Latest / Tech Talks With Kinsoft / IINET Data Breach august 2025
Transcript
- 0:00Hello and welcome to Tech Talks with Ken Soft.
- 0:02I'm your host and I'm really glad you could join
- 0:04us in the space where we stop just, you know,
- 0:06reading the headlines. And start to actually
- 0:08unpack them. Exactly. We turn all that complex,
- 0:11sometimes chaotic tech news into usable knowledge
- 0:15for you. It's great to be here. And honestly,
- 0:17chaotic is probably the perfect word for what
- 0:19we're tackling today. Absolutely. Today, we're
- 0:22doing a bit of a retrospective, looking back
- 0:23at a major event from back in August 2025. We're
- 0:27talking about the massive data breach at the
- 0:29Australian ISP, INET. That's right. And I can
- 0:33just hear people asking, you know. Why look back
- 0:36at something from August 2025? It's January 2026
- 0:39now. Right. Why drag this one up? Well, it's
- 0:41all about context. This breach is just a perfect
- 0:43textbook example of this modern paradox we see
- 0:46in cybersecurity. You have all these incredibly
- 0:49sophisticated threats. Sure. AI, state -sponsored
- 0:53actors, all of it. The works. And yet the actual
- 0:55point of failure here was remarkably, I mean,
- 0:58almost painfully simple. It's that classic chain
- 1:01is only as strong as its weakest link scenario,
- 1:04isn't it? It really is. We're looking at how
- 1:07the credentials of just one employee open the
- 1:10door to hundreds of thousands of customer records.
- 1:13It forces us to ask some pretty uncomfortable
- 1:16questions. About how secure our data actually
- 1:18is. Right. Even with these huge telcos. Exactly.
- 1:21So our mission today is to peel back the layers
- 1:24on this one. We're not just going to list what
- 1:26was stolen. We're going to look at the anatomy
- 1:28of the breach, the very specific and surprisingly
- 1:31high risk nature of some of that data. Especially
- 1:34the modem stuff. Oh, yeah. We've got some fascinating
- 1:37research on that. And then we'll talk about what
- 1:38this means for Australian businesses and, you
- 1:41know, for you at home right now. Shall we get
- 1:43into the numbers? Let's do it. So set the scene
- 1:45for us. It's August 16th, 2025. INET, which is
- 1:50owned by TPG Telecom, discovered something is
- 1:52very wrong. Right. They identified an intrusion
- 1:55into their order management system. Now, let's
- 1:58pause there for a second. OK. When people hear
- 2:00order management, they might think of like. a
- 2:03list of invoices or a spreadsheet. Who ordered
- 2:06a router, that kind of thing. Yeah. But in a
- 2:08telco context, this is the nervous system of
- 2:10the customer relationship. It's the system for
- 2:12NBN connections, for new orders. It holds the
- 2:15who, what, and where of the entire customer base.
- 2:18So it's not the vault with the credit card keys,
- 2:20but it's the front desk that knows everyone's
- 2:23business. That's a perfect way to put it. And
- 2:25the scale was, well, substantial. We're not talking
- 2:29a handful of accounts. We're looking at approximately
- 2:31280 ,000 active email addresses. A quarter of
- 2:36a million people's primary communication channel.
- 2:38Yes, gone. In one go. And it wasn't just emails.
- 2:41About 20 ,000 active landline numbers were leaked.
- 2:44And then there was this other batch, about 10
- 2:46,000 records, that had a trifecta of data. Usernames,
- 2:50street addresses, and phone numbers. And that
- 2:52trifecta is dangerous. We'll definitely get to
- 2:54why in a moment. But there was one detail that
- 2:56really stood out, something that feels a bit
- 2:58more invasive than just a phone number. You're
- 3:00talking about modems? Yeah. Around 1 ,700 modem
- 3:03setup passwords were accessed. That is such a
- 3:06specific and, frankly, unsettling piece of data
- 3:10to lose. Most of us just think of our modem as
- 3:13that blinking box in the corner. But before we
- 3:16dive into the nightmare scenarios for those 1
- 3:18,700 people, the big question, how did they get
- 3:21in? Was this an elite team of hackers, you know,
- 3:25lasers and all that? I wish it were that cinematic.
