Latest / Tech Talks With Kinsoft / Unpacking the January 2026 Prosura Data Breach
Transcript
- 0:00Hello and welcome to Tech Talks with Kinsoft.
- 0:02Great to be here. Yeah, it's late February 2026
- 0:07and I think it's safe to say the year has kicked
- 0:10off with just a massive deafening wake up call
- 0:15for Australian data security. Oh, absolutely.
- 0:17It really has. Like if you were one of those
- 0:19optimistic people who thought, hey. You know,
- 0:22maybe things will cry it down after the chaos
- 0:24of the last few years. Well, the first eight
- 0:27weeks of 2026 have effectively looked at that
- 0:29optimism and said. Absolutely not. It really
- 0:32has been a relentless start to the year. I mean,
- 0:35I've been staring at the reports on my desk all
- 0:37week, and the sheer volume is overwhelming. It's
- 0:41nuts. We aren't just seeing more attacks. We're
- 0:43seeing a shift in tactics, a shift in targets,
- 0:45and frankly, a shift in the level of aggression
- 0:48from threat actors. Yeah. It just feels different
- 0:51this time. It definitely feels personal, and
- 0:53that is exactly what we're going to unpack for
- 0:55you today. Our mission on this show is simple.
- 0:58We take a huge stack of recent sources. So we're
- 1:00talking news reports, company statements, forum
- 1:03discussions, breach notifications. A whole lot.
- 1:06Exactly. And we extract the critical nuggets
- 1:08of knowledge for you. We aren't just reading
- 1:10headlines. We are really doing a deep dive into
- 1:13what this means for your data, your business,
- 1:15and honestly, your sanity. And for today's discussion,
- 1:19we are focusing on a specific case study that
- 1:21really... I think it really illustrates this
- 1:23new reality, the Pursura data breach that came
- 1:27to light in January. Right. Because on the surface,
- 1:30it might sound like just another corporate press
- 1:32release, you know, an insurer gets hit, data
- 1:34gets taken. But the specific details of how these
- 1:37attackers behaved are crucial. It is a wild story.
- 1:40But we aren't stopping there. We're going to
- 1:42broaden the scope and look at how Prosura fits
- 1:45into this chaotic start to 2026. Yeah, including
- 1:48that massive UX fintech breach that just broke.
- 1:51Exactly. We are asking the big question here.
- 1:54What does this mean for anyone trusting companies
- 1:56with their ID? It's a heavy topic, but an important
- 1:59one. So let's get right into it. First up, let's
- 2:03establish the facts regarding Prosura. Okay.
- 2:05Who are they? I feel like a lot of people might
- 2:09not recognize the name immediately. That's a
- 2:11very fair point. Prosura is an Australian financial
- 2:14services company. They specialize in rental vehicle
- 2:18excess insurance. Right. You might actually know
- 2:21them better by their trading name, which is Hiccup.
- 2:23Right, Hiccup. But here's where it gets really
- 2:26tricky for the average consumer. Prosura is a
- 2:29key partner for the comparison site Vroom Vroom
- 2:32Vroom. Exactly. And that right there is your
- 2:35first big lesson in supply chain complexity.
- 2:38Yeah. A lot of people who booked rental cars
- 2:41through Vroom Vroom Vroom ended up having their
- 2:43data sitting with Pursura. Even if they didn't
- 2:45know it. Even if they didn't realize they were
- 2:47dealing with Pursura directly at all. You book
- 2:49on one site, but your data lives on another.
- 2:51So unauthorized access was confirmed. Walk us
- 2:54through the timeline here. How did this actually
- 2:56go down? Well, it happened right as everyone
- 2:58was recovering from New Year's Eve. Prasura detected
- 3:01unauthorized access to their IT systems on January
- 3:043rd. And to their credit regarding containment,
- 3:08they moved fast. They took their policy purchase
- 3:12portals and their claims management systems offline
- 3:14immediately to stop the bleeding. But then we
- 3:17get into the numbers game. And looking at these
- 3:19reports, this is where it gets incredibly confusing
- 3:22for people. Because security researchers estimated
- 3:24about 300 ,000 individuals were affected. Which
- 3:29is a substantial number. It is. But then the
- 3:32attackers went on to a data leak forum and claimed
- 3:35they had... Get this, 98 million lines of records.
- 3:38Right. 98 million sounds absolutely catastrophic.
