Latest / Tech Talks With Kinsoft / Lessons from the Regis Resources Ransomware Incident
Transcript
- 0:00Hello and welcome to Tech Talks with Kinsoft.
- 0:01Hey there. This is the show where we unpack the
- 0:05latest shifts in technology, security, and digital
- 0:09resilience. Really just to keep you ahead of
- 0:11the curve. I am your host and I have to say,
- 0:13just looking at the headlines for the last few
- 0:15weeks. Oh yeah. I mean. 2026 has just decided
- 0:18not to ease us in gently at all. No, definitely
- 0:21not. It feels like the digital landscape just
- 0:23woke up and chose violence this year. It is great
- 0:26to be here and you are absolutely right about
- 0:27that. If if anyone thought the cybersecurity
- 0:30turbulence of late 2025 was just going to plateau
- 0:33or calm down. Right. Well, January 2026 has effectively
- 0:37shattered that illusion. It has been an absolute.
- 0:40roar of activity, specifically right here in
- 0:43Australia. We are seeing a shift in targets,
- 0:45a shift in tactics, and honestly, just a massive
- 0:48shift in the sheer volume of incidents. Exactly.
- 0:51And usually, you know, when we open the show
- 0:53with a statement like it has been a busy month
- 0:54in cyber, we are about to dissect an absolute
- 0:57disaster. Usually, yes. But I want to flip the
- 1:00script a bit today. I want to start with a story
- 1:02that, well, while it's terrifying in its potential,
- 1:06it is actually a massive win. A rare thing these
- 1:08days. Very rare. Or at least it's a master class
- 1:11in how to stare down a barrel and not blink.
- 1:13We really need to talk about Regis Resources.
- 1:16I was really hoping we would start there. The
- 1:18Regis case is practically the only thing industry
- 1:20insiders are talking about right now. I bet.
- 1:22It is the perfect case study because it completely
- 1:26defies the usual narrative of, you know, big
- 1:29company gets hit, big company pays ransom, big
- 1:33company issues a very sad public apology. Right,
- 1:36right. Let's set the stakes for the listeners
- 1:38who maybe haven't dug into their financials recently.
- 1:41Regis Resources is... a massive Australian gold
- 1:45producer. Massive. And when I say massive, their
- 1:47quarterly report just dropped. They announced
- 1:49a record quarter with a cash and bullion build
- 1:51of $255 million. Which brings their total balance
- 1:55to $930 million. Nearly a billion dollars in
- 1:59liquid assets and gold just sitting on the books.
- 2:02That is not just a balance sheet. That is basically
- 2:05a neon sign for every single threat actor on
- 2:08the dark web saying, open for business. Precisely.
- 2:11In the criminal ecosystem, A pot of gold that
- 2:13size, literally and figuratively, it attracts
- 2:15the apex predators. So in November 2025, they
- 2:18were targeted. Right. But the public really only
- 2:21learned the details in January 2026 once the
- 2:24dust had settled. And here is the twist that
- 2:27I just love. Usually when a billion dollar company
- 2:29gets hit by ransomware, we see a massive insurance
- 2:32claim and some quiet under the table payout.
- 2:35But Regis didn't pay a cent. No data was exfiltrated.
- 2:40Operations just kept running. It's almost like
- 2:41watching a heist movie where the bank vault actually
- 2:44does its job. It is incredibly rare. And what
- 2:46we are going to do today is tear apart exactly
- 2:48how they did that. Because it wasn't magic and
- 2:51it definitely wasn't luck. It was architecture.
- 2:54And we also need to pivot from there to discuss
- 2:57why these access failures are effectively replacing
- 3:01traditional hacking as the primary threat factor.
- 3:04And we'll look at the absolute carnage of January
- 3:072026 to see why so many other companies failed
- 3:11exactly where Regis succeeded. Let's get right
- 3:13into the crime scene then. Who exactly was knocking
- 3:16at their door? The group is called Lynx. If you
- 3:19follow the threat intelligence feeds, you definitely
- 3:21know them. They have this really bizarre branding
- 3:24where they claim to be ethical ransomware operators.
- 3:27Ethical ransomware. I always find that pitch
- 3:30just hilarious. It is like a mugger leaving you
- 3:33bus fare. You know, we robbed you, but we did
- 3:35it politely. It is a fascinating psychological
- 3:37play on their part. They claim they don't target
- 3:39hospitals or nonprofits or critical infrastructure
- 3:42because those sectors are quote unquote vital.
