Latest / Tech Talks With Kinsoft / NBN Co Data Breach - Sentap's Infrastructure Data Sale
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. We're your
- 0:02guide through, well, the sometimes pretty complex
- 0:04work in tech. I'm your host. And today we were
- 0:07doing a deep dive. We're looking at something
- 0:09really fresh. An alleged incident reported just
- 0:12back on June 5th, 2025. It involves NBNCO. That's
- 0:16Australia's National Broadband Network. And honestly,
- 0:19it raises some pretty big questions because this
- 0:22is recent news, right? But you're probably not
- 0:24seeing it blasted across major news sites. And
- 0:26that's kind of the core of our deep dive today.
- 0:28Why might something like this potentially involving
- 0:31critical infrastructure not get wider public
- 0:33discussion immediately? What's that say about
- 0:35transparency, especially when it's a government
- 0:37linked body like NBNCO? The source here. is interesting
- 0:40to a platform called Dark Web Informer. So that
- 0:43tells you something straight away about where
- 0:44this info is surfacing. Exactly. So our mission
- 0:47today really is to walk you through what we know
- 0:49about this alleged incident and try to understand
- 0:51the implications, sure, but also peel back the
- 0:54layers on how this sort of information actually
- 0:56surfaces. Or maybe more importantly, why it sometimes
- 0:59doesn't hit the mainstream right away. It's all
- 1:01about understanding, you know, the life cycle
- 1:04of cyber threat intelligence, why that matters
- 1:05for you. OK, right. Let's unpack it then. The
- 1:08basic claim, according to the report from Dark
- 1:11Web Informer on June 5th, it points squarely
- 1:14at NBN Co., the National Broadband Network. The
- 1:17threat actor, the group or person claiming they
- 1:19did this, is called CENTAP. And the size of the
- 1:21data they claim to have. It's pretty staggering.
- 1:24306 gigabytes. Now, 306 gigs. I mean, that's
- 1:27a huge number, obviously. But when the report
- 1:29says sensitive infrastructure data, what does
- 1:32that actually mean? What kind of information
- 1:33are we potentially talking about here? Is it
- 1:35like truly critical stuff? Well, that's where
- 1:37it gets really fascinating and maybe a bit concerning.
- 1:39The specificity. It's not just like. General
- 1:42NBN files. The claim is the data is tied to specific
- 1:46technologies. Hybrid fiber coaxial, HFC, and
- 1:50fighter -to -the -curb FTTC projects. These are
- 1:53the actual methods used to connect millions of
- 1:55homes and businesses across Australia. HFC uses
- 1:58existing cable lines. FTTC brings fiber much
- 2:01closer. Okay, so the actual tech infrastructure.
- 2:03Precisely. And it gets even more specific than
- 2:05that. The report mentions specific regions, just
- 2:07in Queensland, apparently. Places like Bald Hills,
- 2:10Ashgrove. Albany Creek, Kenmore, Stafford. And
- 2:14Centap, the actor, claims this data is highly
- 2:16detailed, technical, and valuable. Valuable for
- 2:19analysts, researchers, and crucially, adversaries
- 2:22targeting telecom infrastructure. Right, adversaries.
- 2:24Yeah. So if this is true, we're not just talking
- 2:27about, say, customer names and addresses, although
- 2:30the source does mention PII, personally identifiable
- 2:33information, might be included in their general
- 2:36reports. We could be talking about the actual
- 2:37blueprints, network diagrams, maybe equipment
- 2:40details, possibly even physical locations for
- 2:43key infrastructure. It's like having an operational
- 2:45map of parts of the network. Highly valuable
- 2:48for anyone wanting to understand it, exploit
- 2:50it. Or maybe even disrupted. Wow. OK, that level
- 2:54of technical detail sounds, yeah, quite chilling.
