Latest / Tech Talks With Kinsoft / VSP Solutions – Stormous Hits a Security-Hardware Distributor
Transcript
- 0:00You know, usually when we think about a corporate
- 0:02cyber attack, we picture a direct frontal assault.
- 0:06Right. We imagine the digital equivalent of a
- 0:08bank robber just, you know, walking straight
- 0:10through the front door. Demanding the cash from
- 0:12the vault. Exactly. And making a run for it.
- 0:15The traditional smash and grab. You breach the
- 0:17perimeter, you grab what you can carry, and,
- 0:20well, you get out before the alarms trigger a
- 0:22response. But the reality of modern cyber threats
- 0:25is it's so much more intricate than that. Oh,
- 0:28absolutely. It's less about robbing a single
- 0:30vault and much more about infiltrating the entire
- 0:33plumbing system of an industry. So welcome to
- 0:36Tech Talks with Kinsoft. Glad to be here. The
- 0:39premise of our show is simple. We take a stack
- 0:41of sources like articles, research, our own notes,
- 0:45and we extract the most critical nuggets of knowledge.
- 0:48So you, the listener, can stay perfectly informed
- 0:51without feeling completely overwhelmed. Exactly,
- 0:54because there is just a constant flood of information
- 0:56out there. We aim to cut through the noise and
- 0:59find the signal. And today's signal is coming
- 1:01from a very specific incident that acts as a
- 1:04perfect microcosm of where enterprise security
- 1:07is failing right now. Yeah, today we are focusing
- 1:09on a recent exclusive report. It was published
- 1:12by Cyber Daily on June 1st, 2026. A really fascinating
- 1:16piece. It really is. The core story here is that
- 1:18VSP Solutions, which is a major Australian video
- 1:21security firm, they were hit by a cyber attack
- 1:24resulting in a 40 gigabyte data leak. Right,
- 1:27but our mission today isn't just to read you
- 1:29the news. No, not at all. We are using this VST
- 1:32incident as a practical lens to understand three
- 1:34massive concepts. Okay, lay them out. We're looking
- 1:37at third party supply chain risks, the hidden
- 1:40dangers of what companies call historical data,
- 1:43and the modern, highly corporate playbook of
- 1:46ransomware leak sites. To understand the severity
- 1:48of any cyber incident, you really have to look
- 1:51past the headline numbers. You have to analyze
- 1:53the actual anatomy of the breach. Like what exactly
- 1:55was exposed when the digital alarms went off?
- 1:57Exactly. And how fast the escalation happened.
- 1:59Well, let's look at the timeline because the
- 2:01speed here is... It's honestly alarming. It really
- 2:04is. On Wednesday, May 13th, 2026, VSP Solutions
- 2:08became aware of an incident involving their business.
- 2:11Okay, so that's day one. Fast forward just 10
- 2:13days, right, to May 23rd, and they were officially
- 2:16listed on a Darknet leak site. Wow. 10 days.
- 2:2110 days. 10 days from realizing something is
- 2:24wrong in your network to having your corporate
- 2:26secrets just pasted on the dark web. And the
- 2:29hackers were very explicit about what those secrets
- 2:31included. Yeah, we are talking about 40 gigabytes
- 2:34of data. And this included... Full financial
- 2:37backups from QuickBooks and Reckon, email archives,
- 2:41staff personal folders. Customer and client databases,
- 2:43too. Right, specifically installers and integrators
- 2:46nationwide. And shipment and order tracking from
- 2:49major physical security brands like Hikvision
- 2:51and Access. You know, 40 gigabytes might sound
- 2:53like a rounding error if you're talking about
- 2:55high -definition video files. Yeah, I mean, that's
- 2:57like, what, a few 4K movies? Exactly. But 40
- 3:00gigabytes of pure text, spreadsheets, SQL databases,
- 3:03and email archives. It's massive. It is an absolutely
- 3:07staggering volume of highly structured, deeply
- 3:10sensitive information. Millions of rows of raw
- 3:14corporate reality. Okay, let's unpack this. Because
- 3:17stealing this specific combination of data isn't
- 3:21just a smash and grab. Right. It's like stealing
- 3:23the architectural blueprints, the bank statements,
- 3:26and the employee diaries of a company all at
- 3:29once. That's a great way to put it. It's a complete...