- 3:44But generous of them. Right. They frame their
- 3:46extortion as a dialogue or a get this a security
- 3:49audit fee. Wow. A security audit fee. But make
- 3:53no mistake, they aggressively target high cash
- 3:56flow businesses like mining because they know
- 3:58the liquidity is there. They saw that billion
- 4:00dollar balance sheet and they moved in. OK, so
- 4:02links. lists a Regis subsidiary, Maxillimus Gold,
- 4:07on their leak site. They're fully expecting a
- 4:09massive payout. But Regis holds the line. You
- 4:13mentioned architecture earlier. Break that down
- 4:15for us. Because once malware is actually inside
- 4:17the perimeter... The game is usually over. Exactly.
- 4:21How did they stop the bleed? It really came down
- 4:23to two things. Speed and segmentation. First,
- 4:27their automated detection systems were perfectly
- 4:28dialed in. They identified the intrusion anomalies
- 4:31almost immediately. Wow. We aren't talking days
- 4:33here. We're likely talking minutes. The system
- 4:36automatically slammed the blast door shut, restricting
- 4:38access and isolating the infected network segments.
- 4:41Which is standard procedure on paper, but rarely
- 4:44executed that fast in the real world. But the
- 4:47real savior here was the backup strategy, right?
- 4:49The air gap. And I know we throw that term around
- 4:51a lot in tech circles, but we really need to
- 4:54appreciate the discipline required to actually
- 4:55maintain an air gap in 2026. That is exactly
- 4:59what I wanted to ask you about. In a modern corporate
- 5:01environment where we want real -time analytics,
- 5:04seamless cloud integration, instant data availability
- 5:08everywhere, true air gapping, which is keeping
- 5:11backups physically or logically disconnected
- 5:14from the network, that is a logistical nightmare.
- 5:17It is. It feels almost archaic. How do you balance
- 5:20that level of security with operational efficiency?
- 5:23That is the million -dollar question, or in this
- 5:26case, the billion -dollar question. You are right.
- 5:28True air gapping creates friction, slows things
- 5:31down. But Regis proved that the friction is just
- 5:34the price of survival. Yeah. They had backup
- 5:36copies of their data that the ransomware simply
- 5:38could not touch. period when the malware tried
- 5:42to crawl laterally through the network to encrypt
- 5:44the recovery points it just hit a dead end so
- 5:46they didn't even need the decryption key from
- 5:48links because they already had a clean slate
- 5:49ready to go exactly they wiped the infected servers
- 5:52and restored from the clean offline backups and
- 5:55the result really speaks for itself despite a
- 5:57massive highly sophisticated attack they produced
- 6:0196 600 ounces of gold in that exact quarter that
- 6:05is incredible operational impact was effectively
- 6:07zero that is the only metric that matters at
- 6:10the end of the day. But this brings me to a broader
- 6:12industry trend I want to explore. Why mining?
- 6:16I mean, obviously the money is there, but structurally,
- 6:19mining feels like it should be so much harder
- 6:22to hack than, say, a digital bank. It is. Rocks,
- 6:27dirt, and big trucks in the middle of nowhere.
- 6:29See, that is the common misconception. Mining
- 6:32is actually currently sitting right in the middle
- 6:34of a perfect storm of vulnerability. It is all
- 6:36about the convergence of IT and OT operational
- 6:39technology. Ah, the classic IT and OT friction.
- 6:42It is the biggest headache in the industrial
- 6:44sector right now. You have these modern mines
- 6:46that are incredibly automated. They're pushing
- 6:48gigabytes of data to the cloud every second for
- 6:51yield optimization and predictive maintenance.
- 6:53Sure. But the physical machines actually doing
- 6:55the work. the crushers, the conveyor belts, the
- 6:57processing plants, they are often running on
- 7:00industrial protocols that are 30 or 40 years
- 7:02old. Things like Modbus and Berfibus. Right.
- 7:05Protocols that were designed before the public
- 7:07Internet was even a consideration for businesses.
- 7:10They were built strictly for reliability and
- 7:12not security. They have no encryption, no authentication.
- 7:15They just blindly trust whatever commands they
- 7:17receive on the wire. Exactly. They were never,
- 7:20ever meant to leave the local closed loop. But
- 7:24now, in the name of efficiency and cloud analytics,
- 7:27we are plugging these medieval systems straight
- 7:29into modern Internet connected networks. We are
- 7:32basically putting a state of the art smart lock.
- 7:35on a wooden castle gate that has rusty hinges.
- 7:38That is a terrifying image. And you add the geography
- 7:41factor to it. Regis operates in the Dupton Belt
- 7:43in Western Australia. These aren't sites you
- 7:46can just drive IT support out to an hour if a
- 7:48server crashes. That is the kicker. These sites
- 7:50are remote, extremely remote. They absolutely
- 7:53require remote access for daily maintenance.
