Latest / Tech Talks With Kinsoft / NSW Treasury Insider Breach – 5,600 Sensitive Documents Exfiltrated
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. So picture
- 0:03this, you know, it's a quiet Sunday afternoon.
- 0:06Right, the time when absolutely nothing is supposed
- 0:08to be happening in a government office. Exactly.
- 0:10But suddenly, the New South Wales Treasury's
- 0:13internal security alarms just, well, they go
- 0:16off. Which is never a good sign on a Sunday.
- 0:18Oh, definitely not. Yeah. But here's the really
- 0:20wild part. The threat they detected, it wasn't
- 0:23coming from like a Russian server farm. Right.
- 0:26It wasn't some dark web syndicate trying to...
- 0:29brute force of firewall, the call was actually
- 0:32coming from inside the house. Yeah, the worst
- 0:34kind of call. Totally. So today we are unpacking
- 0:37this massive cybersecurity incident where a trusted
- 0:41insider, I mean, someone who already worked there,
- 0:43almost walked out the front door with over 5
- 0:45,600 highly sensitive government files. And,
- 0:48you know, we're going to talk about why it took
- 0:50a lightning fast, like a 24 -hour multi -agency
- 0:53strike force to actually stop him. Because it's
- 0:56a case that really... fundamentally rewrites
- 0:58how a lot of organizations need to think about
- 1:01their threat landscape. I mean, traditionally,
- 1:03we think of cybersecurity like a medieval castle,
- 1:05right? Oh, absolutely. You build the walls as
- 1:08high as possible. Right. You build high, impenetrable
- 1:10walls. Yeah. But this incident isn't about someone
- 1:13breaching the walls. What happens when the threat
- 1:15is just, well, someone who already has the keys
- 1:17to the castle? Well, when the attacker already
- 1:20has legitimate credentials, all those external
- 1:22defense mechanisms you've spent millions of dollars
- 1:25on, they instantly become totally irrelevant.
- 1:29Which is exactly why we need to talk about this
- 1:32today. Because if you are managing an IT stack
- 1:35or, I mean, even just running a business where
- 1:37your employees handle sensitive data, this scenario
- 1:40is your absolute worst nightmare. Oh, without
- 1:43a doubt. So let's look at the facts based on
- 1:45the public statements from the NSW police and
- 1:48the state's treasurer, Daniel Mookie. We're looking
- 1:51at an incident where a 45 -year -old man, an
- 1:53employee, allegedly executed this massive data
- 1:57exfiltration to an external server. Right. And
- 2:00we should point out he had been with the Treasury
- 2:01for about three years. Three years. So not a
- 2:03newbie. No, not at all. And that three -year
- 2:07tenure is a critical detail, you know? This wasn't
- 2:10a new hire making some clumsy mistake during
- 2:13their first week of onboarding. Yeah, clicking
- 2:15the wrong button or something. Exactly. This
- 2:17was someone with an established track record,
- 2:19a known entity within the organization. So they
- 2:22had a history, right? A baseline of normal behavior
- 2:24and established relationships with the actual
- 2:27systems they were using every day. Which makes
- 2:29the whole detection part of this event so fascinating
- 2:32to me. Because the treasurer... specifically
- 2:35revealed that this wasn't caught by like the
- 2:38perimeter defenses blocking a hacker. Right.
- 2:41It wasn't the firewall. Yeah, it was flagged
- 2:43by what they called internal security monitoring.
- 2:46But I kind of want to push back on the simplicity
- 2:47of that phrase because. Internal security monitoring
- 2:51sounds like a security guard just watching a
- 2:53CCTV feed, you know. Yeah. Sipping coffee and
- 2:56staring at a screen. Exactly. Yeah. But technologically
- 2:59speaking, I mean, if an external firewall is
- 3:02like a bouncer at the front door, is internal
- 3:04monitoring more like a bank vault alarm? Yeah.
- 3:08Like it triggers not when someone breaks in,
- 3:10but when a trusted employee tries to carry too
- 3:13much cash out. That's a really great way to put
- 3:16it, because it is incredibly complex. The traditional
- 3:19security model is essentially, as you said, border
- 3:21control. Right. You check the passport at the
- 3:24perimeter. And if the passport is valid, meaning
- 3:26the username and password are correct, the person
- 3:30is just allowed in. They're in the country. They're
- 3:32in. But insider threat monitoring operates entirely
- 3:36differently. It doesn't care about your passport.
- 3:38It cares about your behavior once you're inside.
