Latest / Tech Talks With Kinsoft / 3P Corporation – Space Bears Claims a Melbourne Finance Firm
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. I mean, imagine
- 0:02you are running a business, right? Your security
- 0:05dashboards are flashing green and your automated
- 0:08IT reports are proudly declaring, you know, zero
- 0:11data stolen. Yeah. Everything looks perfect on
- 0:14paper. Exactly. The system worked. But at that
- 0:17exact moment, cyber criminals are literally standing
- 0:21in the public square waving around your client's
- 0:23most private financial data for anyone to see.
- 0:26It is a total nightmare scenario for any company.
- 0:29Today we are unpacking this modern digital hood
- 0:33unit. It is basically the cybersecurity equivalent
- 0:35of a bank manager standing in front of you, arms
- 0:37crossed, insisting the vault is perfectly secure
- 0:40and the alarms never went off. Right. While,
- 0:43you know, literally across the street, the bank
- 0:45robbers are happily handing out the bank's cash
- 0:47to random passersby. They're handing out the
- 0:49cash, the safe deposit boxes, the security camera
- 0:51footage, and honestly, probably the bank manager's
- 0:54personal diary too. Yeah, pretty much everything.
- 0:57Because the contradiction between what internal
- 0:59systems report and what threat actors publicly
- 1:01demonstrate, well, it's becoming one of the most
- 1:04pressing challenges in incident response today.
- 1:06Oh, for sure. And our target in this specific
- 1:09mystery is 3P Corporation. They are this boutique
- 1:13financial services aggregate based right in the
- 1:15heart of Melbourne's finance district. Right
- 1:17down in Melbourne. Yeah. Founded back in 2013
- 1:19by the author and TV personality Peter Ziggy.
- 1:23They offer like a comprehensive suite of services.
- 1:26We are talking accounting, tax, financial planning,
- 1:30legal advice, human resources. And that business
- 1:34model is precisely why they are so relevant to
- 1:37this discussion, because a financial services
- 1:39aggregate isn't just a single company, right?
- 1:41No, it's like a hub. Exactly. It functions as
- 1:44a central nervous system for thousands of other
- 1:46entities. When attackers look at a boutique firm
- 1:49like 3P, they don't just see one target. They
- 1:52see a backdoor. Right, a backdoor into every
- 1:54single business client that relies on 3P for
- 1:56payroll or tax lodgment or legal structuring.
- 1:59Yeah, it is a classic supply chain attack. Which
- 2:02makes them an absolute goldmine. I mean, they
- 2:05hold the actual crown jewels of identity theft
- 2:07for thousands of people. But, you know, they
- 2:10probably don't have the billion dollar cybersecurity
- 2:12budget that a massive bank does. Or the, you
- 2:15know, 500 person 2047 Security Operations Center
- 2:18either. Right. Exactly. They operate on leaner
- 2:21margins, which creates this massive asymmetry
- 2:24that hackers just love to exploit. And that asymmetry
- 2:28brings us to the threat actor involved here.
- 2:30The ransomware gang calls themselves Space Bears.
- 2:34Space Bears. You know, you got to love the names
- 2:37these groups come up with. It's ridiculous, but
- 2:39they are very serious. They are not a legacy
- 2:42group that has been around for a decade, though.
- 2:44They emerged onto the scene relatively recently,
- 2:47back in April 2024. Oh, OK, so fairly new. Yeah,
- 2:50but they were presumed to be a Russia -based
- 2:52operation, and they function like a highly efficient
- 2:54corporate enterprise. I mean, before this incident,
- 2:57they had already claimed to 71 victims worldwide.
- 2:59Wow. 71. And they have a proven track record
- 3:02locally in Australia, too, right? They absolutely
- 3:04do. Yeah, because their most recent Australian
- 3:07victim prior to this was a New South Wales charity,
- 3:10Christian Community Aid, which was breached by
- 3:13them in January of 2025. So, I mean, they aren't
- 3:16just making idle threats. No, not at all. They
- 3:19possess the operational capacity to infiltrate
- 3:21and extract data, which. you know, sense the
- 3:24stage for the incident at 3P Corporation. Right.
- 3:26Let's get into the timeline. So according to
- 3:28the timeline provided by Space Bears, they compromised
- 3:313P systems on April 7, 2026. Okay, April 7. And
- 3:36just three days later, on April 10, the group
- 3:38publicly listed 3P on their dark web leak site.