- 3:28It would make for a better movie. But the reality
- 3:31is much more mundane. It looks like it was a
- 3:33phishing attack. Phishing, the thing we've been
- 3:36warned about since the 90s. Very same. The attackers
- 3:39likely tricked a single employee into giving
- 3:41up their login details. Once they had that one
- 3:43key. That was it. They were in the order management
- 3:46system. And this wasn't ransomware, right? They
- 3:48weren't locking things up. No, not at all. This
- 3:50was a quiet extraction. Which is almost creepier.
- 3:52It's like someone breaking into your house not
- 3:54to trash it, but just to photocopy your diary
- 3:56and leave without you knowing. That's a great
- 3:58analogy. They got in, grabbed the data, and got
- 4:01out. And because it wasn't loud, you know, like
- 4:03ransomware, the extraction could happen without
- 4:06triggering all the usual chaos. Now, INET was
- 4:09quick to say the system contained limited personal
- 4:12information. They really stressed that, you know,
- 4:15no driver's licenses, no passports, no credit
- 4:17cards. That sounds good, right? Or is that just
- 4:20corporate spin? Legally, it's better than losing
- 4:23passports for sure. It saves them from certain
- 4:25regulatory headaches. But we have to be so careful
- 4:29with that word limited. Why is that? In cybersecurity,
- 4:32limited data is often the building block for
- 4:35total compromise. Just because they didn't get
- 4:38your credit card number doesn't mean they can't
- 4:39cause you financial harm. Because they can use
- 4:41that limited info to trick you into giving up
- 4:43the rest. Precisely. It creates the foundation
- 4:46for identity fraud, for social engineering. It's
- 4:48the mosaic effect. One piece of tile isn't a
- 4:52picture. But if I have your email, your address,
- 4:54your phone number. Suddenly, I have a very clear
- 4:57picture of who you are. But let's circle back
- 5:00to those modem passwords you mentioned, because
- 5:02that is a risk vector people just don't think
- 5:04about. Yeah, let's unpack this. 1 ,700 modem
- 5:07passwords. I feel like most people get their
- 5:10modem from the ISP. plug it in, use the default
- 5:13password on the sticker, and just forget about
- 5:15it. Why is that so dangerous? Well, if a hacker
- 5:18has your modem password, they potentially control
- 5:20your gateway to the internet. There was a great
- 5:23analysis on this referencing a specific piece
- 5:25of malware called The Moon. The Moon. Sounds
- 5:28like a bad sci -fi movie. It acts like one, too.
- 5:30It targets outdated or compromised routers and
- 5:33turns them into, well, zombies. Okay, so define
- 5:36zombie for me. What is my router actually doing?
- 5:39It's not eating brains. No, but it is being remote
- 5:43controlled. Your router still works for you,
- 5:44you can still stream your shows, but it's also
- 5:46working for them. It becomes part of a botnet.
- 5:49There's a cybercriminal proxy service called
- 5:51Faceless. Faceless? Seriously? Yes, really. And
- 5:55they use these compromised routers to route illegal
- 5:57traffic. So my home internet connection could
- 6:00be used to hide the tracks of a criminal gang.
- 6:03Yes. Criminals need clean IP addresses. If they
- 6:07attack a bank from a known criminal server, they
- 6:10get blocked instantly. But if that traffic looks
- 6:13like it's coming from a nice family home in a
- 6:15suburb somewhere. Just passes right through.
- 6:17And if your modem password is out there, you
- 6:20become a node in their network. You might not
- 6:22even notice a slowdown, but your IP address,
- 6:25your digital fingerprint, is effectively laundering
- 6:28cybercrime. That is terrifying. That completely
- 6:31changes the stakes from someone might read my
- 6:34emails to the police might knock on my door.
- 6:37Exactly. That's why those 1 ,700 passwords were
- 6:39such a critical loss. It turns the victims into
- 6:41unwitting accomplices. And it's not just the
- 6:44hardware risks. We talked about social engineering.
- 6:47When you combine an address, a phone number,
- 6:49and the fact that you're an iNet customer, the
- 6:51scams can get incredibly convincing. Oh, they
- 6:54really can. And we saw this happen. There were
- 6:56discussions on Reddit right after the breach.
- 6:57One user posted about an SMS they got about NBN
- 7:01planned maintenance. I remember this. It wasn't
- 7:03a generic dear customer text, was it? No, and
- 7:06that's the danger. The text mentioned their specific
- 7:09suburb. I think it was Carlisle. It had accurate
- 7:12dates. It looked completely legitimate. And it
- 7:15arrived just days after the breach news broke.
