Latest / Tech Talks With Kinsoft / Gelatissimo Data Breach – DragonForce and the 352GB Heist
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. It's great
- 0:02to be here. So when you think of gelatissimo,
- 0:04you probably think of like sunny Australian afternoons,
- 0:09right? Yeah, exactly. Artisanal gelato, happy
- 0:11memories. Right. It's this very innocent, everyday
- 0:14image. But today we are dragging that bright,
- 0:18sunny brand into the darkest corners of the internet.
- 0:21Which is quite the tonal shift. It really is.
- 0:23Because today we are unpacking a massive 352
- 0:28gigabyte Data heist. And it's one that brings
- 0:31the abstract world of cybersecurity right to
- 0:33the doorstep of everyday retail workers. Yeah,
- 0:36it's a very striking juxtaposition. And, you
- 0:38know, it perfectly illustrates the reality of
- 0:40the modern threat landscape. Definitely. Because
- 0:42we are dealing with this incredibly sophisticated
- 0:44ecosystem of extortion. And honestly, they do
- 0:47not care if you sell software, manufacture cars
- 0:50or, you know, scoop gelato. They really don't.
- 0:53So our mission for this exploration is to basically
- 0:56cut through the dense technical. jargon surrounding
- 0:59this recent ransomware attack. Right, because
- 1:01there's a lot of it. Exactly. We have a stack
- 1:03of incredibly detailed recent reporting here,
- 1:06primarily from Information Age and Cyber Daily.
- 1:11Excellent sources. Yeah. And we want to use those
- 1:13to uncover what this actually means for the human
- 1:16beings whose data is caught in the crossfire.
- 1:19Because there's a real human cost here. Right.
- 1:21We are looking beyond the flashy headlines to
- 1:23understand, like, the mechanics of the attack,
- 1:25the horrifying permanence of the data that is
- 1:28allegedly at risk, and, of course, the agonizing
- 1:31reality of a corporate extortion countdown. It's
- 1:33a lot to cover. It is. OK, let's unpack this.
- 1:36I think the best place to start is just with
- 1:38the scale of the target. And the sheer audacity
- 1:41of the claims being made by the four actors.
- 1:44Yeah, because Gelatissimo is not some small mom
- 1:46and pop operation. No, not at all. I mean, this
- 1:48is a massive franchise. They started right here
- 1:50in Sydney back in 2002. And they have grown to
- 1:53over 60 stores across Australia, plus around
- 1:5822 international locations. Which means they
- 2:00hold a massive amount of operational and employee
- 2:03data. A staggering amount. And according to the
- 2:05reporting, a ransomware group known as Dragonforce
- 2:08posted a listing for Gelatissimo on their dark
- 2:11web leak site. Right. And they claim to have
- 2:14stolen roughly 352 gigabytes of data from the
- 2:17company's systems. Which is just huge. It is.
- 2:20To put that in perspective for you listening,
- 2:22352 gigabytes of purely corporate and text -based
- 2:26data is... Like an absolute ocean of information.
- 2:30Yeah, we're talking about millions upon millions
- 2:33of pages of documents, spreadsheets, communications.
- 2:37Endless files. Exactly. And exfiltrating that
- 2:40amount of data is not an instant process. Right.
- 2:42It's not a quick copy and paste job you do in
- 2:44five minutes. No. Moving 352 gigabytes out of
- 2:47a corporate network without tripping alarms,
- 2:49that often implies that the attackers had persistent
- 2:52undetected access to the systems. Like for a
- 2:55significant period of time? Usually. Slowly,
- 2:57yeah. Slowly siphoning the data out before they
- 3:00ever even made their presence known. Wow. But
- 3:02to prove they actually have this massive warehouse
- 3:06-sized filing cabinet of data, they didn't just
- 3:09dump it all at once on the dark web. No. That's
- 3:11not how the extortion works. Right. Imagine someone
- 3:14stealing that massive filing cabinet. But to
- 3:17prove they have the leverage, they only slide
- 3:19six terrifying folders under your door. That's
- 3:22a great analogy. They released a very tiny, highly
- 3:25curated sample. Yeah. But I want to push back
- 3:28on the core premise here, though. OK, go ahead.
