Latest / Tech Talks With Kinsoft / Goodstone Group Breach – Passport Scans Leaked in CMD Ransomware Attack
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Glad to be
- 0:02here. You know, I was just thinking before we
- 0:04hit record, I want you to imagine waking up to
- 0:07find that your employees' actual passports aren't
- 0:10just, you know, stolen. Right. Which is bad enough.
- 0:14Exactly. But they are actively being auctioned
- 0:17off on, well, essentially a dark web version
- 0:20of eBay. Yeah, to the highest bidder. It's completely
- 0:23wild. It feels entirely dystopian, right? But
- 0:26it's actually unfolding right in our own backyard.
- 0:28So today we are undertaking a thorough exploration
- 0:31into a recent close to home cyber incident to
- 0:34understand exactly how modern ransomware groups
- 0:37are evolving their extortion playbooks. Yeah.
- 0:39And we're looking specifically at how they're
- 0:41moving away from those private behind closed
- 0:44doors threats into these massive public spectacles.
- 0:47Right. Highly public market driven spectacles.
- 0:49We're basing our discussion today on an exclusive
- 0:52article that David Hollingworth published in
- 0:54Cyber Daily back on May 15th, 2026. And really,
- 0:58the whole landscape of digital threats is I mean,
- 1:00it's undergoing this fundamental economic shift
- 1:03right now. Yeah, definitely. Okay, let's unpack
- 1:05this. I want you to put yourself in the shoes
- 1:07of a business leader for a second. You are running
- 1:12a successful, well -regarded local business,
- 1:16right? Implying hundreds of people in your community.
- 1:18A real pillar of the town. Exactly. You manage
- 1:21your properties, you take care of your staff,
- 1:23and then completely out of the blue, you realize
- 1:25that your most sensitive, confidential, corporate,
- 1:29and personal documents are just Up for public
- 1:33auction. In front of the entire world. Yes. The
- 1:36psychological whiplash of that transition, you
- 1:38know, going from standard daily operations to
- 1:41a globally visible crisis, it's just staggering.
- 1:44It really is. And it's designed to be completely
- 1:48destabilizing. That jarring transition is actually
- 1:50the primary source of leverage for these threat
- 1:53actors now. Right. They're no longer just exploiting
- 1:55software vulnerabilities. They are actively engineering
- 1:58a pressure cooker environment. Because they want
- 2:00everyone panicking. Right. Exactly. They want
- 2:02the board of directors, the IT team, the local
- 2:04community, everybody reacting all at once. It
- 2:07creates this chaotic environment where, honestly,
- 2:10paying a ransom starts to look like the only
- 2:12valve to release all that pressure. Yeah. And
- 2:14that pressure cooker is currently a stark reality
- 2:17for the Goodstone Group. Yeah, unfortunately.
- 2:19For context, the Goodstone Group is a major hospitality
- 2:22operator based down in Devonport. So right in
- 2:25northern Tasmania. Right. And they are a massive
- 2:28part of that local economy. According to the
- 2:31reporting, they employ over 350 Tasmanians. That's
- 2:35a huge footprint for a regional area. It really
- 2:37is. We're talking about nine different hotel
- 2:41properties, five standalone bottle shops and
- 2:43a nightclub property, too. Wow. Yeah. This is
- 2:46a regional hospitality staple, deeply, deeply
- 2:49embedded in its community. And, you know, the
- 2:51profile of the victim here is highly indicative
- 2:53of current targeting trends. How so? Well, geographic
- 2:56isolation or, you know, operating outside of
- 2:59major metropolitan hubs, that provides zero friction
- 3:02to global cybercrime networks. Right. Distance
- 3:05means nothing on the Internet. Exactly. And regional
- 3:07hospitality groups are just incredibly complex
- 3:09ecosystems. They manage high volumes of transient
- 3:12customer data. They've got constant payment processing,
- 3:16integrated booking systems. High staff turnover,
- 3:18too, usually. Yes, exactly. high staff turnover
- 3:21so when uh threat actors automated scanners are
- 3:25out there just you know pinging around looking
- 3:27for a foothold A hotel's sprawling vendor network
- 3:31often presents a much more accessible attack
- 3:33surface than, say, a highly locked down bank.
- 3:36Yeah, that makes total sense. And the timeline
- 3:39of how this attack surface is really indicative
- 3:41of that new pressure model you were talking about.
