33stolen, unless they have the key. Like locking
- 10:35it in a safe. Good analogy. And speaking of safety
- 10:38nets. Robust data backup and recovery systems.
- 10:42Having copies stored securely offsite. Yes, and
- 10:45regularly testing that you can actually restore
- 10:47from those backups. Essential for bouncing back
- 10:50quickly from ransomware or other data loss events.
- 10:53Minimizes downtime. Crucial for business continuity.
- 10:57Very. Also, vendor and supply chain management.
- 10:59Really vetting your partner's security practices.
- 11:02Remember the weakest link. Right, that supply
- 11:04chain risk again. And finally, having an incident
- 11:06response plan and actually test. Testing it.
- 11:08Practice drills. Tabletop exercises. Exactly.
- 11:12Knowing who does what, who to call, how to isolate
- 11:14systems before an attack happens makes the response
- 11:17much smoother and more effective. Don't wait
- 11:19for a crisis to figure it out. That's a really
- 11:21comprehensive list. Training, MFA, patching,
- 11:24segmentation, access control, encryption backups,
- 11:27vendor management and planning. Seems like a
- 11:29solid defense. It provides layers. No single
- 11:33thing is foolproof. But together, they build
- 11:36strong resilience. But even with all that, no
- 11:39system is perfect, right? What's the final safety
- 11:42net? the thing that helps when the worst still
- 11:44happens. Yeah, that's where cyber insurance comes
- 11:46in. And it's important to see it as part of the
- 11:49overall strategy, not a substitute for good security.
- 11:52Right. It doesn't prevent attacks, but helps
- 11:54manage the aftermath. Exactly. It helps mitigate
- 11:57the financial fallout, covers things like business
- 11:59interruption costs, data recovery expenses, legal
- 12:02fees, PR help, things that might not be covered
- 12:06by your general liability insurance. So it fills
- 12:08specific cyber related gaps. Yes. And a really
- 12:11valuable part of many policies is access to expert
- 12:15panels. Specialists. Yeah. Like forensic IT lawyers.
- 12:18Precisely. Pre -vetted experts you can call on
- 12:21immediately during a crisis. That can be invaluable
- 12:24for managing the incident quickly and effectively,
- 12:26protecting your operations, your reputation,
- 12:28and your finances. Makes sense to have that expert
- 12:31help on standby. Definitely. But policies vary
- 12:33a lot, so it's really important to talk to a
- 12:35licensed insurance professional to get the right
- 12:37coverage for your specific business and risks.
- 12:40Good advice. So wrapping up then, these incidents,
- 12:45Metricon, Orange, France, they really show that
- 12:48cyber techs are, well, a constant evolving threat.
- 12:51Across all industries. And having strong layered
- 12:54cybersecurity practices isn't just a nice to
- 12:57have anymore. It's absolutely essential. Non
- 13:00-negotiable, really. And maybe a final thought
- 13:02to leave people with. Yeah. As everything gets
- 13:04more digital. And AI gets woven deeper into,
- 13:08well, everything. How do we all organizations,
- 13:11individuals adapt, not just to use these new
- 13:14technologies, but to actually secure them against
- 13:16these really sophisticated and persistent risks?
- 13:19That's a big question. Securing the future as
- 13:21we build it. Yeah, it's the challenge ahead.
- 13:23Definitely something to think about. If you,
- 13:25our listener, are interested in discussing your
- 13:26own security and IT needs, you can find more
- 13:29information and speak with experts over at www
- 13:32.kinsoft .com .au. They can certainly help navigate
- 13:35these challenges. Well, thanks for joining us
- 13:37today on Tech Talks with Kinsoft. My pleasure.
- 13:40We look forward to our next discussion.