- 7:17So put yourself in their shoes. You know there's
- 7:21been a breach. You're on edge. And then a text
- 7:24comes through that gets your location right,
- 7:26your provider right, and asks you to click a
- 7:27link. Your brain just says, oh, this must be
- 7:30real. That's the metadata bypassing our natural
- 7:33skepticism. Exactly. That is why saying it's
- 7:36limited personal information is so misleading.
- 7:38That limited info is the fuel for these high
- 7:41success rate scams. Speaking of trust, the customer
- 7:45reaction wasn't exactly sympathetic, was it?
- 7:48Checking the community pulse, it felt like there
- 7:50was a lot more frustration there than just this
- 7:52one incident. It was a tipping point. You have
- 7:55to remember, Inet used to be the darling of the
- 7:57Aussie tech scene. The gamers ISP, great local
- 8:00support. Right. But longtime users were already
- 8:03unhappy. There was a lot of anger about them
- 8:06offloading their email services to a third party,
- 8:08the messaging company. Oh, that's right. People
- 8:11were suddenly being asked to pay for email addresses
- 8:13they'd had for free for 20 years. Correct. It
- 8:16was a messy migration. And the sentiment was
- 8:18scathing. People were saying, I'm paying this
- 8:20company to keep my data secure. And now it's
- 8:23been leased anyway. There was this strong perception
- 8:26that ever since TPG bought iNet, it's been a
- 8:29strategy of value extraction. Value extraction.
- 8:32That sounds like corporate speak for squeeze
- 8:34it till it's dry. It's exactly that. The theory
- 8:37that you buy a beloved brand, keep the name,
- 8:40but you gut the costs on infrastructure, support,
- 8:43and engineering to maximize profit. The feeling
- 8:46was that support was gone, the tech was aging,
- 8:49and security gaps were inevitable. The hollowed
- 8:51out theory. You keep the paint fresh, but you
- 8:54strip the engine. That's the perception. And
- 8:56a breach like this, well, it confirms all those
- 8:59fears for people. Now, INED did take legal action.
- 9:02They got an interim injunction to stop anyone
- 9:05from publishing the stolen data. That sounds
- 9:07impressive. But does a hacker in Russia care
- 9:11about an Australian court order? Not in the slightest.
- 9:13An injunction like that, it stops legitimate
- 9:16media from publishing. the raw data. It stops
- 9:19a competitor from using it. But the bad actors
- 9:22on the dark web are not checking the court registry
- 9:25before they sell a database. Exactly. Once that
- 9:27data is exfiltrated, it's out there. You can't
- 9:30litigate it back into the bottle. It's like trying
- 9:32to recall a rumor. So that brings us to the bigger
- 9:35picture. This wasn't just happening to INET,
- 9:38right? No, not at all. We need to zoom out. Around
- 9:41the same time, the UK telco cult was hit by a
- 9:44ransomware gang. And here in Australia, we've
- 9:47seen TPC, Telstra, Tangerine, all of them hit
- 9:51by these kinds of credential based breaches.
- 9:53So if all the big players are getting hit, are
- 9:56the hackers just too good? Or are the companies
- 9:59failing at something basic? I'm going to quote
- 10:01someone here, Rich Atkinson from Airtame, because
- 10:04he put it so bluntly. He said these attacks are
- 10:05not new nor particularly sophisticated. So the
- 10:09industry knows about this stuff. They absolutely
- 10:11know about phishing and credential harvesting.
- 10:13These aren't some secret zero -day exploits.
- 10:16So why does it keep happening? It comes down
- 10:18to architecture, specifically a failure to implement.
- 10:22Zero trust and, you know, robust multi -factor
- 10:26authentication or MFA on their internal tools.
- 10:29Zero trust. We hear that buzzword all the time.
- 10:32What does it actually mean in practice? Think
- 10:34of old security like a castle. Yeah. Big walls,
- 10:37big moat. Once you're inside, you're trusted,
- 10:40you can go anywhere. And stealing that employee's
- 10:42password was like getting through the main gate.
- 10:44Exactly. Once they were in, the system said,
- 10:47oh, you have a password. Welcome. Look at everything.
- 10:49Okay. And zero trust. Zero trust is like a high
- 10:53security hotel. Just because you're in the lobby
- 10:55doesn't mean you can get into the penthouse.
- 10:57You need a key card for the elevator, a key for
- 10:59the floor, a key for the room. It never stops
- 11:02checking. It assumes the bad guy is already inside.