- 2:57It's like the schematics for the nation's Internet
- 2:59backbone or parts of it anyway. But that just
- 3:01brings us right back to the big question, doesn't
- 3:03it? If it's potentially that sensitive information
- 3:05that adversaries would find incredibly useful.
- 3:07Why isn't this front page news? Why the apparent
- 3:10quiet from official channels? Yeah. And this
- 3:14is where understanding that information lifecycle
- 3:16is key. A lot of these alleged breaches, especially
- 3:20maybe involving critical infrastructure, they
- 3:22often pop up first on these private intelligence
- 3:25feeds. Dark Web Informer. Despite the name, it's
- 3:29not some hacker form itself. It's more like a
- 3:32specialized newswire for cyber threats. So it's
- 3:35a business. A subscription service. Exactly.
- 3:38Subscriber only. It's aimed at cybersecurity
- 3:40professionals, corporate security teams, government
- 3:42agencies, people who need early warnings. They
- 3:46aggregate intelligence, track leaks, provide
- 3:48alerts. The source itself mentions having thousands
- 3:51of posts, alerts, and unredacted threat feed.
- 3:55Even high -raise images as proof sometimes. Unredacted,
- 3:58so potentially sensitive stuff right there. Potentially,
- 4:00yes. Their own disclaimer notes reports may include
- 4:02unredacted personally identifiable information,
- 4:05PII. gathered from publicly available sources.
- 4:07But they also state very clearly it's for cybersecurity
- 4:10awareness and threat intelligence purposes only,
- 4:12and they condemn misuse. So you see this tiered
- 4:15flow of information, right? It starts with the
- 4:17threat actor making a claim, maybe on a dark
- 4:20web forum. Then it gets picked up by these private
- 4:23intelligence services like Dark Web Informer.
- 4:25And only then, maybe, possibly much later, does
- 4:28it filter through to wider public knowledge or
- 4:31get officially confirmed. So there's this whole
- 4:33hidden layer of information exchange happening
- 4:36before anything hits the public eye. Pretty much.
- 4:39And it exists because, well, the immediate needs
- 4:42of cyber defense teams often come first, before
- 4:44a full public announcement is feasible or even
- 4:47wise. Which brings us right back to NBN Co.,
- 4:50a government -linked entity, vital infrastructure.
- 4:54Why aren't they out there talking about this
- 4:56alleged breach? Is it strategic silence or something
- 5:00else? It feels uncomfortable, you know? It is
- 5:02uncomfortable and it highlights a real tension,
- 5:04a fundamental tension, actually. On one side,
- 5:06yes, a government body managing critical infrastructure.
- 5:09You expect transparency. The public has a right
- 5:11to know about potential risks. But on the other
- 5:13side, managing a major security incident, especially
- 5:16one that's still just alleged, is incredibly
- 5:18complex. Well, first, verification. Dark web
- 5:22claims aren't always true. Threat actors exaggerate.
- 5:25Sometimes they bluff entirely, announcing something
- 5:27prematurely before it's verified. That could
- 5:30cause needless panic. OK, fair point. It could
- 5:33also give the actual attackers, if they exist,
- 5:35way too much information about what NBN Co. knows
- 5:38or doesn't know. It could compromise an ongoing
- 5:41investigation. Think about it. Confirming a breach
- 5:44too early might show your hand. Revealing details
- 5:47could help other attackers. So there are genuine
- 5:49strategic reasons for maybe holding back information.
- 5:53at least initially. Absolutely. Verifying a claim
- 5:55like this takes time. It involves deep forensic
- 5:58work, internal checks, maybe liaison with intelligence
- 6:01agencies. During that whole process, maintaining
- 6:04a degree of strategic silence can be critical.
- 6:06It's a balancing act, a really difficult one.
- 6:09Public right to know versus operational security
- 6:11and investigation integrity. That makes the situation
- 6:14feel a lot more complex than just, why aren't
- 6:16they telling us? The source, Dark Web Informer,
- 6:19they rated this incident's severity as medium.
