Latest / Tech Talks With Kinsoft / NSW Rural Fire Service – Nova Ransomware Hits an Emergency Service
Transcript
- 0:00Imagine waking up in the middle of the night
- 0:02to the smell of smoke. Oh, yeah. That's a nightmare.
- 0:05Right. Your house is on fire. You scramble for
- 0:07your phone. You dial emergency services. But
- 0:10instead of a dispatcher calmly telling you, help
- 0:13is on the way, the line is just dead. Or even
- 0:16worse. The dispatch system is completely frozen,
- 0:20like locked behind a flashing digital ransom
- 0:23note. Which is terrifying. It really is. And
- 0:25today we are looking at this terrifying modern
- 0:27reality. You know, what happens when the very
- 0:30people you rely on for rescue suddenly find themselves,
- 0:33well, held hostage by a massive cyber attack?
- 0:35So welcome to this deep dive. Thanks. Yeah, it
- 0:39is a scenario that literally keeps critical infrastructure
- 0:41defenders awake at night. I bet. And we are pulling
- 0:44today's insights from a June 24th, 2026 excerpt
- 0:48of Tech Talks with Kinsoft. Right. And the focus
- 0:51is this really major cybersecurity incident from
- 0:54late June 2026 involving a ransomware attack
- 0:57on the New South Wales Rural Fire Service, which
- 0:59is widely known as the NSW RFS. And we are using
- 1:03this specific attack as a lens for you guys listening
- 1:06because, I mean, this isn't just about reading
- 1:09a news headline and moving on, right? Exactly.
- 1:11We want to tear the hood off a modern cyber breach.
- 1:13We're going to explore the mechanics of how attackers
- 1:16exploit these seemingly mundane vulnerabilities.
- 1:19Yeah. And then dive into the absolute public
- 1:22relations nightmare of managing a crisis when
- 1:26your servers are locked and you don't even have
- 1:28the facts yourself. It's a huge mess. Yeah. So
- 1:31let's establish the sheer scale of the target
- 1:33here first because, well, I think it frames the
- 1:36entire disaster. Definitely. The scale is really
- 1:39what makes this unprecedented. Yeah. I mean,
- 1:41the New South Wales Rural Fire Service, it is
- 1:44not just some local county fire department. Right.
- 1:46It is actually the world's largest volunteer
- 1:48fire service. Wow. Yeah. We are talking about
- 1:51an organization boasting more than 70 ,000 members.
- 1:5470 ,000? Yep, 70 ,000. And they cover almost
- 1:58the entirety of the state of New South Wales
- 1:59and Australia. That is just a staggering logistical
- 2:02footprint. Just managing the roster for 70 ,000
- 2:07people sounds impossible. Oh, absolutely. Let
- 2:10alone securing their digital access. And the
- 2:13Kinshoff Report notes this is Australia's first
- 2:16confirmed ransomware attack on a government agency
- 2:18in 2026. Yeah. Which, I mean, it sets a very
- 2:23grim tone for the year. It really does. Yeah.
- 2:25However, the report leads with what they call
- 2:28the good news up front. Okay, we like good news.
- 2:31Right. So the actual firefighting operations,
- 2:33the emergency response, the people out on the
- 2:36front lines saving lives, that was entirely unaffected.
- 2:38Oh, thank goodness. Yeah. The attackers breached
- 2:41the corporate ICT systems, so the information
- 2:44and communication technology, but they never
- 2:46touched the trucks, the dispatch radios, or the
- 2:49actual operational response network. Okay, I
- 2:51really want to dig into that mechanism because
- 2:53that doesn't sound like blind luck. No, not at
- 2:55all. I mean, if a virus hits my home computer,
- 2:57it spreads to everything on my Wi -Fi, right?
- 2:59It hits my printer, my phone, my smart TV. So
- 3:02how does a massive digital fire burn down the
- 3:05administrative side of a fire service, but the
- 3:08trucks and radios completely dodge the flames?
- 3:10Well, that survival comes down to a fundamental
- 3:13architectural principle called network segmentation.
- 3:16Okay. In critical infrastructure. And this is
- 3:19whether you are dealing with a power grid, a
- 3:22major hospital or, you know, a statewide fire
- 3:25service. You never build your network as one
- 3:28giant open room. Right. You intentionally isolate.