- 3:32unredacted historical map of the business. And
- 3:34it gives the attackers total leverage. We know
- 3:37modern ransomware groups operate on a double
- 3:39extortion model. Right. They don't just encrypt
- 3:41your network to cause operational downtime anymore.
- 3:44Exactly. They exfiltrate the data first and threaten
- 3:46to publish it. But the mechanics of how they
- 3:50leverage this specific type of structured data,
- 3:53well, that is where the real threat lies. How
- 3:55so? When a group pulls out a QuickBooks backup,
- 3:58they aren't just looking at your bottom line.
- 4:00They're looking at your accounts payable, your
- 4:02vendor payment schedules, your payroll structure.
- 4:04Oh, wow. They're looking for the financial pressure
- 4:06points they can squeeze during negotiation. I
- 4:08understand the financial leverage, but looking
- 4:12at that list of stolen data. The shipment and
- 4:15order tracking for major physical security brands
- 4:18like Hikvision and Axis, that really jumps out
- 4:20to me. Oh, it sure does. Because we are talking
- 4:23about a distributor of security cameras and Axis
- 4:26control panels. Right, which adds a highly unique
- 4:29layer of physical security risk to what is essentially
- 4:32a digital breach. Right. Consider the crossover
- 4:35here. If an attacker has the shipment tracking.
- 4:38MFE addresses and customer databases for enterprise
- 4:41video security products, they know exactly which
- 4:44businesses across Australia are currently installing
- 4:46new cameras. That's terrifying. They know where
- 4:48the blind spots might be during the installation
- 4:50phase. They know what specific models of access
- 4:53control systems are guarding certain facilities.
- 4:56So a digital map has suddenly become a physical
- 4:58map of vulnerabilities across the country. Exactly.
- 5:01A threat actor could theoretically cross -reference
- 5:04those shipment logs with known hardware vulnerabilities.
- 5:07Wait, really? Yeah, like if they see VSP shipped
- 5:10a specific batch of Axis cameras to a government
- 5:13contractor, and that specific model has an unpatched
- 5:17firmware flaw. Then what? Well, the attacker
- 5:20doesn't even need to hack the contractor's network
- 5:22directly. They just exploit the hardware fresh
- 5:25out of the box. You got it. So who is actually
- 5:27executing this level of analysis? Because analyzing
- 5:30the threat actor reveals exactly why a mid -sized
- 5:33Australian distributor was targeted in the first
- 5:35place. Yes. The group claiming responsibility
- 5:38goes by the name Stormus. Stormus. Right. They
- 5:42emerged in 2022. They've claimed more than 140
- 5:45victims, and they operate using a ransomware
- 5:48-as -a -service model, or RACE. But basically
- 5:50running a corporate franchise. Exactly like a
- 5:52franchise. Much like legitimate tech companies
- 5:55use software -as -a -service models, Stormis
- 5:57provides the core encryptor malware, the dark
- 6:00web leak site infrastructure, and the negotiation
- 6:03dashboard. Like a turnkey solution for cybercrime?
- 6:06Precisely. They franchise this toolkit out to
- 6:09affiliates. Affiliates, like independent hackers
- 6:12who do the actual breaking and entering. I get
- 6:14that Raise operates like a franchise, but how
- 6:16do they handle the actual financial split securely
- 6:20without exposing themselves? Does the core group,
- 6:23like Secro the crypto? Well, the modern Raise
- 6:26ecosystem is incredibly specialized. Often the
- 6:29affiliate doesn't even do the initial hacking.
- 6:31Wait, they don't? No. They buy compromised credentials
- 6:34from initial access brokers. Oh, so specialists
- 6:37who just break down the front door and sell the
- 6:39keys. Exactly. The affiliate takes those keys,
- 6:42deploys the stormless malware, and exfiltrates
- 6:45the data. If the victim pays, the ransom goes
- 6:48into a multi -signature cryptocurrency wallet.