- 7:56You have vendors, external contractors, and systems
- 7:59engineers logging in from Perth, from Sydney,
- 8:01maybe even from overseas. Every single one...
- 8:04One of those remote access points is a potential
- 8:06door. And if you have a legacy protocol sitting
- 8:08completely undefended behind that door, once
- 8:11an attacker slips in, they can move through a
- 8:13physical infrastructure incredibly fast. Which
- 8:16segues perfectly into the access failure concept
- 8:19I wanted to discuss today. But when we talk about
- 8:21these major corporate breaches, the popular image
- 8:25in everyone's head is still the movie hacker,
- 8:27right? Oh, yeah. The guy in the hoodie. Exactly.
- 8:30Someone writing custom code in a dark room to
- 8:33exploit some unknown zero -day vulnerability
- 8:36in a firewall. But that is not really the reality
- 8:40anymore, is it? Almost never. There was a fantastic
- 8:42report by Tenable that came out recently that
- 8:45really crystallizes this shift. They argue that
- 8:48the era of the hacker breaking down the digital
- 8:50wall is ending. We are now firmly in the era
- 8:53of the access failure. Meaning they aren't breaking
- 8:55in, they are just logging in. Precisely. They
- 8:57are finding valid keys. Tenable's research shows
- 9:00that the vast majority of Australian breaches
- 9:02aren't sophisticated technical exploits at all.
- 9:04They are simply failures of identity governance.
- 9:07We are talking about forgotten passwords, exposed
- 9:10API keys accidentally left in public code repositories,
- 9:14or service accounts that should have been deleted
- 9:17three years ago when an employee left. Oh, service
- 9:19accounts are the silent killers. You know how
- 9:22it goes. You spin up a quick bot to do a data
- 9:24transfer. You give it full admin rights because
- 9:26you just don't have the time to figure out the
- 9:28specific granular permissions it needs. Yep,
- 9:31happens all the time. And then five years later.
- 9:33That box is still running silently in the background
- 9:35with a password like admin123. And that is exactly
- 9:38what the industry calls toxic clutter. As companies
- 9:42rapidly move their operations to the cloud, the
- 9:45sheer number of identities, both human users
- 9:47and machine accounts, is just exploding. Secrets
- 9:51management becomes literally impossible for humans
- 9:54to do manually. It's too much data. Way too much.
- 9:57Tenable points out that to a security system,
- 9:59a hacker using a valid stolen API key looks exactly
- 10:03like a legitimate automated process. The alarm
- 10:06doesn't ring because the key fits the lock perfectly.
- 10:08It is the digital equivalent of leaving the house
- 10:10key under the doormat and then wondering why
- 10:13the home alarm didn't go off when the burglar
- 10:15just walked through the front door. It really
- 10:17is. And unfortunately, while Regis somehow managed
- 10:20to keep their keys incredibly safe, the rest
- 10:22of the corporate landscape in January 2026 was.
- 10:25Yeah, let's look at the scoreboard for a minute
- 10:28because it is pretty grim reading. I was looking
- 10:30through the Black Fog report for January and
- 10:32the numbers are just staggering. They are. 91
- 10:35publicly disclosed ransomware attacks just in
- 10:38the month of January. And remember, those are
- 10:41just the ones we actually know about because
- 10:43of disclosure laws. The real number behind the
- 10:45scenes is likely much, much higher. And the sector
- 10:48breakdown was super interesting to me. It wasn't
- 10:50finance sitting at the top of the list. No, it
- 10:52was health care. Number one, with 27 separate
- 10:55incidents, followed closely by government agencies
- 10:57and manufacturing. Health care being top is always
- 11:00just devastating because the leverage there isn't
- 11:03just financial. It is literally people's lives.
- 11:06Yeah. But we had some major local hits here in
- 11:09Australia, too. Presura, the big insurer, got
- 11:12hit really hard. That was a highly significant
- 11:14breach, about 300 ,000 customers affected. And
- 11:18this brings us right back to the inherent value
- 11:20of raw data. The attackers accessed names, policy
- 11:24info and travel details. Travel details. Yeah.
- 11:27Now, they didn't get credit card info, which
- 11:29the company pushed as the silver lining. But
- 11:32think about what a smart attacker can do with
- 11:34detailed travel itineraries. Oh, it is prime
- 11:38fishing fuel. If I get an email that knows exactly
- 11:41where I just flew, what dates I was there, and
- 11:43what my specific insurance policy number is,
- 11:45my skepticism drops to zero instantly. I am absolutely
- 11:49clicking that link. Exactly. It allows for highly
- 11:52targeted, incredibly convincing social engineering.