- 3:44Right. Because Goodstone confirmed that on April
- 3:4618th, 2026, they officially began responding
- 3:49to a cybersecurity incident. But it didn't go
- 3:52public right away. No, no. The attackers didn't
- 3:54just lock the servers and leave a text file on
- 3:56a desktop like the old days. Public escalation
- 3:58happened a couple of weeks later, on May 2. Oh,
- 4:01okay. A newly emerged hacking group posted good
- 4:04stone onto their dark web leak site. And they
- 4:07published a sample of the stolen data to, you
- 4:09know, prove they actually had the goods. And
- 4:11we've seen this double extortion model really
- 4:13become the industry standard over the last few
- 4:15years. Yeah. But the curation of that leaked
- 4:18sample, it's become a dark art in itself. It
- 4:21really has. They don't just dump random server
- 4:23logs anymore. No, not at all. They meticulously...
- 4:27Select the documents that will cause the absolute
- 4:30maximum amount of internal panic and external
- 4:33liability. Right. And the sample they curated
- 4:35here is just devastating. I mean, they published
- 4:37employee passport scans. Oof. Yeah. That's rough.
- 4:41A highly sensitive confidentiality agreement
- 4:43and detailed bank reconciliation documents from
- 4:48one of Goodstone's hotels. Just worst case scenario
- 4:50stuff. Totally. Think about the physical equivalent
- 4:53of this tactic. Right. Like obviously it's a
- 4:55modern cyber attack. But if we compare it to
- 4:57a physical burglary the burglar doesn't just
- 5:00break in take the cash from the safe and you
- 5:02know slip away into the night. Right. Instead
- 5:04they take Polaroids of your employees passports
- 5:07snap pictures of your private financial ledgers
- 5:09and then they. literally walk into the center
- 5:11of town and pin those photos to the public notice
- 5:14board. What's fascinating here is the stark contrast
- 5:18between the incredibly damaging, ruthless nature
- 5:22of those, well, those metaphorical Polaroids
- 5:25and the highly mature, responsible reaction from
- 5:29the victim. Yeah, Goodstone handled it really
- 5:31well. We so often critique incident response
- 5:34on this show, but Goodstone handled the immediate
- 5:37fallout with textbook precision. They really
- 5:40did not try to sweep this under the rug at all.
- 5:42The source material outlines that Goodstone's
- 5:44response was immediate and transparent. Which
- 5:47is exactly what you want to see. Yeah. The moment
- 5:49they realized the scope of the incident, they
- 5:51took aggressive steps to contain it and they
- 5:53immediately engaged external cybersecurity experts.
- 5:56Crucial first step. And furthermore, they proactively
- 5:59notified the Australian Cybersecurity Center
- 6:02and the Tasmanian government. They even set up
- 6:05a dedicated email. And that level of proactive
- 6:08communication. is critical for mitigating long
- 6:11-term reputational damage. But, you know, it
- 6:14also exposes the raw asymmetry of modern cyber
- 6:18warfare. What do you mean by asymmetry there?
- 6:21Well, on one side, you have this regional business
- 6:24adhering to complex legal frameworks, regulatory
- 6:28reporting requirements, community obligations,
- 6:30doing everything by the book. And on the other
- 6:32side, you have a completely unconstrained, faceless
- 6:35entity operating totally outside of any legal
- 6:37jurisdiction. And they are leveraging the personal
- 6:40identities of local hospitality workers as essentially
- 6:44disposable bargaining chips. Yeah. It's wild
- 6:46that a local business handled this with such
- 6:48textbook corporate maturity while the attackers
- 6:51are well, the attackers are actually trying to
- 6:53play the exact same corporate game. Right. But
- 6:55in a completely twisted way. Exactly. So the
- 6:57group responsible for pinning those Polaroids
- 6:59to the board, they call themselves the CMD organization.
- 7:02CMD organization sounds very official. Right.
- 7:06Beasley Security analyzed this breach in a May
- 7:0814 blog post and noted this group is incredibly
- 7:11new. Like they only began operations in March
- 7:142026. So they are super new to the scene, but
- 7:17obviously operating with immense aggression.
- 7:19The sources indicate they've claimed eight victims
- 7:22so far in that really short window. Yeah, making
- 7:24Goodstone their very first Australian target.