- 6:51And then it just splits automatically. Yeah.
- 6:52The RaiseApp platform automatically takes its
- 6:55platform fee, usually around 20 to 30 percent,
- 6:57and routes the rest to the affiliate. It's automated.
- 7:00trustless profit -sharing among criminals. That
- 7:03level of corporatization is terrifying. Now,
- 7:06according to the threat intelligence platform
- 7:08Socratar, Stormis is classified as a pro -Russian
- 7:11group. Right. And just to be clear for everyone
- 7:13listening, our goal today isn't to dive into
- 7:15geopolitics or take sides. Of course not. We
- 7:18are simply looking at what the intelligence reports
- 7:20are telling us, right? We're not endorsing any
- 7:23viewpoints, just conveying the factual claims
- 7:26made in the source material regarding the attacker's
- 7:28reported allegiances. Right, just the data we
- 7:30have. But taking that report at face value, I
- 7:33have to push back a bit. Okay, go ahead. If Stormis
- 7:35is ideologically motivated, why target an Australian
- 7:39video security distributor in Minchenbury, New
- 7:42South Wales? That is a very good question. Is
- 7:44it just opportunistic economics? Because hacking
- 7:48a mid -sized distributor doesn't immediately
- 7:51look like a grand geopolitical maneuver. What's
- 7:53fascinating here is how the group itself justifies
- 7:58its targeting parameters. Oh, they actually talk
- 8:00about it. Yeah. In an interview given by a Stormis
- 8:02spokesperson back in October 2025, they explicitly
- 8:06stated that their operations blend financial
- 8:09and political motivations. OK, so a bit of both.
- 8:11Right. They claim target selection is guided
- 8:13by both perceived ideological alignment and economic
- 8:17opportunity. But the critical phrase they used
- 8:19was that they prioritize opportunities that maximize
- 8:22impact. both financially and in terms of influence.
- 8:26Maximizing influence. Yes. So it's not just about
- 8:28the ransom payout. It's about the blast radius
- 8:30of the attack. That is the core of their strategy.
- 8:33The developers build the tools to create maximum
- 8:36leverage, and the affiliates scour the globe
- 8:39looking for the weakest link in the chain. The
- 8:41chain that connects to the most valuable targets.
- 8:44Exactly. Stormis primarily targets organizations
- 8:46in the technology and business services sectors
- 8:49across the U .S., Spain, the UAE, and France.
- 8:53So it's a global operation. Yes. And VSP is one
- 8:56of several victims they claimed after taking
- 8:59an almost six -month hiatus. Stormis' stated
- 9:02goal of maximizing influence directly explains
- 9:04why a distributor like VSP is the absolute perfect
- 9:08target. Because of their position in the market.
- 9:10Right. It's not really about the distributor
- 9:12itself. It's about everyone connected to them.
- 9:14Let's look at the target. VSP Solutions isn't
- 9:17just a standalone shop. No. They have a massive
- 9:19reach. They are based in New South Wales, but
- 9:22they have offices in Queensland, Victoria and
- 9:24Western Australia. They've been distributing
- 9:27video security products since 1993. Over three
- 9:30decades of industry relationships, contracts
- 9:33and digital handshakes. Right. They supply bespoke
- 9:36solutions, everything from physical access control
- 9:39to advanced cloud surveillance platforms. Oh,
- 9:43and they supply these to installers and integrators
- 9:45nationwide. Here's where it gets really interesting.
- 9:49distributor isn't just hitting one business.
- 9:51It's like it's like stealing the master key for
- 9:55an entire apartment complex rather than kicking
- 9:57down individual doors or like poisoning a river
- 10:00at its source. That's a very vivid analogy, but
- 10:03it's accurate. You aren't just attacking the
- 10:05water. You're impacting every town downstream
- 10:06that drinks from it. Exactly. If you breach an
- 10:09end user, you compromise one company. If you
- 10:11breach a distributor, you potentially compromise
- 10:13hundreds or thousands of companies down the line.
- 10:16If we connect this to the bigger picture. This
- 10:19is the very definition of third -party and supply
- 10:21chain risk. Which we hear a lot about lately.
