Latest / Tech Talks With Kinsoft / Inside the Australian Defence Supply Chain Cyberattacks
Transcript
- 0:00Hello and welcome to Tech Talks with Kinsoft.
- 0:03We are so glad you're here with us today. We're
- 0:04jumping straight into the deep end. We really
- 0:06are. We have a stack of reports, breach notifications,
- 0:11and some, well, some pretty alarming intelligence
- 0:13warnings that paint a really stark picture. It's
- 0:18about where the Australian defense industry stands
- 0:20right now. And honestly, it is a massive wake
- 0:25-up call. Wake -up call is probably a... Putting
- 0:27it mildly, if you've been following the headlines
- 0:29at all. Or even if you haven't. Yeah, exactly.
- 0:31What's happened recently with the Australian
- 0:33supply chain is, I mean, it's a masterclass in
- 0:36how modern warfare is shifting. Shifting how?
- 0:39It's moving from the battlefield, you know, directly
- 0:41into the server room. We're talking of the soft
- 0:43underbelly of defense. Yeah. I think people tend
- 0:45to look at the big stuff, submarines, the jets,
- 0:48and think that's the only risk. Right. But today
- 0:51we're looking at the... Piping manufacturers
- 0:54and the turret suppliers. Specifically, we're
- 0:57unpacking the massive breach at ICAT Engineering
- 1:00and then the data leaks around the Redback infantry
- 1:03vehicle. And we're not just, you know, recounting
- 1:06the news here. Our mission today is to figure
- 1:08out how two very different groups, a criminal
- 1:12gang. J Group and a hacktivist collective called
- 1:16Cyber2Fin managed to walk right through the back
- 1:19doors. And maybe most importantly, we are going
- 1:22to dismantle a really dangerous myth I see all
- 1:25the time. Ah, yes. This idea that there's such
- 1:27a thing as non -sensitive data. That distinction
- 1:31sensitive versus non -sensitive, it is quickly
- 1:34becoming the biggest liability in cybersecurity.
- 1:36It's a comfort blanket that is, frankly, suffocating
- 1:40people. Before we get to all that, I want to
- 1:42start with a concept that really stuck out to
- 1:43me. Okay. This idea of a cyber staycation. It
- 1:46sounds kind of pleasant, doesn't it? It does.
- 1:48Like you're taking a break at home. But in our
- 1:50context, it is the exact opposite. It's nightmare
- 1:54fuel. Absolutely. We usually picture cyber attacks
- 1:56as a smash and grab. You know, break the window,
- 1:59grab the jewelry, run. Get in, get out before
- 2:01the cops come. But in the case of the ICANN engineering
- 2:03breach, that is not what happened. The attackers
- 2:06didn't run. No. They moved in. They lived inside
- 2:09the system for 150 days. Five months. That is
- 2:13an eternity in digital time. Just think about
- 2:17the level of intimacy that implies. Intimacy
- 2:20is a good word for it. If someone is in your
- 2:22network for five months, they aren't just stealing
- 2:24files. They're learning your culture. They know
- 2:27who goes to lunch when. They know how the CEO
- 2:29signs off their emails. They know which IT admin
- 2:32gets a bit lazy with password resets. You got
- 2:35it. That's nearly half a year. Imagine someone
- 2:38sitting in your office, reading your mail, looking
- 2:41through your files every single day for five
- 2:43months, and you have no idea they're there. That's
- 2:46the level of compromise we're talking about.
- 2:48It creates a situation where the attacker knows
- 2:50the network better than the defenders do. And
- 2:52that dwell time, that's the technical term, is
- 2:55what allowed them to do so much damage. So let's
- 2:59look at the victim here, ICAD engineering. For
- 3:01anyone who might not be... deep in the procurement
- 3:04weeds, who are they? ICAT is what we call a critical
- 3:06subprime. They aren't a household name like,
- 3:09say, Lockheed Martin or BAE Systems. Right. You
- 3:12won't see their logo on the side of a fighter
- 3:14jet. Exactly. But they are a key player. They
- 3:18specialize in mechanical and structural engineering.
- 3:22So what are they actually building? Think heavy
- 3:24lifting, piping, pumps, marine insulation. A
- 3:29lot of work for naval and industrial projects.