- 3:42They claimed a massive haul over 200 gigabytes
- 3:46of data. 200 gigabytes. And the specifics of
- 3:49that claim were honestly terrifying. Space Bears
- 3:51stated they had the core database, internal financial
- 3:54documents and the personal information of both
- 3:56employees and clients. Yeah, it's basically the
- 3:58worst case scenario list. And they set a ransom
- 4:00deadline for around April 18, basically issuing
- 4:03an ultimatum, you know, pay up by the state or
- 4:06we release everything to the public. Well, and
- 4:08when a threat actor makes a claim like that.
- 4:10You have to remember, they are relying heavily
- 4:11on fear. Sure. Ransomware groups are, by nature,
- 4:14criminal extortionists. They have a massive vested
- 4:18interest in exaggerating their whole. Right.
- 4:20To scare the executive. Exactly. To terrify a
- 4:24company's executive board into authorizing a
- 4:26payout. But I would assume they bluff constantly.
- 4:29Right. I mean, a hacker could. Theoretically
- 4:32grab a tiny handful of superficial files like
- 4:35some public marketing brochures or I don't know
- 4:37an outdated employee phone list. Oh happens all
- 4:39the time. And then they loudly claim they possess
- 4:41the crown jewels. You can't just take a professional
- 4:44liar at their word. No you really can't. That
- 4:47critical thinking is essential in crisis management.
- 4:50Security teams assume the adversary is lying
- 4:53until proven otherwise. Makes sense. This is
- 4:56why a company's initial reaction relies so heavily
- 4:58on their own internal telemetry, the automated
- 5:02data and system alerts flowing through their
- 5:04network. But look, if you are a 3P corporation,
- 5:06you can't just ignore a ticking ransom clock.
- 5:08You have to respond to the public claim. You
- 5:10do. And their response wasn't a negotiation.
- 5:14It was a flat out rejection. The contrast between
- 5:18the attacker's claim and the company's official
- 5:20stance is incredibly stark here. 3P completely
- 5:24and unequivocally disputed the claim that any
- 5:26data was stolen. Yeah, they did. A spokesperson
- 5:29for 3P confirmed that an incident did take place
- 5:32on April 7. But they deliberately framed it as
- 5:36an attempted ransomware attack. Attempted. So
- 5:38they are saying it failed. Right. The company
- 5:40laid out a very confident corporate defense based
- 5:43on, well, basically two distinct pillars. So
- 5:46the first pillar was operational. They stated
- 5:48their internal investigations found their systems,
- 5:50detected the attack and stopped it before any
- 5:53data could be compromised. Right. So the system
- 5:55worked. The alarms went off. The automated doors
- 5:57locked. The threat was neutralized. And the second
- 5:59pillar of their defense was structural. Yeah.
- 6:02This part is really interesting. Interesting.
- 6:03They argued that because three key corporation
- 6:05LTD is technically a holding company, it does
- 6:09not hold any direct client data in the first
- 6:11place. Oh, wow. So they're saying they literally
- 6:12don't even possess the things the hackers are
- 6:15claiming to have stolen. Exactly. The logical
- 6:17conclusion being. There was nothing sensitive
- 6:20for the hackers to steal, even if they had bypassed
- 6:22the defenses. Well, to be fair to 3P, they didn't
- 6:25just sweep the internal alert under the rug.
- 6:27I mean, they followed the textbook procedural
- 6:30playbook for an attempted breach. They absolutely
- 6:33did the right things procedurally. Yeah, they
- 6:35reported the incident and the findings of their
- 6:38internal investigation to the Australian Cybersecurity
- 6:40Center. They informed their staff. They proactively
- 6:44notified potential clients that an incident had
- 6:47occurred, and they closed the perceived gaps
- 6:50in their network to strengthen their controls.
- 6:53On paper, that is exactly how you handle a neutralized
- 6:56threat. You rely on your system logs, you notify
- 6:59the relevant authorities, and you reassure your
- 7:02stakeholders. Right. But this brings us back
- 7:04to the central mystery. The company says their
- 7:06system stopped the attack, no data was taken,
- 7:08and they structurally don't hold client data.
- 7:11Right. The vault is perfectly secure. But the
- 7:13hackers stand there claiming they possess over
- 7:15200 gigabytes of it. And the burden of proof
- 7:18shifts heavily when that ransom deadline expires.