- 3:41It's more like it's like the IRS audit. your
- 3:44spending habits after you already live in the
- 3:46country. Oh, wow. OK. Right. Like it doesn't
- 3:48care that you're a citizen. It cares that a mid
- 3:51-level manager suddenly bought like three luxury
- 3:54yachts in cash. OK. That makes perfect sense.
- 3:57So the system isn't authenticating identity anymore.
- 3:59It's authenticating behavior. Precisely. And
- 4:02the technology driving this is typically called
- 4:04user and entity behavior analytics or UEBA. UEBA.
- 4:08Yeah. And these systems. They spend weeks or
- 4:12even months purely observing. They just watch.
- 4:14And they build a unique behavioral fingerprint
- 4:17for every single user on the network. So it's
- 4:19basically learning everyone's daily routine.
- 4:21Exactly. It learns that, say, employee A logs
- 4:24in at 8 .30 a .m., typically accesses the HR
- 4:27database, maybe downloads 10 megabytes of PDF
- 4:31files a day, and then logs out at 5 .00 p .m.
- 4:35That is their established baseline. Right. So
- 4:37if employee A suddenly logs in at, I don't know,
- 4:402. a .m. on a Sunday and starts pulling gigabytes
- 4:43of data from a completely different department.
- 4:45The system sees the yachts. Right. The system
- 4:47sees the three luxury yachts. Exactly. It flags
- 4:49the anomaly immediately. And in this specific
- 4:52NSW Treasury case, the trigger was the alleged
- 4:55transfer of a substantial cache of documents
- 4:57around 5 ,600 files actually to an external server.
- 5:015 ,600 files? I mean, that's a lot. It's massive.
- 5:04Opening 50 files over in an eight -hour shift
- 5:07on a Tuesday? That's normal workflow. but packaging
- 5:105 ,600 files and attempting to route them to
- 5:13some unrecognized external IP address on a Sunday
- 5:17afternoon. Yeah, that's not normal. No, it's
- 5:19a critical deviation from the baseline. Okay,
- 5:22but let me play devil's advocate here for a second,
- 5:23because I can hear IT administrators listening
- 5:26to this, and they're probably thinking about
- 5:28false positives. Oh, the bane of every IT admin's
- 5:32existence. Right, because if you tune an algorithm
- 5:34to flag anomalies, doesn't the security team
- 5:37just get absolutely burnt? Buried in alerts every
- 5:40time someone has to, like, do a massive quarterly
- 5:43report or archive a giant project folder? Yeah,
- 5:46they do. So how does the system know this specific
- 5:48external transfer was actually malicious and
- 5:52not just, you know, an employee trying to catch
- 5:53up on work from home over the weekend? Well,
- 5:55that is the exact friction point of internal
- 5:58monitoring. If the system is tuned to be too
- 6:00sensitive, you get alert fatigue. Right. The
- 6:03boy who cried wolf. Exactly. And then the security
- 6:05team just starts ignoring the warnings. But if
- 6:08it is too loose, well, 5 ,600 files just walk
- 6:12right out the door. So how do you find that balance?
- 6:14The way modern systems solve this is through
- 6:16context and risk scoring. It isn't just one single
- 6:20metric that triggers the big alarm. It is the
- 6:22confluence of multiple high -risk indicators
- 6:25happening all at once. Okay. What kind of indicators
- 6:27are we talking about? Give me an example. Well,
- 6:29think about the data itself. A robust environment
- 6:31also uses data loss prevention or DLP tagging.
- 6:35Okay. So every file is basically tagged based
- 6:38on its sensitivity level. The system isn't just
- 6:40saying, hey, this user is moving 5 ,600 files.
- 6:43Right. It's more specific. Much more specific.
- 6:45It's saying this user is moving 5 ,600 files
- 6:48and 80 % of them contain metadata tagged commercial
- 6:52and confidence. Oh, wow. Yeah. And it's also
- 6:55saying the destination IP address has absolutely
- 6:58no known association. with our authorized government
- 7:01vendors, and this is all happening outside of
- 7:04typical business hours. I see. So it's the compounding
- 7:07factors that create the conviction. It's the
- 7:09sheer volume plus the high sensitivity of the
- 7:11tags plus the weird destination plus the weird
- 7:14timing. Exactly. Each of those individual factors
- 7:18adds points to a total risk score. And when that
- 7:22score crosses a certain critical threshold, the
- 7:25alert isn't just a passive log entry that someone
- 7:28might check tomorrow. It's a flashing red light
- 7:31right now. It's alarms ringing everywhere. Well,
- 7:33let's talk about the specific data involved here,
- 7:36actually, because that really explains why this
- 7:38alert was treated with such intense urgency by
- 7:41the government. Definitely. This employee, the
- 7:4345 -year -old guy, he wasn't working in just
- 7:46some generic administrative role. He was actually
- 7:49part of the Treasury's commercial team. Right.