- 11:55And we had the Victorian Department of Education
- 11:58breach. That one really bothered me. Unauthorized
- 12:01access to student names, personal emails, and
- 12:04crucially, encrypted passwords. Now, I have heard
- 12:08people online say, oh, it's fine, the database
- 12:10was encrypted, they can't read the passwords,
- 12:12but we really need to bust that myth right now.
- 12:14Please do, it drives me crazy. Just because a
- 12:16password is encrypted or hashed in a database
- 12:18doesn't mean it is safe, especially if the hashing
- 12:21algorithm is old or weak, or if the passwords
- 12:24weren't properly salted with random data. If
- 12:27an attacker actually downloads the encrypted
- 12:29file, they can just use rainbow tables or massive
- 12:32GPU server farms to brute force crack those passwords
- 12:36entirely offline at their own pace. Especially
- 12:39if the students or staff were using common, weak
- 12:42passwords. The word password with a 123 at the
- 12:45end, even when encrypted, is still easily cracked
- 12:47in seconds. Exactly. And the real danger there
- 12:49is credential stuffing. People reuse passwords
- 12:52everywhere. If an attacker cracks your school
- 12:54portal password, they're... immediately going
- 12:56to run a script to try that exact same email
- 12:59and password combination on your banking app,
- 13:01your personal email and your social media. It
- 13:04is a cascading failure across a person's entire
- 13:07digital life. And then there was the Lely family
- 13:09doctor's breach, which was targeted by the Anubis
- 13:12group. Anubis is nasty. They perfectly represent
- 13:14the double extortion tactic that really dominated
- 13:16the January threat landscape. Right. So let's
- 13:19clarify double extortion for you listening. This
- 13:22is where the backup strategy we just praised
- 13:24Regis for potentially falls short if you aren't
- 13:26extremely careful about your perimeter. Correct.
- 13:28In the old days, say five years ago, ransomware
- 13:31just encrypted your machine in place. If you
- 13:34had good backups, you just ignore the ransom,
- 13:35wipe the drive, and restored. Simple. But double
- 13:38extortion means they steal a copy of the data
- 13:41first. Then they encrypt the local machines.
- 13:44So you might restore your servers from your pristine
- 13:47air -gapped backups and be back online in an
- 13:49hour. But the hacker is still holding a copy
- 13:52of your private patient records, your student
- 13:54data, or your corporate trade secrets on their
- 13:56own servers. And they threaten to publish it
- 13:58to the dark web if you don't pay up. Exactly.
- 14:00So the ransom isn't actually for the decryption
- 14:03key anymore. It is a hush payment. It's pure
- 14:05blackmail. Right. This is exactly why... the
- 14:07access failure theory is so critical right now.
- 14:10You have to stop them from entering and exfiltrating
- 14:13data in the very first place. Once the data leaves
- 14:16your building, your backups cannot save your
- 14:18reputation. Honestly, this feels overwhelming.
- 14:22I mean, we are describing a landscape where you
- 14:24have legacy machines that literally cannot be
- 14:27secured by modern standards, cloud complexity
- 14:30that hides open doors in millions of lines of
- 14:33code, and attackers who are silently stealing
- 14:35data before you even know they're on the network.
- 14:37If you were a board member listening to this,
- 14:39what is the actual move? The move is a fundamental
- 14:42mindset shift. Governance is the new firewall.
- 14:46The security experts are making this very clear.
- 14:48This is no longer an IT support ticket. It is
- 14:51a boardroom issue. So what specific questions
- 14:54should the board be asking? Because just asking
- 14:56the IT guy, are we secure, is a totally useless
- 14:59question. Totally useless. The question they
- 15:01need to be asking is, what is our identity inventory?
- 15:04Do we actually know every single human and every
- 15:07single machine script that has a valid key to
- 15:09our front door? Okay, actionable advice time.
- 15:11We have talked a lot. about the problems. What
- 15:13are the tangible solutions for companies in 2026?
- 15:16Three main things. First, exactly as proven by
- 15:19Regis, air gap your backups, but you have to
- 15:22do it intelligently. Use immutable backups in
- 15:25the cloud. That is storage that literally cannot
- 15:27be overwritten, modified, or deleted for a set
- 15:30retention period, even by someone with top -level
- 15:33admin credentials. Oh, that's smart. So that
- 15:35protects you from the road credential issue.