- 3:41It does, and it's designed to sound exactly that
- 3:43way. But we have to be very careful with what
- 3:45I like to call hacker math. Hacker math. I love
- 3:48that term. Explain that for us. So that 98 million
- 3:51figure likely refers to raw database rows. We
- 3:54are talking about server logs, transaction history
- 3:57entries, system events. Okay, so not individual
- 3:59people. Exactly. Think about it this way. If
- 4:02you are a customer, you might have one entry
- 4:05for your name. another for your policy start
- 4:07date another for a payment log another for a
- 4:11change of address right so one single person
- 4:14could generate hundreds of lines of data i see
- 4:17so 98 million lines does not equal 98 million
- 4:20people precisely it's marketing spin threat actors
- 4:24inflate these numbers to increase pressure on
- 4:26the victim company To scare them. To scare them
- 4:29and to make the data look way more valuable to
- 4:32other criminals on the dark web. They are trying
- 4:34to sell a product after all. That makes sense.
- 4:37However, I do want to be clear. For the 300 ,000
- 4:40people who were actually affected, that distinction
- 4:42doesn't make it any less painful. No, absolutely
- 4:45not. And speaking of painful, let's talk about
- 4:47the tactics. Because this wasn't just a steal
- 4:49the data and run situation. No, it wasn't. This
- 4:52is where the story gets chilling and, frankly,
- 4:54where it deviates from the standard script we're
- 4:56used to seeing. This is the part that really
- 4:58stands out in the 2026 landscape. The threat
- 5:01actors didn't just exfiltrate the database. They
- 5:04used the stolen email addresses to contact the
- 5:06victims directly. I saw this. We pulled a Geekzone
- 5:10forum thread for this deep dive. And there was
- 5:13a user, Kiwi Harry, who shared the actual email
- 5:17they received from the hackers. Yes. And it wasn't
- 5:20your standard phishing email full of bad grammar
- 5:22and typos. It was surprisingly coherent. It was
- 5:26incredibly manipulative. The hackers claimed
- 5:29that they had originally tried to contact Prasura
- 5:31to patch this issue and claim a bug bounty. Just
- 5:34to clarify for the listener, a bug bounty is
- 5:36usually a legitimate program, right? Where ethical
- 5:38hackers get paid for... Finding security holes?
- 5:41Correct. That's a standard industry practice.
- 5:43But these guys were framing themselves as helpful
- 5:46researchers who were simply ignored by the company.
- 5:49Right. They claimed Pursura wouldn't listen,
- 5:51so they were essentially forced to go public
- 5:52to the customers. Right. I actually have the
- 5:54quote right here from that email. They wrote,
- 5:56Your trust has already been broken. The company
- 5:59failed to act even after being warned. They basically
- 6:02tried to turn the customers into a weapon against
- 6:05the company's own HR team. It's pure psychological
- 6:08warfare. By framing themselves as frustrated
- 6:11bug bounty hunters who were forced to leak the
- 6:14data, they try to shift the moral blame entirely
- 6:16onto the victim company. That's insidious. It
- 6:20is. They urge customers to pressure Prozora.
- 6:23It creates mass panic, which puts immediate leverage
- 6:26on the victim organization to pay up or negotiate.
- 6:30And the user, Kiwi Harry, noted that the email
- 6:32contained accurate policy numbers, dates, and
- 6:35even links to view invoice that actually matched
- 6:37the real URLs. Yes. It looked terrifyingly legitimate.
- 6:41That is the kicker, even though it came from
- 6:43a ProtonMail address. Which is encrypted, right?
- 6:45Yeah, an encrypted email service often used by
- 6:47privacy advocates, but heavily used by criminals,
- 6:50too. But the inclusion of that specific, accurate
- 6:53data makes it very hard for a layperson to just
- 6:56dismiss it as spam. Right. It proves they have
- 6:58the goods. Exactly. So they have the goods. What
- 7:00exactly did they get? Because Presura came out
- 7:02fairly quickly and said no credit card data was
- 7:05accessed. That is correct. Presura doesn't store
- 7:08credit card details on their end, so payment
- 7:10information was technically safe. However, what
- 7:13they did lose is arguably just as dangerous in
- 7:16the long run. We are looking at names, emails,
- 7:19phone numbers, travel destinations, and policy
- 7:21dates. But there's a sensitive tier here too,
- 7:24right? This is the part that really worries me.