- 7:52So what does that actually mean in terms of the
- 7:54kind of information he had legitimate access
- 7:56to? Well, the commercial team within a state
- 7:58treasury, I mean, they are the financial engine
- 8:00room for government operations. OK. They do not
- 8:03just manage like internal payroll or office supplies.
- 8:06They're intimately involved in the state's commercial
- 8:09relationships and their biggest transactions.
- 8:12We are talking about highly delicate, high stakes
- 8:15negotiations with the private sector. So basically
- 8:18the financial blueprints of exactly how the state
- 8:20does business. Yes, exactly. And Treasurer Mookie
- 8:24emphasized that these files spanned multiple
- 8:26NSW government departments and various massive
- 8:29projects. This team handles 10. I mean, if you
- 8:41were an outside commercial entity, right, like
- 8:43a private company bidding for a billion dollar
- 8:46government contract, knowing the states. internal
- 8:49pricing models and their bottom line leverage,
- 8:51it's basically a cheat code. Oh, it's incredibly
- 8:54valuable intelligence. It is an absolute goldmine.
- 8:56And honestly, that brings us to the hardest problem
- 8:58in all of information security. Which is? The
- 9:00dilemma of authorized access. Because of his
- 9:03specific role on the commercial team, this employee
- 9:06had legitimate, completely required access to
- 9:09these files. He literally needed to open them,
- 9:11read them and process them just to do his daily
- 9:14job. I'm just trying to wrap my head around how
- 9:17difficult that makes the IT team's job. Because,
- 9:20you know, to the operating system, his login
- 9:22is perfectly valid. His permission levels are
- 9:25completely correct. The computer is just saying,
- 9:26yes, you are authorized to view this tender document.
- 9:30Exactly. So the line between an employee diligently
- 9:33doing their job by reading a contract and an
- 9:36employee stealing the state's financial leverage
- 9:39is just. It's paper thin. It is entirely behavioral.
- 9:42That's the only difference. You cannot use a
- 9:44traditional padlock to stop this because the
- 9:46employee holds the master key to the padlock.
- 9:48Right. And this is exactly why the suspected
- 9:51transfer to an external server is the defining
- 9:53action here. The security system doesn't necessarily
- 9:56flag the fact that he accessed the files. It
- 9:58flags the exfiltration. Moving of the file. Yes.
- 10:01It notices the digital supply chain suddenly
- 10:03rerouting to some unauthorized unknown warehouse.
- 10:06And because this data held the literal fight.
- 10:09leverage of the state, an anomaly like that wasn't
- 10:12going to just generate some generic IT ticket
- 10:15to be reviewed over coffee on a Monday morning.
- 10:17No, absolutely not. It triggered an immediate
- 10:19crisis, which really explains the sheer velocity
- 10:22of the government's response. Because when you
- 10:25look at the timeline provided in the public statements,
- 10:28it is genuinely staggering. The timeline is a
- 10:31literal masterclass in incident response. I mean,
- 10:34the internal monitoring system detected the transfer
- 10:37and the breach was reported to the NSW police
- 10:40on a Sunday. And we really need to pause on that
- 10:43for a second. A Sunday. Yeah. Usually you think
- 10:45of massive bureaucratic government processes
- 10:48just grinding to a complete halt over the weekend.
- 10:50Like you assume an alert on Sunday afternoon
- 10:53just sits in an email queue until nine zero zero
- 10:56a .m. Monday. Yeah. In a legacy system. Sure.
- 10:58But. Not in a mature security operations center.
- 11:01An alert of this severity involving commercial
- 11:04treasury data triggers an automated escalation
- 11:07immediately. And the response from law enforcement
- 11:10was just as immediate. By Monday, literally the
- 11:13very next day, the NSW Police Cybercrime Squad
- 11:16and a specialized unit called Strike Force Civic
- 11:19were fully operational. That's crazy fast. It
- 11:23is. They tracked down and arrested the 45 -year
- 11:25-old man right in the middle of Sydney's CBD.
