Latest / Tech Talks With Kinsoft / Lynx Ransomware Targets CBS Tasmania: “Ethical” Claims vs. Reality
Transcript
- 0:00Hello and welcome to Tech Talks with Kinsoft.
- 0:02It's Friday, January 16th, 2026. I'm your host.
- 0:07And if you've been following the news lately,
- 0:09you might feel like the digital ground is just
- 0:11constantly shifting beneath your feet. It really
- 0:13is. And this is the show where we try to, you
- 0:15know, stop the doom scrolling, take a step back
- 0:18and actually unpack what's defining our security
- 0:20landscape. We take the reports, the data, all
- 0:22the messy reality of it and figure out what it
- 0:25actually means. It's great to be here. And you're
- 0:27so right about the ground shifting. I mean, we're
- 0:29starting 2026 with a story that feels like a
- 0:32bit of a throwback to last year's chaos. A twist
- 0:36that really makes you question the motives of
- 0:39the people behind the keyboards. Yeah. Today
- 0:41we're looking at a cyber attack on a Tasmanian
- 0:43nonprofit called Community Based Support, or
- 0:46CBS. This all went down late last year, back
- 0:49in October. Right. And on paper, it looks like
- 0:51a standard data breach. Bad guys get in, data
- 0:54gets out. But there's this bizarre layer of,
- 0:57well, I guess you'd call it... corporate irony
- 1:00on top of the whole thing. Irony is a very polite
- 1:03way of putting it. It's more like a paradox.
- 1:06The group behind this is the Lynx ransomware
- 1:08gang. And if you read their marketing material,
- 1:11and yes, these criminal gangs actually have marketing
- 1:14material. Unbelievable. They claim to have a
- 1:16strict policy against targeting nonprofits and
- 1:19hospitals. Right. The quote unquote ethical criminal.
- 1:23The Robin Hoods of the dark web. We'll steal
- 1:26your data, but we won't steal that data. Precisely.
- 1:29They want to project this image of being like
- 1:31a reasonable business partner. They want victims
- 1:33to think, oh, these are the nice criminals we
- 1:35can negotiate. But this attack on CBS. Just completely
- 1:38dismantles that. It does. So today we aren't
- 1:42just reporting on a breach. We're using this
- 1:44as a case study to look at the volatility of
- 1:47this whole hacker ethics myth and maybe more
- 1:49importantly, the state of ransomware now that
- 1:51we're here in 2026. OK, so we've got a lot to
- 1:54get through. We need to look at the specific
- 1:55data exposed because it's genuinely upsetting.
- 1:58We have to look at the sheer volume of attacks
- 2:00hitting Australia. Spoiler alert, the numbers
- 2:02are bad. They are very bad. And I want to talk
- 2:05about what this all means if you're a business
- 2:06leader listening. If the ethical hackers are
- 2:09coming for nonprofits, then who is safe? So let's
- 2:12start with the victim. Who is community -based
- 2:14support? To really get the severity of this,
- 2:17you have to look at who they serve. CBS Tasmania,
- 2:21I mean, they're not a tech startup. They're not
- 2:23a bank. No. They're a not -for -profit organization.
- 2:25They're dedicated to aged care, disability services,
- 2:29and independent living support. Their whole reason
- 2:32for being... is helping people stay in their
- 2:34homes. So we're talking home modifications, social
- 2:37hubs, helping people with daily tasks, the really
- 2:40essential human stuff. Exactly. And to do that
- 2:44job, to verify eligibility, to tailor that care.
- 2:48They have to hold incredibly sensitive data.
- 2:51You can't run an aged care service without knowing
- 2:53someone's health status, their my aged care number,
- 2:57their Medicare number, their pension details.
- 2:59I was looking at their privacy policy and it's
- 3:00extensive. They collect this stuff because, well,
- 3:03the government requires it and the service demands
- 3:05it. But that just creates this massive honeypot
- 3:07of data. It really does. And that data is valuable,
- 3:11regardless of the moral standing of the organization
- 3:13that's holding it. So take us back to October
- 3:152025. How did this all unfold? Well, CBS just
- 3:19popped up on the Lynx Games dark web leak site.