- 7:27Wow. And reading their public -facing materials
- 7:30in the Cyber Daily piece, it's just a surreal
- 7:32experience. CMD organization aggressively frames
- 7:36itself as a legitimate corporate entity. Oh,
- 7:38really? Yeah. Their leak site literally claims
- 7:41that they are a, quote, new kind of company that
- 7:44specializes in corporate system security and
- 7:47in identifying vulnerabilities. You're kidding.
- 7:50No. They have a published mission statement,
- 7:52okay? To create a secure online environment where
- 7:55every company is safely protected. I mean, it
- 7:59reads like a brochure for a tier one risk advisory
- 8:02firm. It does. Which is a masterful, if entirely
- 8:06cynical, exercise in cognitive manipulation.
- 8:09Cynical is putting it mildly. It's like a mafia
- 8:11protection racket trying to rebrand as a neighborhood
- 8:14watch program. Right, exactly. They smash your
- 8:16windows, raid your cash register, and then hand
- 8:19you this sleekly embossed business card claiming
- 8:21they specialize in structural integrity audits.
- 8:26How does the cybercrime ecosystem arrive at a
- 8:30place where threat actors feel the need to adopt
- 8:33high -end corporate branding? Well, the psychology
- 8:36behind this corporate veneer serves a highly
- 8:38calculated economic purpose. Okay, lay it out
- 8:41for me. When a company experiences a major breach,
- 8:44the executive team is operating under extreme
- 8:46stress, obviously. Sure. If the attacker communicates
- 8:50like a chaotic... unhinged criminal, it reinforces
- 8:54the narrative that the board is dealing with
- 8:56a terrorist. And, you know, corporate governance
- 8:58dictates that you do not fund terrorism. Right.
- 9:01You lock down and refuse to pay. Exactly. But
- 9:03if the attacker communicates using the language
- 9:05of an auditor framing the extortion demand as
- 9:07a consultancy fee or a bounty for identifying
- 9:10critical vulnerabilities, it introduces this
- 9:12cognitive dissonance. It softens the psychological
- 9:15blow. It tricks a stressed executive team into
- 9:18feeling like they are resolving an aggressive.
- 9:21B2B contract dispute rather than, you know, capitulating
- 9:24to an international crime syndicate. That's it.
- 9:27Exactly. It normalizes the extortion. Yeah. They
- 9:29use terms like timeliness. data integrity and
- 9:32confidentiality guarantees because it gives the
- 9:34victim's management team a psychological off
- 9:37ramp. Oh, that's so manipulative. It provides
- 9:39them with the internal justification to authorize
- 9:42a multimillion dollar payout under the guise
- 9:44of procuring a nontraditional security service.
- 9:47Wow. But Beasley securities analysis completely
- 9:50punctures that elite consultant persona. Yeah,
- 9:53it really does. Because despite the slick PR
- 9:56and the high minded mission statements, Beasley
- 9:58assesses CMD or organization's actual tradecraft
- 10:02as having, quote, limited operational maturity.
- 10:05Which is very telling. Right. They suggest CMD
- 10:08might simply be relying heavily on initial access
- 10:10brokers or IABs. And we know how the specialization
- 10:14of labor works in the cybercrime ecosystem. But
- 10:16outsourcing the actual hacking fundamentally
- 10:18undercuts their whole elite security firm narrative.
- 10:21It absolutely exposes them as opportunists rather
- 10:25than sophisticated operators. The dark web economy
- 10:29has evolved into this highly segmented supply
- 10:31chain, right? Yeah. Initial access brokers are
- 10:34specialized actors who do nothing but scan the
- 10:37Internet for compromised credentials, unpatched
- 10:40software or vulnerable remote desktop gateways.
- 10:44They just find the open doors. Right. They pry
- 10:46the window open, but they lack the infrastructure
- 10:48or the desire to actually orchestrate a multimillion
- 10:52dollar extortion campaign. So they monetize that
- 10:55access by selling the coordinates of the open.