- 3:30Why target a gelato company? I mean, are we looking
- 3:33at some highly coordinated cinematic digital
- 3:35heist specifically plotting against gelatissimo?
- 3:39Or is this just like automated opportunism? It's
- 3:43the latter. And the Cyber Daily source provides
- 3:46a very clear profile of the attackers that answers
- 3:48that question entirely. OK, so who are they?
- 3:51So Dragon Force is not a team of rogue hackers
- 3:54huddled in a basement nursing some weird grudge
- 3:56against a gelato chain. Right. No vendetta against
- 3:59ice cream. Exactly. They operate a highly industrialized
- 4:02model. It's known as ransomware as a service
- 4:05or RAS. Ransomware as a service. Wow. Yeah. They
- 4:08essentially function as a malicious software
- 4:10vendor. So they build the infrastructure, but
- 4:12they don't necessarily execute the break in themselves.
- 4:14Spot on. They develop the malicious software.
- 4:18They maintain the dark web leak sites, you know,
- 4:21where the countdown timers are hosted. And they
- 4:23manage the negotiation portals used to extort
- 4:26the victims. So it's basically a platform. That
- 4:28is the core of the Reyes model. Dragon Force
- 4:31relies on what they call affiliates. Affiliates,
- 4:34like marketers. Like independent contractors
- 4:37of the cybercrime world. Oh, wow. Yeah. These
- 4:40affiliates, they scour the internet for literally
- 4:43any vulnerability. An unpatched server, a compromised
- 4:47password, a successful phishing email. Just knocking
- 4:50on digital doors until one opens. Exactly. And
- 4:53once they find a way in, they rent the Dragonforce
- 4:55platform to execute the actual ransomware deployment
- 4:58and the extortion. So how does the money work?
- 5:00Well, when a ransom is paid, Dragonforce takes
- 5:03a 20 % cut for providing the software and the
- 5:06platform. Okay. And the affiliate who actually
- 5:08executed the breach keeps the remaining 80%.
- 5:11That is literally a franchising model for cybercrime.
- 5:14It really is. I mean, the irony is incredibly
- 5:17bitter there, considering Gelatissimo relies
- 5:19on a franchise model for its own legitimate business.
- 5:22yeah the attackers are using the exact same scalable
- 5:25business structures to inflict the damage that
- 5:28is wild and it is a ruthless highly organized
- 5:31business like dragon force actively advertises
- 5:34its platform on russian language hacking forums
- 5:37to recruit skilled affiliates so they are recruiting
- 5:40openly yes they are also believed to have operational
- 5:44links to the notorious lock bit ransomware cartel
- 5:47oh lock bit they're huge very huge but the most
- 5:51important mechanism to understand here is their
- 5:54use of the double extortion tactic. Right, because
- 5:56the old model of ransomware was just about locking
- 5:59you out, wasn't it? Exactly. Hackers would encrypt
- 6:01your files and demand a ransom for the decryption
- 6:03key. It was basically a business interruption
- 6:05problem. Yeah, and if you had good backups, you
- 6:08could simply wipe your systems, restore the data,
- 6:10and ignore the hackers completely. But double
- 6:13extortion changes that. It does. It was invented
- 6:15specifically to bypass the defense of having
- 6:18good backups. Okay, so how does it work? So the
- 6:21affiliate doesn't just encrypt the data anymore.
- 6:24They steal it first. They take it out of the
- 6:26network. Right. They silently exfiltrate that
- 6:29352 gigabytes to their own servers. Then they
- 6:34deploy the encryption to lock the victim's systems,
- 6:37causing that immediate panic and business outage.
- 6:40So the company scrambles, they go to check their
- 6:42backups, right? Yes. And that's when the hackers
- 6:44reveal the second layer of extortion. They say,
- 6:46even if you can restore your systems, we have
- 6:49all your sensitive data and we will publish it
- 6:51to the dark web if you don't pay. It transforms
- 6:55a vandalism problem into a full -blown hostage
- 6:58situation. What's fascinating here is just how
- 7:00prolific this indiscriminate targeting has become.