- 11:28I mean, to go from a system alert on a Sunday
- 11:30to a physical arrest in the city center on Monday
- 11:33is practically unheard of. It really is. Because
- 11:36we constantly see... headlines about these infamous
- 11:38corporate breaches where attackers just linger
- 11:41inside a network for six, eight, sometimes 12
- 11:44months. Yeah, just dwelling in the network. Exactly.
- 11:46They quietly siphon off data and the company
- 11:49only finds out a year later when the FBI knocks
- 11:52on their door or, you know, worse, when their
- 11:54data pops up for sale on the dark web. So how
- 11:57does a government agency actually achieve a 24
- 11:59-hour turnaround like this? Well, it proves the
- 12:02absolute necessity of preparation and automation.
- 12:05You do not execute a Sunday to Monday takedown
- 12:07involving the Treasury, the Cybercrime Squad,
- 12:10and a dedicated strike force simply by winging
- 12:13it. Right, you can't just make it up on the fly.
- 12:15No. This requires highly sophisticated security
- 12:18orchestration, automation, and response platforms.
- 12:22Or SOR platforms. Okay, SOR. Break that down
- 12:26for us. What does an automated response actually
- 12:29look like in those critical first few minutes
- 12:31after the alarm goes off? Sure. So when that
- 12:34UB best system we discussed earlier flags the
- 12:36critical risk score, it doesn't just send an
- 12:39email to an admin. A SO platform will automatically
- 12:42execute a predefined containment playbook. And
- 12:46without waiting for a human analyst to wake up
- 12:48and approve it, the system likely isolated the
- 12:51employee's endpoint right then and there. So
- 12:53it just cuts them off. Exactly. It severed the
- 12:55machine's connection to the broader network and
- 12:57the internet, immediately stopping the external
- 12:59transfer in its tracks. Wow. So it essentially
- 13:02freezes the device in time. Yes. It quarantines
- 13:04the threat instantly. And then it alerts the
- 13:07on -call security leadership. The fact that the
- 13:10NSW chief cybersecurity officer could immediately
- 13:12step in and coordinate a whole of agency response
- 13:14means the connective tissue between the IT department,
- 13:17the agency leadership, and law enforcement was
- 13:20already built. They had run the drills. Exactly.
- 13:22They had run the drills. Everyone knew their
- 13:24role. The literal second the alarm went off.
- 13:28And I think the physical law enforcement action
- 13:30is just as crucial as the digital containment
- 13:33here. Because while Strike Force Civic was arresting
- 13:37the suspect in the CBD, police were actually
- 13:40simultaneously executing a search warrant at
- 13:42a home in Homebush West. Right. And during that
- 13:46raid, they seized electronic devices. Right.
- 13:48And the police statements explicitly noted. they
- 13:51seized a hard drive. And that is the physical
- 13:53manifestation of neutralizing the threat. Because
- 13:56in cyberspace, data can be infinitely replicated.
- 13:59Yep, just copy and paste. Exactly. You can lock
- 14:01down the network all you want, but if the exfiltrated
- 14:03data is already sitting on a hard drive in someone's
- 14:06living room, well, the breach is still active.
- 14:08Yeah, you can't just delete a server log to hide
- 14:11your tracks when the police physically kick in
- 14:13the door and confiscate your actual storage media.
- 14:15Precisely. Securing the physical hardware is
- 14:18really the only way to ensure the data doesn't
- 14:21make it to a secondary buyer or get leaked publicly
- 14:23online. Right. And following the raid, the man
- 14:26was officially charged with accessing and modifying
- 14:29restricted data held in a computer. He was granted
- 14:31conditional bail and he was scheduled to appear
- 14:34before the Downing Center local court on June
- 14:363. But, you know, the police action is really
- 14:39only half the battle. While Strike Force Civic
- 14:42is handling the suspect and bagging the physical
- 14:44drives, what is actually happening back at the
- 14:47Treasury? Because if I'm a citizen or a private
- 14:50business currently negotiating a big contract
- 14:52with the state, I am terrified about the fallout
- 14:55of this. Of course. But the government's containment
- 14:58response was incredibly reassuring on that front.
- 15:01First off, police stated they believe all the
- 15:03alleged stolen data was located and is now fully
- 15:05secure. Which is the best possible outcome. Absolutely
- 15:08the best outcome. Second, they confirmed there
- 15:10was no external compromise to the agency's systems
- 15:13at all. Meaning while all these internal alarms
- 15:16were ringing and chaos was happening inside,
- 15:18no outside opportunistic hackers managed to,
- 15:22like, slip through the perimeter in the confusion.