- 15:37Even if a hacker perfectly steals the head of
- 15:39IT's password, they physically cannot delete
- 15:42the backup files. Exactly. The system won't let
- 15:45them. Second, least privilege. It sounds incredibly
- 15:49boring, but it is absolutely vital. Why does
- 15:52the summer marketing intern have admin access
- 15:54to the finance server? They shouldn't. Right.
- 15:57Why does that third -party HVAC vendor have 24
- 16:00-7 remote access to the network when they only
- 16:04do maintenance on the second Tuesday of the month?
- 16:06Lock it down. Only give access when it is needed
- 16:09and revoke it immediately when it's not. Convenience
- 16:11really is the enemy of security. We say it on
- 16:13the show every time, but it just keeps proving
- 16:15true. It does. And third. Continuous discovery.
- 16:19You cannot protect what you do not know exists.
- 16:22You need automated security tools that are constantly
- 16:25hunting through your own network for exposed
- 16:27credentials, shadow IT applications that employees
- 16:30install without asking, and forgotten API keys.
- 16:33You basically need to find the keys hiding under
- 16:35the mat before the hackers do. It is like treating
- 16:38your digital environment like a physical mine
- 16:40site. In mining, they have these strict zero
- 16:43harm safety policies. They inspect every harness,
- 16:46every vehicle, every single day before shift
- 16:48starts. Regis essentially applied zero harm to
- 16:50their data environment. They treated data toxicity
- 16:53with the exact same respect and fear that they
- 16:56treat cyanide in the gold extraction process.
- 16:58That is the perfect analogy. That cultural translation
- 17:01from physical safety to digital safety is what
- 17:04saved them. They operationalized cyber safety
- 17:06at every level of the company. Well, before we
- 17:09wrap up today, I want to leave you with... one
- 17:10final thought to mull over, or maybe it's more
- 17:12of a warning. We are deep into February 2026
- 17:15now. We have seen the stats from January. Where
- 17:17is this cat and mouse game going next? AI. It
- 17:21is the absolute elephant in the room. We are
- 17:23seeing artificial intelligence being integrated
- 17:25into everything for corporate efficiency, but
- 17:27the attackers have access to the exact same tools.
- 17:30We are standing on the precipice of a... massive
- 17:34automated wave of AI -driven social engineering.
- 17:37Deep fakes. Deep fakes. Real -time voice clones.
- 17:41We are already seeing the early warning signs
- 17:43of it out in the wild. If I am an attacker and
- 17:46I can't hack your password because your company
- 17:48has good hygiene and immutable backups, I will
- 17:51just call you on the phone and I will sound exactly
- 17:53like your CEO. Oh, yeah. Or exactly like your
- 17:56spouse. And I will casually ask you for the access
- 17:58code. That is just terrifying. It means that
- 18:01Zero Trust isn't just a software arc. architecture
- 18:03setting anymore. It has to become a literal life
- 18:05philosophy. Yeah. Verify everything. Skepticism
- 18:08is your absolute best defense going forward.
- 18:11If your boss calls you out of the blue and asks
- 18:12for an urgent wire transfer or password reset,
- 18:15hang the phone, call them back immediately on
- 18:17a known, trusted internal number. The human firewall
- 18:19has to become much harder to break than the digital
- 18:22one. Well, on that slightly paranoid but absolutely
- 18:24necessary note. We're going to wrap things up
- 18:27for today. It is crystal clear that whether you
- 18:30are sitting on a billion dollars of physical
- 18:32gold or just a database of customer emails. The
- 18:36rules of engagement have completely changed this
- 18:39year. They definitely have. But as Regis showed
- 18:41us, preparation pays off. You can survive the
- 18:44worst -case scenario if you have the architecture
- 18:47and the strict governance already in place. Exactly.
- 18:50Look, if today's discussion about access failures,
- 18:52identity governance, and the sheer mess of the
- 18:54January threat landscape has you looking at your
- 18:57own systems a little differently and maybe sweating
- 18:59just a little bit, please don't leave it to chance.
- 19:01Definitely not worth the risk. Go to www .kinsoft
- 19:04.com .au. to discuss your security and IT needs.
- 19:08The team there really understands the nuances
- 19:10we talked about today, from setting up immutable
- 19:12air gapping to conducting a full identity inventory.
- 19:15They are the folks who know how to lock the doors
- 19:17properly, so you do not end up as a cautionary
- 19:19statistic in next month's Blackfog Report. Again,
- 19:22go to www .kinsoft .com .au. Stay safe out there.
- 19:27Thanks for listening to Tech Talks with Kinsoft.
- 19:29Catch you next time.