- 7:04Dragon Force has claimed 505 victims to date.
- 7:07505? Yeah, and that number more than doubled
- 7:09in just a few months following last September.
- 7:12That's terrifying. In the exact same week, they
- 7:14listed Gelatissimo. They also listed a printing
- 7:16specialist, a landscaping company, an engineering
- 7:19firm, and a U .S. medical equipment supplier.
- 7:22So it really is totally random. Completely. They
- 7:24do not care what industry you are in. They only
- 7:27care that you have a database of human identities
- 7:29that they can monetize. Right. And to understand
- 7:32the. the severe credibility of their extortion
- 7:35threats, we really have to look at their track
- 7:37record. Definitely. Last year, Dragon Force claimed
- 7:40an attack on a Queensland -based organization,
- 7:43the Toowoomba Friendly Society Dispensary. A
- 7:47medical dispensary. Yes. They claim to have stolen
- 7:50nearly 36 gigabytes of data. And a medical dispensary
- 7:54hold a completely different classification of
- 7:56data. than a gelato shop. Radically different.
- 7:59I mean, you were moving from corporate operations
- 8:01into deeply private health information. Exactly.
- 8:04And when the dispensary presumably refused to
- 8:07pay the ransom, Dragon Force followed through
- 8:09on their threat. They leaked it all. They leaked
- 8:11the data. The information that became freely
- 8:14available on the dark net included medical documents
- 8:16with names, addresses, and even photographs of
- 8:19patients. Oh my God. It detailed highly sensitive
- 8:22specific medical treatments. Everything from
- 8:25methadone treatment to... prescriptions for emergency
- 8:27contraceptives. That is just beyond cruel. They
- 8:30also leaked staff pay details and high resolution
- 8:33scans of employees' Medicare cards and driver's
- 8:36licenses. Wow. So if Dragon Force is willing
- 8:39to weaponize the private medical history of a
- 8:42dispensary patient, just to prove a point. Yeah.
- 8:45The terrifying reality is that Gelatissimo's
- 8:48employees are facing that exact same ruthlessness.
- 8:51Absolutely. So what specific leverage did the
- 8:54hackers expose this time? What is actually in
- 8:57those six sample screenshots they used as proof
- 9:00of the breach? So the reporting from Information
- 9:03Age details the contents of those six screenshots.
- 9:06Right. And we must explicitly note here that
- 9:09these are the alleged contents of the breach.
- 9:11Very important distinction. This is what the
- 9:13hackers claim to hold used to intimidate the
- 9:15company into pay. Right. So looking at the list,
- 9:17the hackers clearly curated this sample to inflict
- 9:20maximum psychological and operational pressure.
- 9:23Oh, without a doubt. You can basically divide
- 9:25the evidence into two categories, I think, corporate
- 9:27leverage and personal ammunition. Let's look
- 9:29at the corporate leverage first. OK, so on the
- 9:32corporate side, the fourth and fifth screenshots
- 9:34were a bank transfer receipt and a detailed corporate
- 9:37bank statement. Right. Proving they had access
- 9:39to deep financial operations. And then the sixth
- 9:42screenshot amplifies that corporate leverage.
- 9:45significantly. It really does. It was a list
- 9:47of direct contact details. So emails and mobile
- 9:50numbers for corporate staff located in the Philippines,
- 9:53various franchising and operations teams in Australia,
- 9:56and crucially, the direct contacts for the chief
- 9:59executive officer and the chief financial officer.