- 3:33the operational technology, the OT from the information
- 3:36technology, the IT. It's kind of like building
- 3:38a submarine, right? Yeah, that's a good way to
- 3:40look at it. Like you don't build it as one long
- 3:42hollow tube. You build it with heavily reinforced
- 3:45watertight compartments, the bulkheads. Exactly.
- 3:48So if a torpedo breaches the galley, you seal
- 3:50the heavy steel doors. Right. The galley floods,
- 3:52the cooks are having a terrible day, but the
- 3:54engine room stays completely dry and the propellers
- 3:56just keep turning. That is a perfect way to vehicleize
- 3:59it, yeah. The corporate IT network, so the galley
- 4:02in your submarine analogy, it has to connect
- 4:04to the open Internet. Because they have to do
- 4:06normal business stuff. Exactly. Administrators
- 4:08need to receive external emails. They need to
- 4:10process payroll. They need to allow remote access
- 4:13for staff. And because it interacts with the
- 4:15outside world, it inherently has hundreds of
- 4:18windows and doors. Vulnerabilities, basically.
- 4:20Right. But the operational side, the dispatch
- 4:23systems and radio networks, they do not need
- 4:25to check Internet email. So architects physically
- 4:28and logically sever the connection between the
- 4:32two. They seal the bulkhead. They do. In many
- 4:35cases, it is an air gap, meaning there's actually
- 4:37no physical cable connecting the two networks
- 4:40whatsoever. Wow. Or if they must communicate,
- 4:43it's through heavily, heavily monitored firewalls
- 4:46that only allow very specific one way data traffic.
- 4:50Yeah. And that segmentation is literally the
- 4:53only reason the RFS didn't face a catastrophic
- 4:56public safety emergency. OK, but the torpedo
- 4:58still hit the corporate side. It did. And that
- 5:00brings us to, honestly, the most jarring part
- 5:03of the Kinsoft report. If a massive government
- 5:06agency with 70 ,000 personnel gets breached in
- 5:092026, I mean, the mind instantly jumps to elite
- 5:13nation state hackers, right? Zero day exploits,
- 5:17advanced malware. Exactly. Dropped from a satellite
- 5:20or something. But the report details an entry
- 5:23vector that is aggressively mundane. Very mundane.
- 5:26The entry vector was a compromised account. combined
- 5:29with an internet -facing remote access system.
- 5:32Unbelievable. Specifically, the reports point
- 5:35to Citrix, which is a highly common remote access
- 5:38gateway used by large organizations all over
- 5:41the world. Wait, hold on. You are telling me
- 5:43that a world -record -holding government agency
- 5:45was compromised by a stolen or guessed password?
- 5:48Basically, yeah. Someone just typed a username
- 5:50and a password into a public website and walked
- 5:52right into the corporate mainframe? Well, that's
- 5:54the reality of modern cyber warfare. The most
- 5:57common way into a network is simply logging in.
- 5:59That is wild. I mean, think about the logistical
- 6:02nightmare you pointed out earlier. You have 70
- 6:04,000 volunteer members. Right. Rural fire stations
- 6:09from their home computers, from personal mobile
- 6:12devices on cellular networks. Right. They're
- 6:14everywhere. Yeah. So to make that work, the RFS
- 6:18has to use gateways like Citrix or VPNs. Because,
- 6:21I mean, if I am a volunteer captain sitting in
- 6:24my living room and I need to update a roster,
- 6:26I have to securely tunnel into the headquarters
- 6:28network. Exactly. And that tunnel essentially
- 6:31paints a picture of a corporate desktop right
- 6:34there on your home screen. If that gateway only
- 6:38requires a single key, just a password, It is
- 6:42incredibly fragile. Yeah, clearly. And attackers
- 6:45don't even have to manually guess passwords anymore.
- 6:47They use a technique called credential stuffing.
- 6:49Right. I've heard of this. Yeah. They take millions
- 6:51of usernames and passwords stolen from old breaches,
- 6:54say a random fitness app that got hacked back
- 6:56in 2021, and they run automated scripts. Just
- 6:59blasting them at the login page. Exactly. To
- 7:01test those exact same passwords against the RFS
- 7:04Citrix gateway. And because humans reuse passwords
- 7:06everywhere, eventually one unlocks the door.