- 3:21They posted proof of the incident on October
- 3:2410th. Now, CBS came out and they did confirm
- 3:27a cyber incident. They said it was contained
- 3:29and thankfully had no impact on operations. Which
- 3:33is a small miracle in itself. I mean, usually
- 3:35operations just grind to a halt. It is a credit
- 3:38to their IT resilience, for sure, that they kept
- 3:40services running. You know, while the doors stayed
- 3:43open, the digital vault was cracked. They figured
- 3:46out that a subset of data was copied. And this
- 3:49is where I want to pause, because subset of data
- 3:51sounds so clinical, so sterile. It does. But
- 3:53when you look at what Lynx posted to prove they
- 3:56had access, the proof of life, so to speak, it's
- 3:59chilling. Yeah. They posted an employee detail
- 4:01form, a tax invoice, and then there was this
- 4:03one photo that just made my stomach turn. You're
- 4:05talking about an ID card? Yeah, a photo of a
- 4:07working with vulnerable people ID card. It's
- 4:10just such a visceral example of what we're dealing
- 4:12with. That card belongs to a staff member who
- 4:16has been vetted to work with at -risk people.
- 4:19By publishing that, Lynx isn't just proving they
- 4:21hacked a server. No, they're doxing a care worker.
- 4:24Exactly. They're exposing names, residential
- 4:27addresses, ID numbers of the very people who
- 4:30are trying to protect the community. It just
- 4:32proves that the human element is the ultimate
- 4:34vulnerability. You can have firewalls, policies,
- 4:36whatever. But if a sophisticated actor wants
- 4:39in or just one person clicks the wrong link,
- 4:41that data is gone. But this brings me back to
- 4:44that ethical criminal nonsense. You mentioned
- 4:47Lynx has a strict policy. I'm looking at their
- 4:49manifesto from July 2024 right now. The press
- 4:52release, as they called it. It's incredible.
- 4:54It's insane. They literally say their clear intention
- 4:56is to avoid undue harm. They say they encourage
- 4:59dialogue and resolution rather than chaos. It
- 5:02sounds like a mediation firm. We're just here
- 5:04to facilitate a transaction. It's branding. It's
- 5:07pure and simple. We have to understand that in
- 5:102026, ransomware is a business. It's an industry.
- 5:13And like any industry, they have public relations
- 5:15issues. Lynx tries to position themselves as
- 5:18the clean option to lower the heat from law enforcement.
- 5:21Don't chase us, FBI. We don't hit hospitals.
- 5:24Exactly. If you attack a hospital and people
- 5:26die because systems go down, the full weight
- 5:29of the global intelligence community comes down
- 5:31on you. But if you attack a car parts manufacturer,
- 5:33maybe you fly under the radar. But the reality
- 5:36check here is brutal. Despite that manifesto,
- 5:40they hit CBS. They hit CBS. And it's not just
- 5:42CBS. They hit VET track. A student management
- 5:46system. That's education data. And if you look
- 5:49at their broader list, they have over 300 victims.
- 5:52Clutch Industries Automotive Manufacturing lost
- 5:54350 gigs of engineering docs. Brown and Hurley,
- 5:57the truck dealership, lost 170 gigs of HR data.
- 6:01Oof. That HR data is the key, isn't it? That's
- 6:03where the identity theft really kicks in. That's
- 6:05the goldmine. So if they have a manifesto, why
- 6:07just ignore it? Are they just liars? Or is there
- 6:09something more structural happening here? That's
- 6:12the critical question. I think we have to remember
- 6:14how modern ransomware works. It's rarely one
- 6:18guy in a hoodie doing everything. It's ransomware
- 6:20as a service or a race. OK, so break that down
- 6:23for us. Think of it like a franchise model. The
- 6:26Lynx developers, they write the malicious software
- 6:28and they run the payment site, their corporate
- 6:31HQ. Then. They rent that software out to affiliates,
- 6:35freelance hackers who actually break into the
- 6:38networks. So HQ might write a manifesto saying
- 6:41we love nonprofits, but the affiliate who just
- 6:44broke into the server sees a payday and doesn't
- 6:46care. Bingo. The affiliate gets a commission,
- 6:49usually 70 to 80 percent of the ransom. So if
- 6:52they stumble into a nonprofit like CBS, are they
- 6:54going to walk away because of a manifesto on
- 6:56a website? No way. They want their cut. Exactly.
- 6:59The developers might technically disapprove,
- 7:02but they still host the data on the leak site
- 7:04because they want their cut, too. Money beats
- 7:06the manifesto every single time. That makes the
- 7:09whole ethical claim even more dangerous because
- 7:12it gives victims this false sense of security.
- 7:14Oh, we're a charity. We're safe. No, you're not.
- 7:17You're just a target with a different tax status.
- 7:19Correct. And we can say this isn't an isolated
- 7:21incident. If we zoom out to the stats from borderless
- 7:24CS and black fog for late 2025 and early this
- 7:27year, the volume is just staggering. Yeah, I
- 7:30was looking at the January 2025 numbers, a record
- 7:33breaking 92 publicly disclosed attacks in one
- 7:36month. That was up 21 percent from the year before.