- 15:25Right. The external defenses held strong the
- 15:28entire time. And furthermore, the NSW chief cybersecurity
- 15:31officer executed the containment strictly according
- 15:35to the state's existing cybersecurity plan. OK.
- 15:37And the ultimate result of that highly coordinated
- 15:40effort is that they could confidently announce
- 15:42there was no current impact on any NSW government
- 15:46services. The citizens relying on the state weren't
- 15:49disrupted. The infrastructure didn't falter.
- 15:51Which really highlights that rapid containment
- 15:54is just as critical as prevention. if not more
- 15:57so. Definitely. I mean, you might not be able
- 15:58to stop a trusted employee from deciding to act
- 16:00maliciously on a random Sunday afternoon. But
- 16:04if your systems can detect it instantly, freeze
- 16:06the endpoint, and get police to secure the physical
- 16:09data within 24 hours, you have successfully neutralized
- 16:12the threat before the real damage is realized.
- 16:15It is a textbook example of organizational resilience
- 16:17because resilience isn't about never having a
- 16:20security incident. That's impossible. Right.
- 16:22It is about your organization's ability to absorb
- 16:25the shock, contain the blast radius, and just
- 16:27maintain operations without skipping a single
- 16:30beat. So synthesizing everything we talked about
- 16:33today, What are the core technical realities
- 16:36that, you know, every single organization needs
- 16:39to take away from this Treasury incident? Well,
- 16:42I think there are three primary takeaways here.
- 16:44First, the perimeter is no longer the sole battleground.
- 16:47The people inside your organization, precisely
- 16:50because of their authorized access, pose a massive
- 16:54and highly complex risk. The call is coming from
- 16:57inside the house. Exactly. Second, it proves
- 16:59the absolute necessity of contextual behavioral
- 17:02monitoring. Simple rule -based security just
- 17:05fails against insider threats. Yeah, because
- 17:07they have the right passwords. Right. You need
- 17:10systems like UEBA and DLP that actually understand
- 17:13what normal workflow looks like so they can immediately
- 17:15flag high -risk deviations based on volume, sensitivity,
- 17:19and destination. And the third takeaway. Third,
- 17:21detection is entirely useless without an automated
- 17:24coordinated response. If you detect a breach
- 17:26on Sunday but you don't act until Monday morning,
- 17:29the data is already gone. Yeah, you need those
- 17:31automated SR playbooks to freeze the threat instantly
- 17:34and the organizational muscle memory to rely
- 17:37on law enforcement right away. It really forces
- 17:40a complete paradigm shift in how you view data
- 17:43protection. It really does. And you know, that
- 17:45actually brings me to a final lingering thought
- 17:47for you, the listener, to ponder on your own.
- 17:50We have spent the last 30 years in the tech industry
- 17:53obsessively focusing on building taller and thicker
- 17:56digital walls to keep the bad guys out. Yep.
- 17:59But as those parameters become more and more
- 18:01impenetrable, the easiest way out is through
- 18:04the people who already hold the keys. So will
- 18:07the entire future frontier of cybersecurity simply
- 18:10become about monitoring the behavior of the people
- 18:12we have already decided to trust? It is a really
- 18:15challenging reality to confront. But honestly,
- 18:18when the technology is perfectly secure, the
- 18:20human element becomes the primary vulnerability.
- 18:23Trust, but verify, has never been more relevant
- 18:25than it is right now. It really hasn't. Well,
- 18:28we want to warmly thank you for joining us on
- 18:30this episode of Tech Talks with Kinsoft. We hope
- 18:32this discussion gave you a sharper perspective
- 18:34on the mechanics of insider threats and the reality
- 18:37of modern incident response. Yeah. Understanding
- 18:40the specific tactics and technologies involved
- 18:42is really the crucial first step in evaluating
- 18:45your own defenses. Absolutely. And if today's
- 18:48conversation has you thinking about the visibility
- 18:50within your own networks, we warmly encourage
- 18:52you to visit www .kinsoft .com .au. Whether you
- 18:57are looking to discuss your personal security
- 18:59architecture or you need to explore comprehensive
- 19:01IT and security solutions for your business to
- 19:04prevent exactly these kinds of blind spots, the
- 19:06team at Kensoft is ready to help you build that
- 19:08resilience. Thanks again for listening, and we'll
- 19:11catch you on the next one.