- 7:09But that implies the RFS was relying... entirely
- 7:12on just a password as the only lock on the door.
- 7:14It feels, honestly, incredibly reckless for the
- 7:17modern era. It does. I mean, my bank, my streaming
- 7:20service, even my local gym app forces me to confirm
- 7:23my identity with my phone before I can log in.
- 7:26How is it that a government gateway lacked that
- 7:29basic friction? It often comes down to budget,
- 7:32legacy systems, and frankly, user friction. Right.
- 7:36Rolling out advanced security to a constantly
- 7:38shifting roster of 70 ,000 volunteers is expensive
- 7:42and technically taxing. But as the RFS learned,
- 7:46the alternative is much worse. Yeah, clearly.
- 7:50So what did they do once they realized they were
- 7:52in? The moment the breach was detected, they
- 7:54executed standard containment protocols. They
- 7:57forced a massive global password reset for all
- 8:00members. Okay. That makes sense. Yeah, and that
- 8:02included external services those members use,
- 8:04which kind of gives you an idea of how far the
- 8:06tentacles of a compromised account can really
- 8:08reach. Right, because if they got into their
- 8:10email, they could reset everything else. They
- 8:12also restricted access to certain websites from
- 8:15RFS computers, right? I assume that wasn't just
- 8:18to stop employees from browsing social media.
- 8:20That was a tactical move to stop the bleeding.
- 8:23Precisely. Once an attacker is inside that Citrix
- 8:26tunnel, they don't just sit there. They engage
- 8:29in lateral movement. Meaning they start looking
- 8:31around? Yes. They start the network, they locate
- 8:34the data they want to steal, and then they try
- 8:36to establish an outbound connection to their
- 8:39own dark web servers to exfiltrate that data.
- 8:42Oh, okay. So by blocking access to external sites...
- 8:46The RFS was trying to sever the attacker's outbound
- 8:48data pipeline. That makes total sense. And this
- 8:51feels like a direct warning to anyone listening
- 8:53right now who works remotely. Like if you log
- 8:56into your company's network from your couch on
- 8:58a Friday, the mechanics protecting you have to
- 9:00be bulletproof. Absolutely. The Kinsoft report
- 9:03is very explicit about the technical reality
- 9:05check here. Oh, the report is completely unyielding
- 9:08on this point. A password alone is fundamentally
- 9:10broken as a security control. Broken. If your
- 9:14organization operates a VPN, Citrix, remote desktop
- 9:17protocol, or any external gateway, it absolutely
- 9:21must be shielded by multi -factor authentication,
- 9:24MFA, without exception. Let's break down the
- 9:29mechanics of why MFA is the silver bullet here,
- 9:32rather than just throwing the acronym around.
- 9:33It's not just an annoying extra step. It fundamentally
- 9:36changes the math for the attacker, doesn't it?
- 9:39It changes the physical requirements of the attack.
- 9:42Authentication relies on three concepts. Something
- 9:45you know, something you have, and something you
- 9:47are. A password is just something you know. And
- 9:49a data broker on the dark web can know it too.
- 9:52Right, they just buy it. Exactly. But MFA introduces
- 9:54something you have. When you enter your password,
- 9:57the system generates a time -sensitive cryptographic
- 10:00token that is sent out of band, usually to a
- 10:03physical authenticator app on your personal smartphone.
- 10:07Meaning the attacker sitting in Eastern Europe
- 10:09can buy my password for 50 cents. But unless
- 10:12they also physically break into my house and
- 10:14steal a phone out of my pocket, that password
- 10:16is useless. Exactly. That is the mechanical genius
- 10:18of it. And the report also. heavily emphasizes
- 10:22active monitoring for unusual logins. Oh, interesting.
- 10:26Yeah, because a password and MFA stop the initial
- 10:29breach, but behavioral monitoring catches the
- 10:32anomalies. If an RFS volunteer who historically
- 10:35logs in from Sydney at 5 .00 p .m. suddenly initiates
- 10:39a Citrix session from a masked IP address at
- 10:423 .0 a .m. The system should notice that. Right.
- 10:45The network shouldn't just ask for a password.
- 10:47It should flag the session and lock the account
- 10:49entirely. Okay. So the attackers found a digital
- 10:52bulkhead that hadn't been sealed properly, and
- 10:54they walked right through. That brings up the
- 10:56obvious question. Who is actually on the other
- 10:58side of that keyboard? Because this is where
- 11:00the dynamic of the attack shifts from technical
- 11:02lockpicking to outright psychological warfare.