- 10:02Wow. The CEO and CFO. That brings us to the personal
- 10:06ammunition, which is almost scarier. Yeah, the
- 10:08employee data. The first screenshot was an alleged
- 10:11spreadsheet listing employee first and last names,
- 10:14their gross earnings, their paid leave, overtime
- 10:16bonuses, and withheld taxes. Extremely granular
- 10:20payroll data. Extremely. And most alarmingly,
- 10:23that same spreadsheet. appeared to list the last
- 10:26four digits of the employee's tax file numbers,
- 10:28their TFNs. Which is highly sensitive. And then
- 10:31a second sample was just wild to me. It was an
- 10:33alleged visa application. Right. Containing a
- 10:36passport number, a phone number, a professional
- 10:39email address, and the person's actual home address.
- 10:42Just a complete identity kit right there. Yes.
- 10:44And the third sample was an incident report from
- 10:47a 2025 workplace accident. Yeah, which provides
- 10:51deeply personal, potentially sensitive medical
- 10:54or human resources context. So the threat model
- 10:57changes entirely depending on whose data we are
- 11:00looking at in that sample. Exactly. And the Information
- 11:02Age article actually includes... some critical
- 11:05insights from Nalin Arakulaj. The associate professor.
- 11:08Yes, an associate professor in cybersecurity
- 11:09at RMIT University. And he breaks down exactly
- 11:13how this data is weaponized. Okay, how does he
- 11:15explain it? Well, for the senior executives,
- 11:17the danger really lies in sophisticated corporate
- 11:20fraud. Like using those leaked contact details
- 11:23of the CEO or CFO. Exactly. Those are incredibly
- 11:26valuable because they enable what the industry
- 11:28calls whaling. Whaling. Like phishing, but for
- 11:31the big fish. Precisely. Highly targeted scams
- 11:34and impersonation attacks. Because, I mean, if
- 11:37threat actors have the CEO's exact mobile number,
- 11:41their internal email format, and the context
- 11:44of recent corporate bank transfers. They have
- 11:46everything they need. They can craft an incredibly
- 11:49convincing message. Like they can text a junior
- 11:51accountant at 4 .0 p .m. on a Friday claiming
- 11:55to be the CEO in an urgent meeting. I need you
- 11:58to authorize this massive wire transfer to a
- 12:00new vendor right now. Exactly. And they don't
- 12:03even need to hack the bank at that point. They
- 12:04just hack the human trust within the company.
- 12:07Right. The senior executives are the keys to
- 12:10the corporate vault. Yeah. But Professor Oroklige
- 12:12points out that the danger for junior staff is
- 12:15arguably much worse on a personal level. How
- 12:18so? Because the sensitive data exposed in those
- 12:21other screenshots, the tax file number details,
- 12:23granular earnings information, visa documents,
- 12:26and passport numbers that forms a complete identity
- 12:28profile. And this data isn't just used once,
- 12:31right? No, not at all. In the dark web economy,
- 12:33a profile containing a passport number, a home
- 12:35address and partial TFNs is bundled up and sold
- 12:38to identity brokers. Identity brokers. Yeah.
- 12:42Criminals use automated tools to exploit this
- 12:44information at scale. They use it to open fraudulent
- 12:47lines of credit, apply for loans or file fake
- 12:50tax returns. And the brutal reality here is that
- 12:53junior staff. The people making the gelato or
- 12:57handling the franchise administration, they generally
- 13:00have far fewer financial and legal resources
- 13:02to recover from having their identity stolen.
- 13:05Compared to a corporate executive. Absolutely.
- 13:07Here's where it gets really interesting. Professor
- 13:10Araklage provided a quote in the reporting that
- 13:13I think perfectly captures the terror of this
- 13:17situation. What did he say? He said, once this
- 13:20kind of data is out, you can't change it like
- 13:22a password. It can follow people for years. That
- 13:25is chilling. And it's so true. It is. Because,
- 13:29like, you can cancel a compromised credit card
- 13:31in 10 minutes, right? Avially. You can force
- 13:33a company -wide reset of every single login credential.
- 13:36Yeah, well. But you cannot easily change your
- 13:38tax file number. No, you can't. You cannot alter
- 13:40the history of a workplace injury. Changing a
- 13:43passport number involves significant bureaucratic
- 13:45hurdles. And your home address is your physical
- 13:48reality. This data is permanent. It is permanent.