- 10:23Right, because attackers have realized that enterprise
- 10:26companies spend millions securing their own internal
- 10:28networks. A major bank or a government agency
- 10:31will have world -class firewalls, strict multi
- 10:34-factor authentication, and a 247 security operations
- 10:38center. Hacking them directly is expensive and
- 10:40loud. Yeah, but that same bank has to hire a
- 10:43local integrator to install their security cameras.
- 10:46Right. buys their hardware from a distributor
- 10:50like VSP. The attacker looks at this chain and
- 10:53realizes the distributor is the fulcrum. So if
- 10:56they compromise the vendor, they gain immense
- 10:59leverage over the vendor's massive network of
- 11:02clients. Exactly. Let's talk about the mechanics
- 11:04of how this data becomes a downstream weapon.
- 11:06Okay. If Stormis has VSP's email archives and
- 11:10customer databases, they can launch incredibly
- 11:12sophisticated spear phishing campaigns. Because
- 11:15they aren't sending generic spam anymore. No.
- 11:17They can send an email to an integrator that
- 11:19says, hey, regarding your current order of 50
- 11:21Axis cameras for the new downtown bank branch,
- 11:23we need you to review this updated. shipping
- 11:26invoice that is so specific the email comes from
- 11:29a real vsp email thread referencing a real purchase
- 11:33order speaking to the exact person who handles
- 11:35procurement And the integrator clicks the invoice,
- 11:38their network is compromised, and the attacker
- 11:40uses that access to pivot directly into the bank's
- 11:43network during the installation phase. Exactly.
- 11:46When Stormist leaked those customer databases
- 11:49mapping out nationwide security installations,
- 11:51they turned a localized IT headache into a nationwide
- 11:55supply chain vulnerability. The domino effect.
- 11:58One piece falls and it threatens the entire board.
- 12:01Precisely. So once the attackers execute this
- 12:04double extortion play on a critical supply chain
- 12:07node, the victim's immediate response dictates
- 12:10the fallout. Let's look at how VSP handled this
- 12:12because there are lessons here. Yes. VSP's public
- 12:15response was honestly textbook crisis management.
- 12:18Oh, really? Yeah. They stated that the incident
- 12:20did not affect their current business operations
- 12:22and that they are continuing to serve clients
- 12:24with full confidence. Right. They clarified something
- 12:27crucial, though. They claimed the impact of data
- 12:29was historical in nature and pertained to a related
- 12:31business. And they immediately took steps to
- 12:35contain the incident, engaging forensic experts
- 12:37and cybersecurity advisors. Yeah, they engaged.
- 12:40with law enforcement and notified relevant Australian
- 12:42government agencies. They also explicitly committed
- 12:45to communicating transparently with their clients
- 12:48and stakeholders. Which is exactly what you're
- 12:50supposed to do. Right. This is the modern blueprint
- 12:52for how to handle a leak site listing. You acknowledge
- 12:55it, isolate it, bring in the experts and communicate
- 12:58the scope of the impact to anyone downstream
- 13:00who might be affected. There is a detail in this
- 13:03story, though, that is just dripping with. dark
- 13:05humor. Oh, the file sharing part. Yes. So the
- 13:08hackers, Stormus, took this 40 gigabytes of stolen
- 13:12corporate data and published it on a popular
- 13:14public file sharing platform. But within a few
- 13:18days, the data was gone. And not because of a
- 13:21massive international police sting? No, because
- 13:24the hosting service terminated the hacker's account
- 13:26for a violation of our terms of service. It's
- 13:29hilarious, really. It highlights the bizarre
- 13:31ecosystem of modern cybercrime. It really does.
- 13:34You have highly sophisticated operations utilizing
- 13:37advanced encryption and initial access brokers,
- 13:40but they still rely on mundane, everyday Internet
- 13:44infrastructure to host their stolen files. It
- 13:47is literally like an international jewel thief
- 13:49successfully robbing the Louvre, bypassing laser
- 13:53grids and armed guards, making a clean getaway
- 13:56and then immediately getting their getaway car
- 13:58towed because they parked in a loading zone.