- 11:05It really does. So the group claiming responsibility
- 11:08for this breach operates under the name Nova,
- 11:10and they are also tracked by threat intelligence
- 11:12as Rolord. Nova. They always pick names that
- 11:17sound like a Bond villain's shell company, don't
- 11:19they? They really do. But they aren't just a
- 11:22few rogue coders in a basement, are they? The
- 11:25Kinsoft source labels them a ransomware -as -a
- 11:28-service operation. Yes. The term ransomware
- 11:31-as -a -service, or RIE, it basically represents
- 11:34the industrialization of cybercrime. The industrialization.
- 11:37Think of legitimate software platforms you use,
- 11:40like cloud storage or project management software.
- 11:44You pay a subscription, you get a slick dashboard,
- 11:47and the company handles all the heavy lifting
- 11:49in the background. Right. Well, Nova operates
- 11:51the exact same way on the dark web. They're developers.
- 11:54They write the sophisticated encryption malware.
- 11:57They build the leaked sites. They manage the
- 11:59cryptocurrency negotiation portals. So they build
- 12:02the weapon, but they don't necessarily pull the
- 12:04trigger themselves. That is the terrifying part.
- 12:06They franchise the weapon out to independent
- 12:08contractors who are known as affiliates. Oh,
- 12:10wow. Yeah. The affiliates are the ones who actually
- 12:13buy the stolen Citrix passwords. They execute
- 12:16the credential stuffing and they navigate the
- 12:19victim's network. Once the affiliate has stolen
- 12:21the data and deployed the Nova encryptor, they
- 12:24just sit back. And if the victim pays the ransom,
- 12:26the Nova developers take a 20 or 30 percent cut
- 12:29for providing the software and the affiliate
- 12:31keeps the rest. It is a literal franchise model
- 12:34for digital extortion. That is crazy. It is.
- 12:37It lowers the barrier to entry so much that any
- 12:40criminal with just like basic networking skills
- 12:43can become a devastating threat. And Nova has
- 12:47been refining this business model since early
- 12:492025. According to the source. They have. Which
- 12:53means by the time they hit the New South Wales
- 12:55Rural Fire Service in late June 2026, their playbook
- 13:00is highly optimized for maximum psychological
- 13:02impact. Right. And they proved that on June 26th,
- 13:05when they listed the RFS on their public leak
- 13:07site and dropped a massive, absolutely terrifying
- 13:09claim, NOVA publicly stated they had stolen 300
- 13:12gigabytes of data. 300 gigabytes. Yeah. To put
- 13:15that in perspective for you listening, if you
- 13:17are stealing dense corporate text documents,
- 13:19PDFs and spreadsheets. 300 gigs is millions upon
- 13:22millions of pages. Oh, easily. It is a number
- 13:25engineered to induce total panic in the RFS boardroom.
- 13:28And panic among the 70 ,000 volunteers who suddenly
- 13:31fear their personal addresses, banking details
- 13:34and identities are in the hands of a cartel.
- 13:36Absolutely. But then we get the counter -narrative,
- 13:39right? The RFS investigates, they look at their
- 13:42internal logs, and they release a statement pushing
- 13:43back. They do. They say the forensics show many
- 13:46of the affected files were purely historical,
- 13:49routine, old administrative data. And crucially,
- 13:52they state there is zero evidence that sensitive
- 13:55personal information was accessed. Right. And
- 13:58this specific moment in the timeline is what
- 14:01the Kinsoft source calls a really useful teaching
- 14:03moment. Why is that? Well... We have this massive
- 14:07public discrepancy. The attacker claims a catastrophic
- 14:10data heist, but the victim claims a minor low
- 14:14-impact intrusion. It creates a Schrodinger's
- 14:17data scenario for the public. Exactly. Until
- 14:19the final forensics are published, the stolen
- 14:21data is simultaneously a highly sensitive catastrophe
- 14:24and a completely worthless pile of digital dust.