- 13:51And that permanence is the engine of the extortion.
- 13:53Right. The attackers know that Gelatissimo knows
- 13:56this data cannot be taken back once it is published
- 13:59to the broader internet. Once it's out, it's
- 14:01out. Exactly. If a junior employee's visa application
- 14:04and passport details are leaked, they might not
- 14:06feel the impact tomorrow. Or even next month.
- 14:09Right. But three, four, five years down the line,
- 14:12they could go to apply for a mortgage. only to
- 14:15discover a string of defaulted loans taken out
- 14:18in their name. By someone who bought their identity
- 14:20profile for pennies on some Russian forum. Exactly.
- 14:23The psychological toll of that invisible threat
- 14:26hanging over the workforce is immense. Which
- 14:28brings us to the agonizing reality of the countdown
- 14:30timer. The ticking clock. Yeah. According to
- 14:34the reporting, at the time the articles were
- 14:35published, Dragon Force had set a timer on their
- 14:39dark web leak site. Right. They gave Gelatissimo
- 14:42less than five days. About four days and 12 hours
- 14:45to be exact. Barely any time at all. To respond
- 14:48before they threaten to publish the entire 352
- 14:51gigabyte data set. It is a completely artificial
- 14:54deadline. It's designed purely to force panic.
- 14:57Just to pressure them. Yeah. They want the corporate
- 15:00leadership to make a rushed emotional decision
- 15:03to pay the ransom before they even have time
- 15:06to fully understand the scope of the breach.
- 15:09So how does a company actually operate? when
- 15:12that clock starts ticking. Yeah. I mean, the
- 15:15public usually only sees a brief public relations
- 15:17statement, but behind the scenes, the pressure
- 15:20must be staggering. Oh, it's a war room environment.
- 15:23To understand the response, we really have to
- 15:25separate the hackers' psychological warfare from
- 15:28what Gelatissimo has actually confirmed to the
- 15:30press. Yes, let's stick to the facts. Based strictly
- 15:33on the official statements provided to Information
- 15:35Age and Cyber Daily, the company initiated a
- 15:38very specific sequence of events. First, Gelatissimo
- 15:41confirmed that they did detect unauthorized access
- 15:43to a part of their systems. Okay. They publicly
- 15:46acknowledged that a cyber incident is actively
- 15:48being investigated. Right. Second, immediately
- 15:51upon discovering the incident, they engaged external
- 15:53cybersecurity experts to contain the breach and
- 15:56run the forensics. So they called in the cavalry.
- 15:59And they also stated they are working urgently.
- 16:03To verify the third party's claims, which is
- 16:05crucial, they're trying to understand the exact
- 16:08nature and extent of the impacted information.
- 16:11And finally, they formally notify the Office
- 16:13of the Australian Information Commissioner, the
- 16:16OAIC, and the Australian Cybersecurity Center,
- 16:20the ACSC. If we connect this to the bigger picture.
- 16:23Yeah, you can see the incredible regulatory and
- 16:26operational tightrope the company is walking
- 16:28during those five days. By notifying the OAIC
- 16:31and the ACSC, they are triggering a massive legal
- 16:35and regulatory mechanism. They aren't just dealing
- 16:37with hackers anymore. No, they are no longer
- 16:39just fighting. the hackers. They are on the clock
- 16:41with the federal government. Right. The incident
- 16:44response team is facing this immense forensic
- 16:46bottleneck. Absolutely. They have external analysts
- 16:49desperately combing through network logs, just
- 16:52trying to reconstruct the attacker's path. Because
- 16:54they have to figure out if Dragonforce actually
- 16:57exfiltrated 352 gigabytes of data, or if they
- 17:01only managed to grab those six folders and are
- 17:03just bluffing about the rest. Right. Verifying
- 17:06the scale of the theft takes time. but the artificial
- 17:09countdown timer on the dark web. It doesn't care
- 17:12about forensic timelines. Not at all. And while
- 17:15the technical team is dealing with that forensic
- 17:18bottleneck, the leadership team is managing the
- 17:20legal reporting requirements. Because personal
- 17:23data is involved. Exactly. They have to navigate
- 17:25the notifiable data breaches scheme, assessing
- 17:28the risk of serious harm to individuals, and
- 17:31preparing to formally notify the affected employees
- 17:34and franchisees. And simultaneously, they are
- 17:37managing the human crisis. The staff. Yes. The
- 17:40company spokesperson explicitly stated they're
- 17:43apologizing for the concern the incident caused
- 17:45and that they take the protection of entrusted
- 17:47information very seriously. It's a very tough
- 17:50conversation to have. Imagine trying to communicate
- 17:52with a workforce that is... undoubtedly terrified
- 17:55about the exposure of their passports and tax
- 17:57files. While likely not having all the concrete
- 17:59answers yet because the forensic investigation
- 18:02is still underway. Exactly. You are dealing with
- 18:05an active extortion threat, regulatory demands,
- 18:09panicking employees, and media scrutiny all at
- 18:13the exact same moment. It's a nightmare scenario.