- 7:26Unfortunately, yes. For customers who had actually
- 7:29filed a claim. So if you had an accident in your
- 7:31rental car. Exactly. If you filed a claim. The
- 7:34breach included driver's licenses and images
- 7:37related to that team. Driver's licenses. I feel
- 7:39like we often gloss over that when we hear about
- 7:41breaches, but that is the absolute golden ticket
- 7:45for identity theft. It is extremely high value
- 7:48data. Think about it. A credit card gets stolen.
- 7:51It can be canceled and replaced in 24 hours.
- 7:54Right. The bank reverses the charges. You get
- 7:56a new card. Your life goes on. Exactly. But a
- 7:58driver's license, that is a primary identity
- 8:01document. Yeah. It is used for know your customer
- 8:04or KYC checks at banks. It's used for setting
- 8:08up phone contracts, for applying for personal
- 8:10loans. So if a criminal has a high res scan.
- 8:13of my license. They can bypass a huge amount
- 8:16of security filters at other institutions. They
- 8:18essentially become you. Wow. And unlike a credit
- 8:20card, you can't just cancel your date of birth
- 8:22or your license number easily. That data sticks
- 8:25with you. That explains the massive operational
- 8:28impact, too, because Prozura had to shut down
- 8:31new sales and their self -service portal for
- 8:34weeks. I don't think they posted a restoration
- 8:37update until mid -January. That is a significant
- 8:39business disruption. Massive. You're talking
- 8:42about weeks of zero revenue from new sales combined
- 8:45with a reputational hit. It shows that even if
- 8:48you don't lose credit card data, the operational
- 8:50cost of a breach like this is immense. And the
- 8:53scary thing is, ProZero wasn't the only one having
- 8:55a bad start to the year. This feels like it's
- 8:57part of a much bigger wave. It certainly is.
- 9:00If we pivot to the broader landscape, 2026 is
- 9:03rapidly shaping up to be the year of the breach
- 9:05in Australia. Because just a few weeks after
- 9:08the Presura news kind of settled down, we got
- 9:11hit with the UX breach in February. Tell us about
- 9:14that one. UX is a fintech company, right? Correct.
- 9:17A Sydney -based fintech. And this one was arguably
- 9:20worse in terms of pure volume. They exposed the
- 9:24personal and financial details of 444 ,538 Australian
- 9:30borrowers. Nearly half a million people. Yes.
- 9:33And looking at the technical notes we have here,
- 9:35the cause was entirely different, too. Brazura
- 9:38was unauthorized access, an active hack. What
- 9:42happened to UX? UX appears to be a case of severe
- 9:45misconfiguration. It wasn't necessarily a sophisticated
- 9:48break -in where some hacker cracked an encrypted
- 9:50code. Okay. It was an unsecured database, specifically
- 9:54a MongoDB Atlas cluster. Right. And it was left
- 9:57open and accessible to the public internet for
- 9:59at least 10 months. 10 months. 10 months. That
- 10:02is an eternity in cyber time. And just so we're
- 10:04completely clear for the listener, when you say
- 10:06unsecured MongoDB cluster... what are we actually
- 10:08picturing here imagine leaving a giant filing
- 10:11cabinet full of loan applications on the sidewalk
- 10:13outside your office unlocked 24 7. anyone walking
- 10:18past who knows what a filing cabinet looks like
- 10:20can just pull open a drawer and take whatever
- 10:22they want wow that is effectively what happened
- 10:24on the internet it requires zero hacking skills
- 10:27to access if you just know where to look and
- 10:29the data hall was massive huge 141 gigabytes
- 10:33good grief containing loan applications residential
- 10:36addresses and again those highly valuable driver's
- 10:39licenses and it affected borrowers across a hundred
- 10:42different lenders because ux acts as an intermediary
- 10:45so again we have that supply chain issue Exactly.
- 10:48You might not even know who UX is, but your lender
- 10:50used them and now your data is gone. So we have
- 10:53a hack at an insurer and a wide open door to
- 10:56fintech. But looking at the list of incidents
- 10:59from January and February 2026, it really seems
- 11:02like no sector is safe right now. It is completely
- 11:04indiscriminate. Look at January. The Victorian
- 11:07Department of Education confirmed a breach impacting
- 11:091 ,700 government schools. Wow. Then you have
- 11:12Regis Resources, which is a major gold producer,
- 11:15confirming a cyber attack. Gold mines in schools.
- 11:19You seriously couldn't pick two more different
- 11:21industries. Right. And let's not forget hospitality.