- 7:39And it didn't slow down. By December, we were
- 7:42still seeing nearly 80 attacks a month. And look
- 7:44at the sectors. Despite all the talk about avoiding
- 7:47critical infrastructure, health care was the
- 7:49most targeted sector in late 2025. 14 attacks
- 7:53in December alone. That is terrifying. So where
- 7:56does Australia sit in all this? Because it feels
- 7:58like we're hearing about a new breach every single
- 8:00week. We are punching way above our weight, unfortunately.
- 8:02In December 2025, the U .S. made up about 46
- 8:06% of victims, which you'd sort of expect. Sure,
- 8:08big economy. But Australia was second globally.
- 8:10We made up 14 % of the victims. 14%. That is
- 8:14a massive slice of the pie for a country our
- 8:16size. Why are we such a target? It's a combination
- 8:19of things. We're a wealthy nation. We digitize
- 8:22very quickly. But our cybersecurity maturity
- 8:24hasn't always kept pace. We're seen as, you know,
- 8:27cash rich and time poor. Let's talk about some
- 8:30of the big ones, because it's not just the volume,
- 8:32it's who's getting hit. And not just to list
- 8:34them, but to look at the types of attacks. Like
- 8:36we had the massive data dumps, like MediSecure.
- 8:40Right. That was a direct hit on a data aggregator.
- 8:4312 .9 million Australians. That is basically
- 8:46half the country having their prescriptions and
- 8:49Medicare numbers exposed. It's a mass casualty
- 8:52event in digital terms. But then you have the
- 8:55supply chain stuff, right? Like Volkswagen. Yes.
- 8:57800 ,000 EV owners exposed. And that wasn't necessarily
- 9:01a hack of the car itself, but a configuration
- 9:03error in the data handling. It exposed geolocation
- 9:06data. Which is a nightmare. If you can track
- 9:08a car, you can track the person. And then Qantas,
- 9:10up to six million records exposed, but that came
- 9:12through a call center breach, didn't it? Exactly.
- 9:14This is the third party risk we're always talking
- 9:16about. Qantas might have great security, but
- 9:19if the call center they hired has a weak password
- 9:21policy, the data flows out just the same. Even
- 9:24politicians aren't safe. The United Australia
- 9:26Party and Trumpet of Patriots got hit. Which
- 9:29just shows you that ideology doesn't matter to
- 9:31the algorithm. A ransomware scanner doesn't care
- 9:34about your politics. It cares about your open
- 9:36ports. We've talked a lot about links, but they're
- 9:39just one shark in the tank. The marketplace is
- 9:41crowded. We've got groups like Quillen, Ink Ransom,
- 9:44Medusa. Are they all pretending to be ethical,
- 9:47too? No, and that's the contrast. Take Medusa.
- 9:50They are incredibly aggressive. They demanded
- 9:52$150 ,000 from a small ENT clinic and $300 ,000
- 9:55from AirDex Australia. They don't write manifestos.
- 9:57They put up countdown clocks. And Quillen. Quillen
- 10:00is very active. They hit the West Quay Shopping
- 10:02Center and even the Church of Scientology in
- 10:04the U .K., posted visa and financial records.
- 10:07They're all about volume and pressure. You mentioned
- 10:09pressure. We used to talk about double extortion,
- 10:13encrypt the files, then threaten to leak them.
- 10:16But it feels like the tactics are evolving. It's
- 10:19getting nastier. It is. The industry term is
- 10:21moving toward triple extortion or even compliance
- 10:25weaponization. Compliance weaponization. That
- 10:28sounds like a lawyer's fever dream. What on earth
- 10:30does that mean? So imagine a hacker steals your
- 10:33data. You refuse to pay. In the past, they'd
- 10:36just leak it. Now, they might email your customers
- 10:39directly and say, hey, this company lost your
- 10:41data. You should sue them. Wow. Or, and this
- 10:44is the really nasty part, they might threaten
- 10:46to report the breach to the OAIC or the privacy
- 10:49regulator themselves, guaranteeing you get hit
- 10:52with a massive fine if you don't pay the ransom.
- 10:54So they're using our own privacy laws as a weapon
- 10:57against the victim. Pay us a million or pay the
- 11:00government 10 million in fines. Exactly. It turns
- 11:02the regulatory framework into part of their extortion
- 11:04toolkit. That is just diabolical. So let's pivot.