- 7:21Because when April 18 passed without a payment,
- 7:24Space Bears didn't just walk away. No, they followed
- 7:27through. Yeah, they followed through on their
- 7:28threat, moving from making claims on the dark
- 7:31web to actually publishing the files. And they
- 7:34published a 213 .3 gigabyte compressed archive
- 7:38to a popular clear web file hosting site. And
- 7:41that clear web aspect is crucial. Right, it's
- 7:44not hidden away. Exactly. They didn't bury this
- 7:47in some obscure, heavily encrypted corner of
- 7:49the dark web where only sophisticated hackers
- 7:51congregate. By putting it on a clear web hosting
- 7:54site, anyone with a standard web browser could
- 7:57reach it. And the metrics on that file hosting
- 7:59site are just staggering. According to the site's
- 8:02own properties, that massive archive was downloaded
- 8:05196 times. Wow. 196 times. That isn't just one
- 8:10security researcher looking at it. That represents
- 8:12potentially 196 different threat actors or identity
- 8:15thieves or data brokers grabbing a complete copy
- 8:18of the archive for themselves. To determine the
- 8:21truth between the two competing narratives, journalists
- 8:23at Cyber Daily conducted a review of this leaked
- 8:26data. Oh, good. So we have actual eyes on the
- 8:29payload. Yeah. They examined the 30 folders of
- 8:32company data that were dumped and what they found
- 8:34forcefully dismantled the company's defense that
- 8:38a holding company doesn't hold direct client
- 8:40data. Wow. OK, so what was actually in it? Well,
- 8:44the contents are highly sensitive and incredibly
- 8:45specific. The leak includes hundreds of authority
- 8:49to deduct funds forms. Authority to deduct funds.
- 8:53So those are used for tax returns, right? Exactly.
- 8:56And they feature full bank details. They feature
- 8:58actual wet signatures from customers. And they
- 9:01are stamped on official 3P letterhead. Oh, that's
- 9:04not good. No. They were even found in a folder
- 9:06explicitly labeled 3P accounting and tax trust
- 9:09account. Man, that totally destroys the holding
- 9:12company argument. It does. The review also uncovered
- 9:15trust account statements. remittance advice,
- 9:17employee pay slips, and internal document templates.
- 9:20The files relate to more than 4 ,500 business
- 9:23service clients. 4 ,500 businesses. Yeah, we
- 9:26are looking at their private correspondence,
- 9:28their tax returns, and signed corporate deeds.
- 9:31The most terrifying discovery, though, was a
- 9:34single document within this leak that contains
- 9:36more than 2 ,700 tax file numbers. 2 ,700 TFNs.
- 9:42Yeah, a tax file number is the absolute holy
- 9:44grail for IT. identity theft in Australia. Because
- 9:47you just can't change it, right? Exactly. It
- 9:49functions as a permanent identifier. You cannot
- 9:51easily change it if you can change it at all.
- 9:53When an identity thief acquires a TFN alongside
- 9:56a wet signature, a person's full name, and their
- 9:59banking details, they possess a complete turnkey
- 10:02kit for executing severe financial fraud. That's
- 10:05horrifying. They can open lines of credit. file
- 10:08fraudulent tax returns, and systematically dismantle
- 10:11a person's financial life. So we are looking
- 10:13at what I can only describe as Schrodinger's
- 10:16brooch. I like that. You know the famous thought
- 10:18experiment, right? Yeah. The cat in the box is
- 10:21simultaneously alive and dead until you open
- 10:24it and look. In this case, the data is allegedly
- 10:27completely safe, locked away and uncompromised,
- 10:30according to the company's internal system logs
- 10:32and official statements. But simultaneously,
- 10:35it is demonstrably public, downloaded nearly
- 10:38200 times and being analyzed by journalists on
- 10:41the clear web. Schrodinger's breach perfectly
- 10:43captures the cognitive dissonance of modern incident
- 10:46response. I mean, it highlights a dangerous overreliance
- 10:50on internal software to tell us what reality
- 10:52is. Wait, if the logs say everything is fine,
- 10:55but the data is demonstrably gone, the hackers
- 10:58must be tampering with the cameras, so to speak,
- 11:00right? Yes, exactly. Are they just logging in
- 11:02as administrators and simply turning the security
- 11:04software off so it can't record them? That is
- 11:07one of the primary methods, and it requires a
- 11:09fundamental shift in how we understand cybersecurity
- 11:12software. People tend to view security logs as
- 11:15this omniscient, all -seeing eye that monitors
- 11:17the entire network from above. Like a magic camera.