- 14:28Perfectly said. I mean, think about the megaphone
- 14:30analogy. Let's hear it. A burglar breaks into
- 14:33your house. Instead of sneaking away quietly,
- 14:35he stands on your front lawn with a megaphone
- 14:38shouting to the whole neighborhood that he just
- 14:40stole your priceless family heirlooms, your passport,
- 14:44and your life savings. Right. Meanwhile, you're
- 14:46standing in your garage, looking around, realizing
- 14:50the safe is locked, and the only thing missing
- 14:52is a cardboard box of old tax returns from 1998.
- 14:56That perfectly captures the chaos of incident
- 14:58response. The hardest truth to accept is that
- 15:01in the first 48 hours of a breach, both the megaphone
- 15:04claim and the garage reality can coexist. Neither
- 15:08side actually has the full picture. But why would
- 15:10the hacker risk their credibility by lying? I
- 15:13mean, if they exaggerate and the victim calls
- 15:15their bluff, doesn't the hacker lose all their
- 15:17leverage? Well, you have to understand the leverage
- 15:19mechanism. Hackers don't really care about their
- 15:21long -term honesty rating. Right. They care about
- 15:24creating immediate, unbearable pressure. If Nova
- 15:27claims 300 gigabytes, the media runs with that
- 15:30number. Of course they do. The public demands
- 15:31answers. The pressure on the RFS executives becomes
- 15:35so intense that the hackers hope they will just
- 15:37pay the ransom to make the negative headlines
- 15:40disappear, regardless of what data was actually
- 15:42stolen. So it's extortion by PR crisis, not just
- 15:45by encryption. Exactly. That makes the victim's
- 15:48communication strategy a total minefield. If
- 15:51I am the RFS, my first instinct is to run to
- 15:53a microphone and say, everyone calm down. They
- 15:56just got the 1998 tax returns. Your data is safe.
- 15:59And that instinct is exactly what destroys organizations.
- 16:02Really? Oh, yeah. Forensics take weeks. Finding
- 16:06out exactly which server an attacker touched
- 16:08requires parsing millions of lines of network
- 16:11logs. Right. If you rush to the microphone and
- 16:13confidently declare no sensitive data was lost,
- 16:16and then a week later Nova publishes the current
- 16:18payroll data of your volunteers on the dark web,
- 16:21your organization's credibility instantly evaporates.
- 16:25You look incompetent, or worse, you look like
- 16:27you were actively covering it up. Yes, and regaining
- 16:30the trust of your workforce and the public after
- 16:32that is nearly impossible. Managing that gap
- 16:36between the attacker's claims and the slow reality
- 16:39of digital forensics is honestly the ultimate
- 16:42test of leadership during a cyber crisis. That
- 16:44brings us to the universal playbook, because
- 16:46the mechanics we are discussing here don't just
- 16:49apply to a government fire service. Not at all.
- 16:51If you are listening to this and you run a logistics
- 16:54company or you manage a small design firm or
- 16:57you are just trying to keep your personal data
- 16:59secure, you are operating in the exact same threat
- 17:02landscape. You are. The Kinsoft report distills
- 17:06this entire saga down to core takeaways that
- 17:08apply to everyone. They do, and the takeaways
- 17:10are intensely practical. The first revolves around
- 17:13the technical reality of the entry vector. We
- 17:16keep coming back to compromised accounts on remote
- 17:18access points because it remains the Achilles
- 17:20heel of modern networks. Meaning, stop worrying
- 17:23about movie -style hackers bypassing firewalls
- 17:26with 3D graphics and start worrying about your
- 17:28employees' weak VPN password. It's exactly that.
- 17:32The report explicitly advises that organizations
- 17:35must verify that the remote access gateways are
- 17:38locked down. Right. It is not enough to assume
- 17:40IT handled it three years ago. You need active
- 17:43patching, meaning software vulnerabilities are
- 17:46closed the moment updates are released. You need
- 17:49multi -factor authentication universally enforced.
- 17:52And the source strongly recommends that if you
- 17:55are uncertain about the state of your remote
- 17:56access, you need to initiate a comprehensive
- 17:58review of your IT security needs immediately.
- 18:02potentially even engaging specialists to audit
- 18:04those entry points. And the second takeaway deals
- 18:06with the psychological warfare side, right? The
- 18:09crisis management. Yeah. Because if you wake
- 18:11up tomorrow and Nova or some other ransomware
- 18:13group lists your company on their leak site claiming
- 18:16they stole half your servers, what is the actual
- 18:19play? The play is emotional discipline. The report
- 18:22frames it around the claims problem. You must
- 18:24resist the urge to panic and you must equally
- 18:27resist the urge to blindly dismiss the threat.