- 10:57window to a group like CMD. Exactly. Historically,
- 11:00IABs would sell that access for a flat fee, maybe
- 11:03a few hundred or a few thousand dollars, depending
- 11:05on the revenue of the target company. Okay. But
- 11:08the economic model is really shifting toward
- 11:10affiliate structures now. An IAB might hand over
- 11:13the access in exchange for a 20 % cut of the
- 11:16final ransom. This means groups like CMD Organization
- 11:20don't need elite, groundbreaking engineers writing
- 11:23zero -day exploits. They just need capital to
- 11:26buy access, some off -the -shelf ransomware to
- 11:28deploy once inside, and a slick PR front -end
- 11:32to manage the extortion. So CMD is essentially
- 11:34just the customer service and billing department
- 11:37for a decentralized network of hackers. That's
- 11:39a perfect way to put it. They buy the access,
- 11:42grab the data and slap their corporate logo on
- 11:44the ransom note, which frankly makes the way
- 11:47they are attempting to monetize the good stone
- 11:49data even more alarming. Right. Because the corporate
- 11:52messaging isn't their only innovation. They are
- 11:55fundamentally altering the mechanics of the digital
- 11:57extortion market. And the financial demand in
- 12:00this case is substantial, which really serves
- 12:02as. the baseline for this new market mechanic.
- 12:04Yeah, let's talk numbers. The extortion demand
- 12:07for the Goodstone data is roughly $1 million.
- 12:09In cryptocurrency terms, based on the article's
- 12:12publication date, that translates to nine Bitcoin.
- 12:16But the innovation isn't the price tag. CMD organization
- 12:19has introduced a tactic where they're allowing
- 12:22anyone on the Internet to bid on the stolen data
- 12:25offered on their website. Which represents a
- 12:27radical structural shift in how data breaches
- 12:30are weaponized. Yeah. And here's where it gets
- 12:33really interesting. I mean, is this public bidding
- 12:35war actually. a functional economic model or
- 12:39is it purely a psychological weapon? It's a great
- 12:42question. Because the idea of a dark web eBay
- 12:44for stolen passports sounds terrifying. But I
- 12:47have to wonder about the liquidity of that market.
- 12:50Like, are there really dozens of competing criminal
- 12:52syndicates sitting around with a million dollars
- 12:54in Bitcoin ready to outbid each other for the
- 12:56HR files of a Tasmanian hotel group? If we connect
- 13:00this to the bigger picture, the auction format
- 13:02is heavily weighted towards psychological warfare,
- 13:04sure. but the underlying product they are selling,
- 13:07which is exclusivity, holds immense very real
- 13:10economic value for a specific subset of buyers.
- 13:14Beasley Security's analysis highlights that this
- 13:16tactic completely shatters the traditional closed
- 13:19room negotiation model. Right, because the victim
- 13:21is no longer just negotiating against the attacker's
- 13:24patients. They're negotiating against a public
- 13:27countdown clock and the threat of this invisible
- 13:30market. Exactly. When negotiations happen in
- 13:33secret, the threat actor's leverage is capped
- 13:35by what the victim's cyber insurance policy will
- 13:38cover or what the company's cash reserves can
- 13:40handle. Makes sense. But by dragging a podium
- 13:43into the town square and taking public bids,
- 13:46the attacker removes that cap. They are signaling
- 13:49to the victim, we don't actually need you to
- 13:51pay. We have an entire marketplace of buyers
- 13:54who will. Whether or not a massive bidding war
- 13:58actually materializes is almost secondary to
- 14:01the panic that the threat of the auction induces
- 14:03in the boardroom. Yeah, the panic is the point.
- 14:05But Beasley Security points out a very specific
- 14:08technical danger here, which is the concept of
- 14:11exclusive access. Right. If someone wins this
- 14:14auction, CMD locks the sale to that single buyer.
- 14:18And, you know, I always assumed that when negotiations
- 14:20failed, stolen data was just dumped onto a public
- 14:24forum for any low -level scammer to grab. That
- 14:26used to be the standard, yeah. But locking it
- 14:28to a single buyer changes the entire economic
- 14:30model of identity theft, doesn't it? It changes
- 14:33the model completely by introducing the luxury
- 14:36of time. The fundamental problem with publicly
- 14:39dumped data is noise. Too many people using it
- 14:43at once. Exactly. If CMD releases the Goodstone
- 14:45employee passports and banking details to the
- 14:48general public. Thousands of disparate actors
- 14:51descend on the exact same data set simultaneously.