- 11:20Right. But logs are just software programs. They
- 11:23only show you what they are specifically consigned
- 11:26to monitor, and crucially, they only report what
- 11:30the operating system's permissions allow them
- 11:32to see. OK, so if an attacker gains administrative
- 11:35privileges, maybe by stealing the credentials
- 11:38of a high level IT worker through a phishing
- 11:41email, they basically become the boss of the
- 11:44network. They can just tell the security cameras
- 11:46to look the other way. Or they can operate entirely
- 11:49out in the open using legitimate tools. This
- 11:52is a tactic known as living off the land. Living
- 11:54off the land. What does that mean in this context?
- 11:57Well, IT departments back up. gigabytes of data
- 12:00every single day, right? They use standard file
- 12:02transfer software to move massive amounts of
- 12:04information to cloud servers for safekeeping.
- 12:07Sure, regular maintenance. If an attacker uses
- 12:09those exact same administrative tools to move
- 12:11the data out of the network, the security software
- 12:14doesn't trigger an alarm. Oh, wow. It looks at
- 12:17the activity and assumes it's just a routine
- 12:19Tuesday server backup performed by an authorized
- 12:22user. So the software isn't broken. It's just
- 12:25being tricked by stolen credentials into validating
- 12:27the robbery. Precisely. And the mechanism of
- 12:30ransomware dwell time makes this even more deceptive.
- 12:33Hackers don't just break in and immediately start
- 12:36encrypting things. Right. They hide. Yeah. They
- 12:38often sit silently in a network for days, weeks
- 12:41or even months. They spend that time mapping
- 12:44the network, finding the most valuable data and
- 12:47quietly exfiltrating it using those legitimate
- 12:49tools we just talked about. And all of that happens
- 12:52without triggering a single alarm. Nothing. Total
- 12:55silence. So when does the security software actually
- 12:58wake up and declare an attack is happening? At
- 13:00the very end of the attack sequence. Once the
- 13:03hackers have successfully copied all the data
- 13:05they want, they trigger the actual ransomware,
- 13:08the malicious payload that scrambles the company's
- 13:10files and throws a ransom note on the computer
- 13:13screens. Oh, I see. This encryption process is
- 13:16highly anomalous behavior. The security software
- 13:18finally recognizes the malware, springs into
- 13:21action, and blocks the encryption from completing.
- 13:24So the system generates a cheerful automated
- 13:26report saying, hey, success, we detected and
- 13:30stopped a ransomware attack. Yes. And the company
- 13:33looks at the log, breathes a sigh of relief,
- 13:36and writes a confident PR statement. While completely
- 13:39missing the fact that the encryption was just
- 13:41the noisy distraction at the end of the heist?
- 13:43Exactly. It stopped the encryption, but the silent
- 13:46data theft, the exfiltration, had already occurred
- 13:49days beforehand. That is wild. Relying purely
- 13:52on automated initial alerts to draft a definitive
- 13:55public denial is incredibly dangerous. It leads
- 13:59directly to the contradiction we see in this
- 14:01case. It fundamentally changes how a company
- 14:03should weigh contested claims. I mean, let's
- 14:05say you are a business owner managing a crisis
- 14:07response team. The hackers say they have your
- 14:10data, but your IT dashboard is completely green.
- 14:13You cannot artificially generate 2 ,700 valid
- 14:16Australian tax file numbers tied to real names
- 14:19just to run a bluff. No, you can't. The physical
- 14:21evidence of a 213 .3 gigabyte compressed file
- 14:25filled with verified letterhead stamped documents
- 14:28heavily outweighs the internal log report. Oh,
- 14:31absolutely. When evaluating leak site claims,
- 14:34security professionals look for proof of life.
- 14:37Proof of life. They need a sample of data that
- 14:39proves the attacker actually breached the core
- 14:41systems and didn't just scrape public websites.
- 14:44In this scenario, the attackers didn't just provide
- 14:47a small sample. They dumped the entire payload.
- 14:50Yeah, 200 plus gigs. A file of that magnitude
- 14:53containing deeply specific financial histories
- 14:56is impossible to fake. So the sensible, mature
- 15:00response requires active verification. If you
- 15:03find yourself in the middle of a suspected breach,
- 15:06the absolute wrong move is to issue a blanket
- 15:08denial based solely on automated alerts. It's
- 15:11the worst thing you can do. You have to look
- 15:13outward. When the hackers post a claim or a sample
- 15:15on the dark web, your incident response team
- 15:18must actively cross -reference those specific
- 15:20dark web samples with your own internal databases.