- 18:15So what does this all mean for you? For the listener.
- 18:18Right. When we synthesize the mechanics of the
- 18:21Dragon Force Reyes model, the curation of that
- 18:24sample data, and the impossible corporate tightrope
- 18:26of the response, what is the ultimate takeaway?
- 18:30It becomes very clear that this is not just a
- 18:32story about a gelato chain having a bad week.
- 18:34Not at all. It is a masterclass in understanding
- 18:36how invisible supply chains and everyday networks
- 18:40are the true targets of modern cybercrime. We
- 18:43often default to thinking that cyber warfare
- 18:45only targets massive financial institutions or
- 18:48defense contractors. Right, like the movies.
- 18:50But the reality is that franchising networks,
- 18:52retail chains, and the everyday mundane administrative
- 18:55data they hold. Like payroll processing, visa
- 18:58applications, incident reports. That is the high
- 19:00volume currency of the dark web economy. The
- 19:03threat actors don't care about the product being
- 19:05sold. They don't care about the gelato. They
- 19:08care about the database of human identities required
- 19:10to run the business. It really reframes how we
- 19:14must. Think about the information we hand over
- 19:16to our employers or the businesses we frequent.
- 19:19Definitely. We are trusting these organizations,
- 19:21not just with our labor or our transactions,
- 19:23but with our digital permanence. And that trust
- 19:26is being systematically tested by industrialized
- 19:29extortion operations that view literally every
- 19:31unpatched server as an opportunity to monetize
- 19:34human privacy. It's a sobering reality. It is.
- 19:38If today's discussion has you thinking about
- 19:40your own digital footprint, your business's vulnerabilities,
- 19:43or how to navigate this increasingly complex
- 19:45landscape, we strongly encourage you to visit
- 19:48www .kinsoft .com .au to discuss your own security
- 19:52and IT needs. Because you do not want to wait
- 19:55until an artificial countdown timer appears on
- 19:58a dark web forum to start taking your digital
- 20:00perimeter seriously. Preparation and proactive
- 20:03defense are the only ways to survive in this
- 20:05environment. To wrap up our analysis today, there
- 20:08is a broader societal implication here that builds
- 20:11on everything we have discussed. Something we
- 20:13all need to sit with as these attacks become
- 20:15more frequent. We spent a lot of time discussing
- 20:17Professor Arkaz's insight about how this data
- 20:20is indelible. Right. You can't just change it.
- 20:22If our most sensitive foundational information...
- 20:26Our passport numbers, our tax files, our medical
- 20:29histories cannot simply be reset like a compromised
- 20:33password. Are we rapidly approaching a future
- 20:36where we have to assume our personal history
- 20:39is permanently public? Wow. And if we accept
- 20:41that our data will eventually be breached, how
- 20:44does that fundamentally change the way we live,
- 20:46the way we establish trust, and the way we work
- 20:48online? That is an incredibly unsettling but
- 20:51entirely necessary thought to leave on. Thank
- 20:54you for exploring the mechanics and the human
- 20:56cost of this incident with me.