- 11:04So even with the password, a zero trust system
- 11:07would have challenged them. Ideally, yes. It
- 11:10should ask, OK, you have the password, but are
- 11:12you on the usual device? Why are you trying to
- 11:14download 280 ,000 records at 3 door a .m.? And
- 11:18clearly that didn't happen here. No. Australian
- 11:21enterprises are failing to build systems that
- 11:23assume credentials will be compromised. They're
- 11:26still just building bigger castle walls. It's
- 11:28frustrating. We tell everyone to put two -factor
- 11:31on their Facebook account. How is a major telco
- 11:34missing this on a critical internal database?
- 11:37It often comes down to friction and old systems.
- 11:40That order management system might be 10, 15
- 11:43years old. Retrofitting modern security onto
- 11:46old tech is hard. It's expensive. And it slows
- 11:49things down. It does. So they trade security
- 11:51for speed until the breach happens. And then
- 11:54they realize the cost of not doing it was much,
- 11:56much higher. So let's pivot to the so what part
- 11:59of this. We've analyzed it. What did we learn
- 12:02and what should people do? Let's start with any
- 12:03businesses listening. For businesses, the takeaway
- 12:06is an absolute intolerance for single factor
- 12:09authentication. A single password is just negligence
- 12:12at this point. If you have employees accessing
- 12:14customer data, MFA has to be mandatory. No exceptions.
- 12:18And there's a second layer too, right? Yes. Monitoring
- 12:21for data exfiltration. to find that for us. We
- 12:23spend so much money stopping people getting in,
- 12:26the firewalls, the antivirus. We forget to watch
- 12:29what's going out. Data exfiltration is the theft.
- 12:32If a system that usually looks at one record
- 12:35at a time suddenly exports a list of 280 ,000,
- 12:38alarms should be screaming. It's like a bank
- 12:41teller suddenly walking out with a wheelbarrow
- 12:43full of cash. Even if they have a badge, someone
- 12:45should probably ask a question. Precisely. Automated
- 12:48tools can spot this. User Dave usually looks
- 12:51at 50 records a day. Today he looked at 50 ,000.
- 12:53That's an anomaly. Block it. Okay, now for our
- 12:57listeners, the everyday users. What's the to
- 12:59-do list? Number one, the modem. If you're using
- 13:03the ISP's modem and you've never changed the
- 13:04password on the sticker, do it today, right now.
- 13:07Don't let your rider become a zombie for the
- 13:09faceless game. Exactly. Number two. Vigilance
- 13:12on texts. We saw how good that scam text was.
- 13:15If you get a text about billing or maintenance,
- 13:17do not click the link. No matter how real it
- 13:19looks. Go to the website directly. Type it into
- 13:21your browser yourself. Takes 10 extra seconds.
- 13:24And finally. Password hygiene. I know we say
- 13:27it all the time, but use a password manager.
- 13:30If you are using the same password for your iNet
- 13:32account that you use for your bank, that's called
- 13:34credential stuffing, hackers take that one password
- 13:37and try it. So one breach becomes a breach of
- 13:40your entire life. It can be. Unique passwords
- 13:43are your only real defense. It's simple advice,
- 13:46but it works. It does. And I want to leave our
- 13:49listeners with one final thought. We trust these
- 13:52companies with our entire digital lives. But
- 13:55if a massive telco with all its resources can
- 13:59be opened up by one employee clicking one phishing
- 14:01link, how secure is the vendor you trust with
- 14:05your data? That is a sobering thought. It really
- 14:07highlights that security isn't something you
- 14:10can just outsource and forget about. It's an
- 14:11active responsibility. Well, on that note, thank
- 14:14you for walking us through all this. It's complex
- 14:16stuff, but understanding how these failures happen
- 14:18is the best way to protect yourself. Absolutely.
- 14:21Stay curious and stay skeptical. If this discussion
- 14:24has raised any red flags for you, for your own
- 14:26business's safety, maybe you're wondering if
- 14:29your internal tools have the right MFA, or if
- 14:31you're vulnerable, we strongly suggest you go
- 14:33to www. Thank you. www .kinsoft .com .au. You
- 14:39can discuss your security and your IT needs with
- 14:41people who live and breathe this stuff. Don't
- 14:43wait for the breach to happen. Thanks for listening
- 14:46to Tech Talks with Kinsoft. We'll catch you next
- 14:49time.