- 3:32They are the gears in the machine. So they aren't
- 3:35building the missiles, but they're building the
- 3:36things that make the ships that carry the missiles
- 3:38actually work. Precisely. And that makes them
- 3:41a prime target that, well, maybe nobody is watching.
- 3:45Oh, so? If you want to stop a ship, you don't
- 3:47need to blow up the hull. You just need to mess
- 3:49with the pumps that keep it afloat or the cooling
- 3:51systems for the engine. And that's where the
- 3:53attackers come in. We've got a group called J
- 3:55-Group. Sounds like a boy band. Acts like a digital
- 3:58cartel. In the reports, they're called a ransomware
- 4:00gang. But their behavior here felt different,
- 4:05more calculated. J Group is interesting. Usually
- 4:08ransomware gangs are noisy. They encrypt your
- 4:10files, lock you out, demand payment, quick turnover.
- 4:13Right. But here, the sophistication suggests
- 4:15they knew exactly what they were stealing. They
- 4:18used a technique called living off the land.
- 4:20I've heard this term thrown around. It sounds
- 4:22like a survivalist show. In a way, it is. It's
- 4:25survivalism for hackers. It means the attackers
- 4:27didn't bring in a bunch of their own custom malicious
- 4:30software that would, you know, trip an alarm.
- 4:32They didn't install some flashy hack tool. Nope.
- 4:35Instead, they used the tools that were already
- 4:38there. They used the system administrator's own
- 4:40toolkit against them. So if the IT team uses
- 4:43a remote desktop tool to fix a printer, the hackers
- 4:47use that exact same tool to steal a file. That's
- 4:50it. To a security system that isn't tuned correctly,
- 4:53it just looks like an employee doing their job.
- 4:56Oh, look, the admin is moving files. Except it
- 4:59isn't the admin. It's JGroup, using the admin's
- 5:01credentials and software. It's incredibly sneaky.
- 5:03It's hiding in plain sight. But how did they
- 5:05get in initially? Was it some sophisticated zero
- 5:08-day Mission Impossible stuff? I wish. The reports
- 5:12point to an exploit of a known vulnerability
- 5:14in an older VPN appliance. A VPN appliance. The
- 5:18very thing that's supposed to keep us secure.
- 5:20That's the irony, isn't it? Security tools, if
- 5:23you don't patch them, they become the vulnerability.
- 5:25It's like installing a steel door but leaving
- 5:27the key under the mat. J Group found the key
- 5:30under the mat. They found the note under the
- 5:32mat telling them where the key was. Okay, so
- 5:34they get in, they spend five months living off
- 5:37the land, moving laterally, which I assume means
- 5:40hopping from computer to computer. Yep. And they
- 5:43started collecting data. They actually used a
- 5:45phrase that sent a shiver down my spine. They
- 5:48said they curated a museum of corporate secrets.
- 5:51That phrase, curated a museum, it really speaks
- 5:54to their arrogance, but also their method. They
- 5:57weren't just looting. They were cataloging. And
- 5:59when they finally exfiltrated the data, they
- 6:02took 800 gigabytes. 800 gigs. That is massive.
- 6:06We're not talking about a few spreadsheets here.
- 6:08No, we're talking about a significant chunk of
- 6:11the company's digital brain. Employee files,
- 6:14passport scans, HR info, which is a nightmare
- 6:18for the staff. Identity theft waiting to happen.
- 6:20Big time. But operationally, they took client
- 6:22communications, invoices, and technical documentation.
- 6:26Specifically, CAD drawings. CAD drawings. The
- 6:30blueprints. Essentially, yes. And the connection
- 6:32here is to major projects. The files pertain
- 6:35to the Hunter Class Frigate Program and the Collins
- 6:38Class Submarine Program. The submarines. Okay,
- 6:41that's the crown jewel. And this is where the
- 6:43story gets into a bit of a he said, she said
- 6:46situation. Right. ICAD CEO Gerard Dyson confirmed
- 6:50the access, but he was very specific. He said
- 6:53it was limited to non -sensitive project information.
- 6:56Which is the standard crisis comms playbook.