- 15:23You have to check if the files the hackers are
- 15:24holding match the files in your cabinet. If the
- 15:27threat actor posts... posted document titled
- 15:29Trust Account Statement April PDF, your forensic
- 15:32team needs to immediately search your network
- 15:34for that exact file structure and hash. If it
- 15:38matches, you know your perimeter was breached,
- 15:41regardless of what the green lights on your dashboard
- 15:43say. Which brings up a huge point about communication
- 15:45strategy. 3P Corporation told their clients early
- 15:49on that an attack was attempted, but no data
- 15:51was compromised. Yeah, they did. Imagine being
- 15:54one of those 4 ,500 business clients. You read
- 15:57that email, you breathe a sigh of relief, and
- 15:59you tell your own employees that everything is
- 16:02fine. And then reality hits. A month later, you
- 16:05read in the news that your wet signature and
- 16:07your employees' TFNs have been downloaded almost
- 16:10200 times by unknown actors. The betrayal of
- 16:14trust there is enormous. It's catastrophic for
- 16:17a business relationship. Transparent, ongoing
- 16:19communication with clients is far safer and ultimately
- 16:24better for long -term reputation than a premature
- 16:27all -clear. Right. You can't just cross your
- 16:29fingers. No. It is completely acceptable to tell
- 16:31clients, look, we detected an intrusion. We successfully
- 16:35stopped the encryption process, but we are currently
- 16:37conducting a deep forensic analysis to determine
- 16:40if any data was copied before we intervened.
- 16:42That sounds so much more professional. We advise
- 16:45you to remain vigilant while we confirm the facts.
- 16:48Yeah, that approach sets realistic expectations.
- 16:51It treats the client like a partner in the security
- 16:53process rather than, you know, a liability to
- 16:57be managed and minimized. It shows you actually
- 16:59understand the complexity of the threat landscape.
- 17:01And when a PR denial gets... debunked by journalists
- 17:04reviewing the actual leaked data days or weeks
- 17:07later the company doesn't just look like a victim
- 17:10of a sophisticated cyber attack anymore no they
- 17:12look terrible they look either grossly incompetent
- 17:15or actively deceptive recovering from that specific
- 17:18kind of reputational damage um The loss of trust
- 17:22from your core clientele is far harder than recovering
- 17:24from the initial technical hack. Because you
- 17:26cannot spin your way out of a mathematical reality.
- 17:29Once a 213 gigabyte archive containing 2 ,700
- 17:32tax file numbers and thousands of physical signatures
- 17:35is downloaded 196 times on the clear web, that
- 17:39digital footprint is permanent. Oh, it's out
- 17:41there forever. It is distributed across the globe,
- 17:44sitting on hard drives from Moscow to Miami.
- 17:46Data absolutely cannot be unleaked. And the permanence.
- 17:50of that leak raises fundamental questions about
- 17:53our regulatory frameworks and our corporate crisis
- 17:55playbooks. Yeah, they feel outdated. Because
- 17:58many of these playbooks were written a decade
- 17:59ago, designed for an era where a breach meant
- 18:02a lost laptop, not a silent exfiltration of an
- 18:06entire corporate aggregate. It really leaves
- 18:08us with a massive lingering question to ponder
- 18:11as we wrap up today's exploration. If our current
- 18:14data notification laws allow a company to confidently
- 18:17rely on flawed internal logs to deny a breach,
- 18:21a breach that has already been downloaded 200
- 18:24times by unknown actors, how can you, the listener,
- 18:27ever truly know your identity is safe? It's a
- 18:30scary thought. If the bank manager doesn't even
- 18:32know the vault is empty because the camera monitors
- 18:34were paused, the alarms are entirely useless.
- 18:37The security apparatus we rely on might just
- 18:39be offering the illusion of control. Something
- 18:41every business needs to think about. Before we
- 18:43go, if this story has you looking sideways at
- 18:46your own system logs, wondering what your blind
- 18:48spots are, or realizing your business might be
- 18:51an aggregate target, You need to take action
- 18:53before an incident occurs. We strongly encourage
- 18:56you to visit www .kinsoft .com .au to discuss
- 19:01your security and IT needs, ensuring your systems
- 19:03and response plans are tested, verified, and
- 19:06actually ready for the realities of modern cyber
- 19:08threats. Definitely check them out. Thank you
- 19:10for tuning in to Tech Talks with Kinsoft. We
- 19:12will be back soon to help you navigate the next
- 19:14complex story. Until then, keep an eye on the
- 19:17vault and don't just trust the green lights.
- 19:18Stay safe out there.