- 11:08If I'm a business owner listening to this, maybe
- 11:11I ran a midsize logistics firm or a nonprofit
- 11:14like CBS. What's the actual takeaway? Because
- 11:17get better firewalls feels a bit. 2015. Firewalls
- 11:22are baseline their table stakes. The real lesson
- 11:25from CBS and these other breaches is about blast
- 11:28radius. Explain that. Okay, so CBS had an ex
- 11:31-employee's tax invoice and documents filed with
- 11:34the health department. Why do they still have
- 11:36that accessible? If you get hit, the damage is
- 11:39determined by what the hackers can grab. If you
- 11:41delete data, you no longer need... data minimization,
- 11:44you limit the blast radius. You can't leak what
- 11:46you don't hold. Correct. If CBS had archived
- 11:49that data into cold storage offline backups or
- 11:52just deleted it after the statutory period, the
- 11:54hackers might have gotten in, but they would
- 11:56have found empty filing cabinets. But instead,
- 11:58they found that working with vulnerable people
- 12:00ID card. And that creates a lifelong headache
- 12:02for that employee. We should touch on that personal
- 12:04impact. If you're the person whose ID card was
- 12:07in that leak, what actually happens? It's not
- 12:09just change your password, is it? No, for a Tasmanian
- 12:12resident in this scenario, it's an administrative
- 12:14nightmare. Service Tasmania guidance says if
- 12:17your driver's license is compromised, you have
- 12:20to apply for a whole new license number, not
- 12:22just a new card, a new number. Which means updating
- 12:25every single service that uses it to verify who
- 12:28you are. Right, and if that specific personal
- 12:30information card is compromised, it's the same
- 12:32thing. You're likely directed to ID care. which
- 12:36is a fantastic service. But having to use it
- 12:38means your life has already been completely disrupted.
- 12:41You are now on Identity Watch for years. It's
- 12:44the gift that just keeps on giving. It is. And
- 12:46the government response, you know, the ACSC,
- 12:48the OAIC, they're there to notify and regulate.
- 12:51In the CBS case, they determined a subset was
- 12:54taken and make sure notifications went out. But
- 12:57regulation can't put the toothpaste back in the
- 12:59tube once that data is on the dark web. It's
- 13:01there. So we have a marketplace of criminals
- 13:03who may or may not lie about their ethics. We've
- 13:06got a franchise model that incentivizes attacks
- 13:08on everyone. And we have a regulatory environment
- 13:11that hackers are now weaponizing. It just feels
- 13:13like we're walking through a minefield. We are.
- 13:16And I think the provocative thought for 2026
- 13:18is this. The line between the ethical hacking
- 13:21groups and the ruthless ones is gone. It's a
- 13:25distinction without a difference. The burden
- 13:27of defense has shifted. It's no longer just about
- 13:29preventing entry. Because as we see with supply
- 13:32chain attacks, entry might happen through a vendor
- 13:34you trust. So the goal is resilience. The goal
- 13:37is asking, if they get in today, can we survive
- 13:41it? And how much data will they actually find?
- 13:44We might be entering an era where data breaches
- 13:46are treated more like natural disasters inevitable.
- 13:48The question is, is your house built to withstand
- 13:51the hurricane? That is a very heavy reality check,
- 13:54but a necessary one. Hope is definitely not a
- 13:56strategy here. No, hope is not a strategy. Preparation
- 13:59is. Well, we've covered a lot of ground today,
- 14:01from the hypocrisy of the Lynx gang to the hard
- 14:04reality of Australian cyber stats. It's complex.
- 14:07It's scary. But ignoring it is the absolute worst
- 14:10thing you can do. Absolutely. Awareness is the
- 14:13first step to defense. Now, if you're listening
- 14:15to this and you're the one responsible for that
- 14:18blast radius in your company and you're maybe
- 14:20starting to sweat a little bit thinking about
- 14:22your own data retention policies, good. That
- 14:25means you're paying attention. But you don't
- 14:27have to panic. Panic leads to bad decisions.
- 14:29You need a plan. Exactly. We don't want you to
- 14:32be the case study on our next show. So if you
- 14:34want to shore up your IT defenses or just figure
- 14:37out where your vulnerabilities actually are,
- 14:39you need to talk to the experts. You should head
- 14:41over to www .kinsoft .com .au. They live and
- 14:46breathe this stuff, so you don't have to. That's
- 14:48www .kinsoft .com .au to discuss your security
- 14:52and IT needs. Get ahead of the problem before
- 14:54it becomes a headline. Couldn't have said it
- 14:56better myself. Thank you so much for joining
- 14:58us on Tech Talks with Kinsoft. Stay safe out
- 15:01there, watch your data, and we'll catch you next
- 15:02time. Bye for now.