- 6:59You want to contain the panic. You want to say
- 7:01it's bad, but it's not catastrophic. The hackers,
- 7:04they weren't having it. They openly mocked that
- 7:07claim. They basically said non -sensitive. We
- 7:09have the designs for the pumps that go into your
- 7:11submarines. And that is where the non -sensitive
- 7:13myth just completely falls apart. This is the
- 7:16part I really want people to understand. Let's
- 7:18drill into that. To me, or to a business executive,
- 7:21a pump is a pump. It moves water. Why is a drawing
- 7:25of a pump a national security risk? Think about
- 7:27submarine warfare. The entire game is silence.
- 7:31You want to be a hole in the water. Exactly.
- 7:33To be silent, you need to manage vibration and
- 7:36acoustic noise perfectly. The pumps, cooling
- 7:39pumps, hydraulic pumps, they are primary sources
- 7:42of mechanical noise. So if I have the blueprints
- 7:45for the pump... If you have the blueprints, you
- 7:47know the flow rates, you know the RPM, you know
- 7:50the materials, the tolerances. From that, a sophisticated
- 7:54adversary can calculate the... acoustic signature
- 7:57of that submarine. You can figure out exactly
- 7:59what it sounds like underwater. You got it. And
- 8:01if you know what it sounds like, you can program
- 8:03your torpedoes or your sonar to look for that
- 8:05specific sound. So that nonsensitive drawing
- 8:08of a water pump. becomes the key to tracking
- 8:11and syncing a multi -billion dollar asset. That's
- 8:14the connection. It's terrifying. It completely
- 8:16reframes what we consider sensitive. It's not
- 8:18just the secret weapon. It's the nuts and bolts
- 8:21that hold it together. And it caused a lot of
- 8:23confusion in the supply chain. A huge amount.
- 8:25You had the ASC, the Australian Submarine Corporation,
- 8:28claiming ICAT isn't even a supplier. Right. And
- 8:31holds no sensitive data. Meanwhile, BAE Systems
- 8:34confirmed ICAT is a supplier and they were managing
- 8:37the situation. It sounds like the left hand didn't
- 8:39know what the right hand was doing, or maybe
- 8:41just how far down the chain the data had traveled.
- 8:43That's it. The visibility creates a fog, and
- 8:47JGroup used that fog. But ICAD wasn't the only
- 8:50wake -up call. We have to talk about the Redback.
- 8:52Yes, the Redback Infantry Fighting Vehicle. This
- 8:55is part of that huge $7 billion Land 400 program
- 9:00for the ADF. A next -generation vehicle. And
- 9:02this attack was different. This wasn't J -Group.
- 9:04This was a group called CyberDufan. Okay, and
- 9:06why does that distinction matter? Well, J -Group,
- 9:08as we said, is criminal enterprise. They want
- 9:11leverage. They want money. CyberDufan is described
- 9:14as an Iran -backed hacktivist group. So they
- 9:17aren't looking for a payday. No. They're looking
- 9:19for disruption. They want to influence geopolitical
- 9:22conflict. Specifically, they target entities
- 9:25connected to Israel. Right, because the Redback
- 9:27has turret systems supplied by Israeli defense
- 9:30companies. Exactly. So CyberTufan didn't hack
- 9:33the Australian army directly. They hacked the
- 9:36Israeli suppliers. And in doing so, they found
- 9:39high -res images, technical drawings. About the
- 9:43Redback vehicle. destined for Australia. And
- 9:46they posted it all on Telegram. Which has really
- 9:48become the public square for these leaks, hasn't
- 9:50it? It has. It's accessible. It's fast. But the
- 9:53key here is that it's collateral damage. Australia
- 9:56wasn't the primary target, but our secrets were
- 9:59in the filing cabinet that got raided. It just
- 10:01shows you can't view your security in isolation.
- 10:05Your security is only as good as a supplier in
- 10:07a completely different hemisphere. It's the global
- 10:10village of defense manufacturing. And right now,
- 10:13the village has some broken fences. So what does
- 10:17this all mean for the non -sensitive data miss?
- 10:19We keep going back to this. Can we dig deeper
- 10:22into why that label is so misleading? I think
- 10:24it's the most dangerous term in modern cybersecurity.