- 11:25Oh, yeah. Seagrass. Seagrass Boutique Hospitality
- 11:27Group was claimed by the Cairo's ransomware gang
- 11:30in February. And then the Aeromedical Society
- 11:32of Australasia was hit by lock bit. That is just
- 11:36a terrifying mix. Emergency medical services,
- 11:39restaurants, mining, education. So when you look
- 11:43at all these reports on your desk, what patterns
- 11:45are actually emerging? What is the trend for
- 11:472026? There are two main trends emerging from
- 11:50this chaos. The first is a major shift in the
- 11:53endgame. What do you mean by endgame? Well...
- 11:56We used to see a lot of encryption -only ransomware.
- 11:59Right. Where they just lock your computers, encrypt
- 12:01your files, and demand money to give you the
- 12:03decryption key. Yeah, the classic ransomware
- 12:05model. Exactly. But now we're seeing a massive
- 12:08shift toward data theft and extortion. So it's
- 12:11less about give us money to get your service
- 12:12back and more about give us money or we tell
- 12:15everyone your secrets. Precisely. It is what
- 12:17we call double extortion or sometimes extortion
- 12:19only. The Prasura case is a prime example of
- 12:22this. Right. They stole the data and immediately
- 12:25started leveraging the customers to force a payout.
- 12:28They don't even need to encrypt your network
- 12:30if they can cause enough panic among your user
- 12:32base. It makes total sense because companies
- 12:35have gotten so much better at backups over the
- 12:37last five years. So locking the computers isn't
- 12:40quite as scary as it used to be. Exactly. You
- 12:42just restore from a backup. But leaking the data.
- 12:45You can't undo that with a backup. No. Once the
- 12:48toothpaste is out of the tube, you cannot put
- 12:50it back. And the second big trend. Supply chain
- 12:54risk. We've touched on that a bit. Yeah, we saw
- 12:56it with Pursura affecting the Vroom Vroom customers.
- 12:59We saw it with UXitat affecting borrowers across
- 13:02100 different lenders. You might really trust
- 13:05the company you are buying from, but do you trust
- 13:08the third -party insurer they use? Or the fintech
- 13:11platform processing the loan in the background.
- 13:14Exactly. That is the really scary part for consumers.
- 13:17You can have great personal security, but if
- 13:19your partner leaves the back door open, you are
- 13:22still in trouble. Which brings us to the big
- 13:24takeaway for our listeners. Why does this keep
- 13:27happening? Is the technology failing or are we
- 13:30failing the technology? Yeah, let's get technical
- 13:32for a second. What are the actual failing points
- 13:34inside these organizations? Based on the deep
- 13:37dive into these reports, it essentially comes
- 13:39down to two somewhat boring but absolutely critical
- 13:42concepts, identity and access management or IAM
- 13:45and data segregation. Okay, let's unpack those.
- 13:48Start with IAM. Right. So in the Pursura case,
- 13:50it was unauthorized access. That usually implies
- 13:53weak access controls. Like bad passwords? Yeah,
- 13:56maybe single -factor authentication or credentials
- 13:59that were stolen somewhere else and reused. If
- 14:02you have strong IAM, like mandatory multi -factor
- 14:05authentication, strictly limiting who can log
- 14:08in from where, it's so much harder for an attacker
- 14:11to just walk in the front door. And data segregation,
- 14:13that sounds like what? Putting things in different
- 14:15boxes? That is exactly what it is, about limiting
- 14:18the blast radius of a breach. Blast radius, right.
- 14:21If an attacker gets into your front -end web
- 14:23portal, should they be able to automatically
- 14:25access the entire back -end database of driver's
- 14:28license images? Definitely not. Ideally, no.
- 14:32Those images should be segmented, highly encrypted,
- 14:35and kept in a completely separate, highly secure
- 14:37zone. Which didn't happen with UX. Right. In
- 14:40the UX case, leaving a massive MongoDB cluster
- 14:43open to the internet suggests a total failure
- 14:46of both segregation and configuration management.
- 14:49Everything was just there, together. It sounds
- 14:52like basic IT hygiene, but clearly it is being
- 14:56missed at a very high level. It is often sacrificed
- 14:59for speed or ease of access. Developers want
- 15:02the data to be easy to query, to build apps faster.