- 14:00The mundane rules of the Internet still apply.
- 14:02Exactly. But underneath that irony, there is
- 14:05a very serious warning hidden in VSP's statement
- 14:08about the data being historical in nature. Yeah,
- 14:12this is something I really want to dig into.
- 14:13Why do companies keep so much historical data,
- 14:16and why is it so dangerous? This raises an important
- 14:19question for any IT leader listening today. Okay.
- 14:22Companies are usually hypervigilant about securing
- 14:24their active, day -to -day operational data.
- 14:27They put it in the cloud, behind the newest zero
- 14:29-trust security protocols. But they often leave
- 14:32decades of old data sitting on legacy servers.
- 14:35They keep it for compliance reasons, tax audits,
- 14:38or simply because no one wants to take the responsibility
- 14:40of hitting the delete button on 10 years of corporate
- 14:44history. It's the digital equivalent of putting
- 14:46an unpickable smart lock on your front door,
- 14:49but leaving your old financial records in a cardboard
- 14:52box by the curb. To an attacker, that old data
- 14:55is a goldmine. Let's look at the forensic realities
- 14:57of what historical data actually contains. What's
- 15:00usually in there? It holds legacy network architectures.
- 15:03It holds old email archives that reveal the internal
- 15:06power dynamics of the company. Most dangerously,
- 15:09it holds old passwords. And we know human psychology.
- 15:12People reuse passwords. Constantly. If an attacker
- 15:16pulls an employee's password from a five -year
- 15:18-old database, there is a statistically significant
- 15:20chance that employees using a variation of that
- 15:23exact same password for their current... highly
- 15:25secured accounts. Wow. Furthermore, historical
- 15:28financial data gives attackers the baseline they
- 15:30need to craft highly convincing business email
- 15:33compromise scams, like those QuickBooks files.
- 15:36Right, the Reckon and QuickBooks backups. Even
- 15:39if the data doesn't disrupt your operations today,
- 15:41it gives the attacker massive leverage for extortion,
- 15:44it damages your reputation with clients who trusted
- 15:48you, and it triggers serious privacy law violations.
- 15:52So what does this all mean for the people listening?
- 15:54Let's summarize. When we look at this VSP incident
- 15:57holistically, a few massive takeaways emerge.
- 16:00Okay, first one. First, ransomware has evolved
- 16:03into a highly franchised corporate business model
- 16:07through ransomware as a service. Like we talked
- 16:09about, we are dealing with specialized supply
- 16:12chains of cybercrime. Absolutely. And the second.
- 16:15Second, attackers are deliberately targeting
- 16:17the distributors and the vendors because breaching
- 16:20the middleman maximizes their downstream leverage
- 16:23and influence over hundreds of other companies.
- 16:25And the final takeaway. And third, your old forgotten
- 16:28historical data can and will be weaponized against
- 16:31you if it isn't properly secured or systematically
- 16:34destroyed. I urge organizations to reflect on
- 16:37that last point immediately. If cyber criminals
- 16:40are actively digging up historical data. to use
- 16:42as leverage in double extortion schemes, it forces
- 16:46us all to ask a difficult question. What's that?
- 16:49When does archiving data stop being a strategic
- 16:52business asset and start becoming a toxic liability?
- 16:55Think about your own infrastructure right now.
- 16:57How many digital ghosts of old businesses, forgotten
- 17:01projects, and legacy backups are sitting quietly
- 17:04on your company's servers, just waiting for an
- 17:06initial access broker to find them? It is a really
- 17:09sobering thought, and it's exactly why being
- 17:11proactive is the only real defense here. It's
- 17:13not enough to secure the perimeter. You have
- 17:15to understand exactly what is sitting inside
- 17:17it. So to make sure your active and historical
- 17:19data is actually protected and to discuss your
- 17:22security and IT needs before they become a dark
- 17:25web headline, visit www .kinsoft .com .au. Stay
- 17:31secure out there. Thank you so much for joining
- 17:33us on Tech Talks with Kinsoft. Stay informed,
- 17:35and we'll catch you next time.