- 10:27It creates a false sense of security. Companies
- 10:30think, well, we don't hold the nuclear codes,
- 10:32so we're not a target. But the bad guys don't
- 10:34need the codes if they have the map to the room
- 10:36where the codes are kept. That's a perfect analogy.
- 10:39Let's look at it through the lens of what intelligence
- 10:41agencies call mosaic theory. Mosaic. Imagine
- 10:45a mosaic. One little tile. It's just a blue square.
- 10:48It means nothing on its own. Right. That's your
- 10:49non -sensitive invoice or your staff roster.
- 10:52But if an intelligence agency steals 10 ,000
- 10:55of those tiles and puts them all together. They
- 10:57see the whole picture. They see the military
- 10:59capability. They see everything. If I have your
- 11:01staff roster, I know when your surge periods
- 11:03are. If I have your invoices, I know who your
- 11:04subcontractors are. If I have your project timelines,
- 11:07I know when a ship is launching. None of those
- 11:09documents are marked secret, but together they
- 11:11provide a roadmap. An exact roadmap. Yeah. It
- 11:14tells you who the weak links are. If I know a
- 11:16major defense prime uses a specific small engineering
- 11:20firm for, say, their HVAC systems, and I know
- 11:24that firm has weak security. You hack the HVAC
- 11:27guy. You hack the HVAC guy. You live in their
- 11:29system for 150 days. You learn their email patterns,
- 11:32their invoice numbers. Then you send a legitimate
- 11:35looking email from that trusted partner to the
- 11:38big defense contractor. And because it's coming
- 11:40from a known partner, they open the malicious
- 11:42attachment. And you're in. It's all about exploiting
- 11:45those trust relationships. Adversaries target
- 11:48the smaller firms to get the language and patterns
- 11:51they need. This brings us to the bigger picture.
- 11:54We're not just talking about criminals trying
- 11:56to make a quick buck anymore. No. We're talking
- 11:58about state -backed threats. ASIO has been pretty
- 12:01loud about this. Mike Burgess, the director general
- 12:04of ASIO, has been very blunt. He's warned that
- 12:07state backed hacking groups and he specifically
- 12:09mentioned efforts linked to China and Russia
- 12:11are intensifying their efforts to infiltrate
- 12:14our critical infrastructure. And their goal isn't
- 12:17just spying, is it? Espionage is part of it,
- 12:20for sure. But the more concerning goal is what
- 12:22they call pre -positioning. Pre -positioning.
- 12:24That sounds ominous. It is. It means getting
- 12:27into the water, power, transport or defense networks
- 12:30and just waiting. Laying the groundwork for sabotage.
- 12:32Exactly. The goal is to be able to disrupt these
- 12:35systems at a time of their choosing, say, during
- 12:38a geopolitical crisis. So the CyberStaycation
- 12:41J group took inside ICAD. A state actor could
- 12:45do the same, but instead of stealing data, they
- 12:48plant a logic bomb to shut down the manufacturing
- 12:50line three years from now. That is the threat.
- 12:53Imagine if we needed to ramp up production of
- 12:56the Redback vehicle because of a conflict, but
- 12:58the machines just wouldn't turn on because a
- 13:00sleeper code had been activated. And what's complicating
- 13:03all this is the convergence of these threats.
- 13:05The lines are blurring. They really are. Sometimes
- 13:08criminal gangs act as proxies for states. Sometimes
- 13:12states buy data from criminal gangs. J Group
- 13:15might have stolen that ICAD data for ransom,
- 13:17but who's to say they didn't sell a copy to a
- 13:20foreign intelligence service on the side? So
- 13:22you don't even know who you're fighting. It could
- 13:24be a guy in a hoodie or a military unit. Or both.
- 13:27Now, looking at where we are right now, February
- 13:292026, it feels like we can't go a week without
- 13:32a new headline. The landscape is incredibly aggressive.
- 13:35Just recently, we've seen the active exploitation
- 13:38of a flaw in SolarWinds' web help desk. SolarWinds
- 13:41again? I feel like we've been talking about them
- 13:43for years. It's a recurring theme because it's
- 13:45such a ubiquitous tool. It's used everywhere.