- 18:30You have to walk the tightrope of transparency.
- 18:32Transparency paired with verified facts. The
- 18:35golden rule is investigate aggressively, verify
- 18:40through immutable log files, and communicate
- 18:42only what you know to be absolutely true. Right.
- 18:45It is incredibly powerful to stand before your
- 18:48employees or the public and say, we confirm an
- 18:51unauthorized entry occurred. We see signs of
- 18:54data access, but we do not yet have forensic
- 18:56confirmation of exactly what files were taken.
- 18:59We will update you the moment the logs confirm
- 19:01the scope. That level of candor buys you grace.
- 19:04It tells the public you are in control of the
- 19:06investigation, even if you weren't in control
- 19:09of the breach. You own the narrative rather than
- 19:11letting a criminal with a megaphone own it for
- 19:13you. It strips the attacker of their primary
- 19:15weapon, which is uncertainty. The advice from
- 19:19the source is clear. Stay patched to defend the
- 19:22network and stay skeptical of attacker claims
- 19:24to defend the narrative. It really is a remarkable
- 19:27case study. We started by looking at a 70 ,000
- 19:29strong volunteer fire service that barely dodged
- 19:32a catastrophic operational failure thanks to
- 19:35the digital bulkheads of network segmentation.
- 19:37We traced the fatal flaw back to a single compromised
- 19:40password on an exposed Citrix gateway, a flaw
- 19:44that multi -factor authentication could have
- 19:46totally neutralized. Completely. And we unpacked
- 19:49the shrug. Hardinger's data crisis, where a highly
- 19:52organized ransomware as a service cartel tried
- 19:55to manufacture a PR nightmare to force a payout.
- 19:58It encapsulates everything challenging about
- 20:00defending modern infrastructure. The technical
- 20:03solutions are often straightforward. But implementing
- 20:06them across human networks and managing the fallout
- 20:08when they fail is deeply complex. It really is.
- 20:12Now, based on everything we've extracted from
- 20:14the Kinsoft report and the mechanics we've explored
- 20:16today, what is the final provocative thread you
- 20:19want the listener to pull on after this deep
- 20:21dive? Well, I think it requires us to fundamentally
- 20:23rethink the definition of a data breach. Okay.
- 20:26How so? Traditionally, we view ransomware as
- 20:29a technical theft. We picture gigabytes of data
- 20:32being siphoned out of a server, holding corporate
- 20:34secrets hostage. But look closely at Nova's playbook
- 20:37here. They used a dark web blog to blast a completely
- 20:42unverified 300 gigabyte claim to the global media.
- 20:46It forces a disturbing realization. What if the
- 20:50true weapon of modern ransomware isn't the data
- 20:53they successfully steal? Wait, you're saying
- 20:56the data is secondary. I am saying the primary
- 20:58weapon is the public panic, the immediate loss
- 21:01of trust, and the reputational damage a cartel
- 21:04can manufacture with a single exaggerated blog
- 21:08post. Wow. The attacker doesn't actually need
- 21:10to steal the crown jewels to hold your organization
- 21:12hostage. They simply need the neighborhood to
- 21:14believe they have them. They don't need the jewels.
- 21:16They just need the megaphone. That completely
- 21:18changes how you calculate risk. It really does.
- 21:21It means a breach isn't just a technical failure.
- 21:23It is a direct assault on the psychological trust
- 21:25between an organization and the people it serves.
- 21:28Exactly. And when that organization is the emergency
- 21:30service you expect to save your life, that manufactured
- 21:33panic is incredibly destructive. It demands that
- 21:36we build defenses not just around our servers,
- 21:38but around our organizational narratives. That's
- 21:41a heavy, critical thought to leave on. We will
- 21:43let you all mull that over. Thank you for joining
- 21:46us on this deep dive into the architecture of
- 21:48modern cyber conflict. Before you close your
- 21:51laptop or lock your phone today, take five minutes
- 21:54to check multi -factor authentication settings
- 21:56on your most critical accounts. Don't leave your
- 21:58digital front door swinging in the wind. We'll
- 22:00catch you on the next one.