- 15:05But in 2026, the price of that convenience is
- 15:07becoming unbearable. Let's talk about that price,
- 15:10the aftermath. Yeah. Coursera responded by notifying
- 15:12the ACSC, the Australian Cyber Security Center,
- 15:15and the OAIC. But there was a bit of a dilemma
- 15:18with their transparency, wasn't there? There
- 15:20was. And this is a nightmare scenario for any
- 15:22crisis communications team. Because Pursura eventually
- 15:25set up an incident page and confirmed the breach,
- 15:28but the attackers beat them to the punch. Exactly.
- 15:32When the very first time your customer hears
- 15:34about a breach is from the criminal who stole
- 15:37their data, you have completely lost control
- 15:39of the narrative. Yeah, you look terrible. It
- 15:41causes immediate panic and severe reputational
- 15:44damage. It makes the company look incompetent
- 15:46or even worse, like they were actively trying
- 15:48to hide the breach. Now, Prezura did warn customers,
- 15:52eventually, telling them strictly not to engage
- 15:55with the attackers or pay them any money. Which
- 15:58is absolutely the correct advice. You should
- 16:00never, ever negotiate with individual hackers
- 16:04as a consumer. But by the time they sent that,
- 16:06the fear was already sown. And the cost for the
- 16:09company isn't just reputational anymore. You
- 16:11mentioned earlier that the legal costs are rising,
- 16:14too. It is not just a slap on the wrist. That's
- 16:16right. We really have to look at the regulatory
- 16:18context here. In February 2026, right as all
- 16:21these breaches were unfolding, FIIG Securities
- 16:24was fined $2 .5 million by the federal court.
- 16:28$2 .5 million? Yes. For cybersecurity failures
- 16:32related to a breach from a few years prior. That
- 16:35is a very serious number. It sets a massive precedent.
- 16:38The courts and regulators are clearly saying
- 16:40that cybersecurity is not just an IT problem
- 16:42anymore. It is a strict legal obligation for
- 16:46license holders. If you fail to protect client
- 16:48data, you will pay for it. Literally. So companies
- 16:52are getting squeezed from both sides right now.
- 16:54The hackers are demanding ransoms on one side
- 16:57and the regulators are demanding fines on the
- 16:59other. It's a total pincer movement. And caught
- 17:01right in the middle are the customers wondering
- 17:03where their driver's license scam has ended up
- 17:05on the dark web. It's really sobering reality.
- 17:08So looking back at the Pursura incident and this
- 17:11whole chaotic start to 2026, what is the big
- 17:15takeaway here for you? I think the Persora breach
- 17:17is a perfect case study for the modern threat
- 17:21landscape. Yeah. It shows us that attackers are
- 17:24becoming much more aggressive. They will contact
- 17:25your customers directly. It shows us that non
- 17:28-financial data like driver's licenses is extremely
- 17:31valuable currency for identity theft. And it
- 17:34serves as a stark reminder that our digital supply
- 17:37chains are incredibly fragile. It really does
- 17:41feel like the rules of engagement have just permanently
- 17:43changed. They have. And I have a final thought
- 17:45for you to mull over. Let's hear it. We are seeing
- 17:47attackers effectively weaponize customer service.
- 17:51Weaponize it. Yes. By emailing the customers
- 17:54directly, they're trying to create a massive
- 17:57denial of service attack on the company's own
- 17:59support lines and HR teams. Oh, wow. It's fueled
- 18:02entirely by panic. So if customer panic is now
- 18:06becoming a primary weapon for cyber criminals,
- 18:08how do organizations defend against that? It
- 18:11is not just a firewall problem anymore. It's
- 18:13a psychological one. That is a terrifying thought.
- 18:16Because how do you patch human panic? You can't.
- 18:18That's something we definitely all need to consider.
- 18:21Security really isn't just about code anymore.
- 18:23It's about communication and it's about trust.
- 18:25Absolutely. Well, that brings us to the end of
- 18:27our deep dive today. I want to thank you all
- 18:29for joining us on Tech Talks with Kinsoft. Thanks
- 18:32for listening, everyone. And listen, if today's
- 18:34discussion has raised any questions about your
- 18:35own organization's resilience, whether it's your
- 18:38access management, your data segregation or just
- 18:41your readiness for an incident like this, we
- 18:43strongly suggest you head over to www .kinsoft
- 18:47.com .au. That's www .kinsoft .com .au. Go there
- 18:52to discuss your security and IT needs before
- 18:54you end up as our next case study. Great advice.
- 18:57Until next time, stay secure out there.