- 13:48If you control the help desk software, you control
- 13:51the IT department. And if you control IT... You
- 13:54own the company. Yeah. And then you have the
- 13:57attack on Hansa Merkur, the German insurance
- 13:59giant. A ransomware attack by the Dragon Force
- 14:02gang. They claim to have stolen 97 gigs of data.
- 14:05It just reinforces that ICAD wasn't a one -off.
- 14:08This is a global escalation. If you have data
- 14:11or if you provide a critical service, you are
- 14:13on the list. It really drives home the point
- 14:16that this isn't going away. So taking all of
- 14:18this in the 150 -day dwell time, the non -sensitive
- 14:22data myth, what's the takeaway? If I'm a business
- 14:25leader or just managing IT for a mid -sized firm,
- 14:28I'm feeling pretty exposed right now. You should
- 14:30feel exposed. That's the first step. The key
- 14:32lesson here is that the perimeter is dead. You
- 14:34can't just build a wall around your company and
- 14:36think you're safe. The entire supply chain is
- 14:38your attack surface. So practically speaking,
- 14:40what do we do? First, vendor risk management
- 14:42is crucial. You have to know how secure your
- 14:44partners are. You need to audit them. You can't
- 14:46just trust. You must verify. Check their patching
- 14:49cadence. Exactly. And stop using the term non
- 14:53-sensitive as an excuse to be lax. Treat all
- 14:56data as if it has value. If it's worth keeping,
- 14:59it's worth protecting. And technically, network
- 15:02segmentation is vital. That's stopping that lateral
- 15:05movement we talked about. Right. If a hacker
- 15:07gets into the reception desk's computer, they
- 15:10shouldn't be able to just hop straight over to
- 15:11the server holding the submarine blueprints.
- 15:14You need internal blast doors. Blast doors. I
- 15:17like that image. Like on a ship. Precisely. If
- 15:20one compartment floods, the ship doesn't sink.
- 15:24J Group moved laterally because they could. The
- 15:27doors were wide open. We need to make that movement
- 15:30difficult. Make them work for it. Make them work
- 15:32for every inch. If they have to break down a
- 15:34door, every time they move, they make noise.
- 15:36And if they make noise, you catch them. So it's
- 15:38shifting from preventing entry, which seems impossible,
- 15:41to detecting presence. Yes. We need to catch
- 15:45them during the staycation, not after they've
- 15:47checked out with all your stuff. It's a lot to
- 15:49process. But I think the story of the cyber staycation
- 15:52is the one that's going to stick with me. It
- 15:53should. It forces you to ask the uncomfortable
- 15:55question. Which brings us to our final thought.
- 15:59We know J Group lived in a defense contractor
- 16:01system for five months, undetected. They watched,
- 16:05they learned, they cataloged. So the question
- 16:07is, if they can do that to a defense contractor
- 16:10who is currently vacationing in the networks
- 16:14of the apps and services you use every single
- 16:17day. Who is reading your emails right now? Who
- 16:19is watching your data flow just waiting for the
- 16:21most damaging moment to make their move? You
- 16:24assume your network is empty. But until you look,
- 16:27you don't really know. You don't. That is a chilling
- 16:29thought to end on, but a necessary one. Ignorance
- 16:33is definitely not bliss in this industry. No,
- 16:35it's not. Awareness is the first step to defense.
- 16:38Absolutely. Thank you so much for joining us
- 16:40on Tech Talks with Kinsoft. We hope this look
- 16:43at the defense supply chain has been eye -opening.
- 16:45It's always a pleasure to unpack these things.
- 16:47Let's just hope the next wake -up call isn't
- 16:49quite so loud. Now, if listening to this has
- 16:51made you a little sweaty about your own security
- 16:53posture or you're wondering if your supply chain
- 16:56is resilient enough, Don't just panic act. Right.
- 16:59Whether it's IT needs, security audits, or just
- 17:01figuring out where your non -sensitive data is
- 17:04exposed, you really do need expert help. Exactly.
- 17:07So head over to www .kinsoft .com .au. That's
- 17:12www .kinsoft .com .au to discuss your security
- 17:16and IT needs. They can help you lock those doors
- 17:18front, back, and digital. Thanks for listening.
- 17:21And stay secure out there.