- 14:53And they all try to monetize the exact same identities
- 14:56at the exact same time. Which immediately triggers
- 14:59the fraud detection algorithms at major financial
- 15:01institutions. Right. Of course it does. If 50
- 15:04different IP addresses try to use the same Tasmanian
- 15:06passport to open cryptocurrency exchange accounts
- 15:09or apply for credit cards within a 24 -hour window,
- 15:12the anti -money laundering and know -your -customers
- 15:14systems flag the identity immediately. So the
- 15:17banks freeze the accounts, the passports are
- 15:19marked as compromised, and the data set becomes
- 15:22essentially worthless overnight. Precisely. Public
- 15:25data depreciates instantly because of the sheer
- 15:27volume of chaotic competing attacks. So by selling
- 15:31exclusive access, CMD is guaranteeing the buyer
- 15:34a silent environment. Yes. If a malicious syndicate
- 15:37pays a premium at this auction, they are the
- 15:40only ones inside the vault. They don't have to
- 15:42rush. They purchase dwell time. the exclusive
- 15:45buyer can spend weeks or even months quietly
- 15:48analyzing the internal reporting structures of
- 15:51the goodstone group oh man they can use the stolen
- 15:54confidentiality agreements to craft highly convincing
- 15:57targeted spear phishing emails to external vendors
- 16:00they can slowly synthesize the passport scans
- 16:03with other data points to build robust synthetic
- 16:06identities all while patiently bypassing kyc
- 16:09protocols without tripping any concurrent alarms
- 16:11exactly it dramatically increases the return
- 16:13on investment for the criminal buyer. But conversely,
- 16:16it makes the data infinitely more dangerous for
- 16:19the actual human bills whose information was
- 16:21stolen. On questions. The employees of Goodstone
- 16:23Group aren't just dealing with their data being
- 16:25cast into the noisy wind of the Internet. Their
- 16:28identities are being handed over to a dedicated,
- 16:30heavily invested syndicate who paid top dollar
- 16:33at an auction. Right. That syndicate now has
- 16:37a massive financial incentive to squeeze every
- 16:40conceivable cent of value out of those specific.
- 16:43passports to recoup their million dollar investment.
- 16:46It is the ultimate commoditization of human identity.
- 16:49The attackers have optimized the supply chain
- 16:52via initial access brokers. They have normalized
- 16:56the extortion through corporate branding. And
- 16:58now they are maximizing the yield. through exclusive
- 17:01public auctions. It's chilling. They're utilizing
- 17:04fundamental marketplace economics to engineer
- 17:06maximum leverage. It really strips away any remaining
- 17:09pretense of amateur hacking, doesn't it? Completely.
- 17:12This is a highly organized, market -driven industry.
- 17:14The Goodstone incident makes it undeniably clear
- 17:17that cyber attacks are no longer localized IT
- 17:20problems that can be quietly resolved by a tech
- 17:23support team resetting some servers. They are
- 17:25high stakes, highly visible corporate crises.
- 17:28The defensive strategy can no longer just focus
- 17:31on building a taller firewall. Organizations
- 17:34have to understand the economic drivers of the
- 17:37adversaries they are facing. You really have
- 17:38to know the business of your enemy. Exactly.
- 17:41When attackers are mimicking corporate structures
- 17:43and utilizing sophisticated market dynamics,
- 17:45the defense requires an equally mature, comprehensive
- 17:49approach to incident response, data segregation,
- 17:53and identity management. Well said. And as we
- 17:55wrap up this discussion, I want you, the listener,
- 17:59to... really sit with what this market evolution
- 18:01means for the future of our personal information.
- 18:04The big question. It is. If ransomware cartels
- 18:06are successfully moving toward exclusive public
- 18:08bidding wars, what happens to the fundamental
- 18:10concept of privacy? Yeah. We are entering an
- 18:13era where your stolen identity isn't just a byproduct
- 18:16of a corporate breach. It becomes a rare single
- 18:19owner commodity aggressively optioned off to
- 18:22the highest bidder on a dark red trading floor.
- 18:25It's a sobering reality for sure. It really is.
- 18:28And it underscores exactly why robust modern
- 18:30security architectures are absolutely not optional
- 18:33anymore. If you're wondering how to protect your
- 18:35own organization from these rapidly evolving
- 18:37market -driven threats, we'd love to help you
- 18:39prepare and build out those defenses. Please
- 18:41visit www .kinsoft .com .au to discuss your own
- 18:45security and IT needs. Thanks for joining us
- 18:47and stay safe out there.