- 6:22What does that tell us? Does medium downplay
- 6:25the risk for national infrastructure? That medium
- 6:27rating is interesting, yeah. It likely suggests
- 6:30that, based on the initial assessment from the
- 6:32intelligence provider, the immediate widespread
- 6:35operational impact might not be seen as critical.
- 6:38Perhaps NBN's core systems aren't thought to
- 6:41be immediately compromised for disruption, or
- 6:43their defenses are considered robust enough to
- 6:45contain the immediate fallout. So not DEF CON
- 6:481, maybe? Perhaps not for immediate network collapse,
- 6:51no. But... And this is a really big, big, but
- 6:53medium severity absolutely does not diminish
- 6:57the long -term strategic value of this kind of
- 6:59data if the breach is real. For an adversary,
- 7:02getting hold of detailed technical specs, HFC,
- 7:05FTTC project details, network layouts, that's
- 7:09gold. It's not about a quick hit. It's about
- 7:11reconnaissance. Building up intelligence for
- 7:13future, potentially much more targeted and effective
- 7:15attacks down the road. It's like intelligence
- 7:18gathering for a future campaign. Okay, so medium
- 7:20might relate to immediate operational risk, but
- 7:23the long -term strategic risk could still be
- 7:25very high. Precisely. And that's why understanding
- 7:27this whole picture is so important. Knowledge
- 7:29is valuable, but context is everything, right?
- 7:32This alleged incident, surfacing the way it did,
- 7:35it really underscores that critical information
- 7:37doesn't always come neatly packaged or through
- 7:39the channels you expect. You have to ask, who's
- 7:42reporting it? Why are they reporting it? Who's
- 7:43their audience? And what are the legitimate,
- 7:46complex reasons why an organization like NBN
- 7:49Co. might be navigating this carefully, balancing
- 7:51security, investigation, and that public right
- 7:54to know? forces you to think more critically
- 7:57about where information comes from and why some
- 8:00stories take time to emerge, or maybe never fully
- 8:03do. Understanding the source, like knowing this
- 8:07came via a specialized Intel platform, is key
- 8:10to evaluating it properly. This dive, I think,
- 8:13should definitely make you, our listeners, think
- 8:15about those different layers of information out
- 8:17there, and why some things, even really important
- 8:19things, might not hit the headlines immediately.
- 8:21It challenges you to look deeper. So, okay. We've
- 8:25walked through this alleged NBN Co. breach. The
- 8:28claim from Centap, 306 gigs of potentially sensitive
- 8:31HFC and FDTC data, the source being dark web
- 8:34informers sparking that whole discussion about
- 8:36why it wasn't more public and the really tough
- 8:38questions around transparency for government
- 8:40-linked critical infrastructure. It's a fascinating
- 8:42case study in how information flows or doesn't
- 8:45flow in our digital age. Thanks for taking this
- 8:47deep dive with us on Tech Talks with Kinsoft.
- 8:49Yeah, absolutely. And as we've kind of touched
- 8:51on throughout navigating this stuff, whether
- 8:53it's understanding these big potential threat
- 8:56landscapes like this MB &Co situation or just
- 8:59making sure your own digital security, your business's
- 9:02security. is up to scratch. It really requires
- 9:05staying informed and often getting expert help.
- 9:09Understanding the threats is always that crucial
- 9:11first step to building a proper defense. So for
- 9:13anyone listening who wants to discuss their own
- 9:15security posture or their IT needs in general,
- 9:18you can find a lot more information and support
- 9:20over at www .kinsoft .com .au. Definitely worth
- 9:24checking out. Keep asking questions, everyone.
- 9:26Keep thinking critically about the tech news
- 9:27you see and hear. And always consider the story
- 9:30behind the story. What else is moving beneath
- 9:31the surface? We'll be back soon with more deep
- 9:33dives right here on Tech Talks with Kinsoft.