Latest / Tech Talks With Kinsoft / Scotch College Data breach August 25
Transcript
- 0:00Hello and welcome back to Tech Talks with Kinsoft.
- 0:01I'm your host. Today we have a heavy one. We
- 0:05aren't just looking at the latest gadgets or,
- 0:07you know, software updates. We are looking at
- 0:08a stack of documents that paints a pretty worrying
- 0:11picture of the education sector in Australia.
- 0:13We've got news reports, a dense 160 -page compliance
- 0:17manual, and forensic timelines of a major cyber
- 0:21event. It is good to be here, and you are right
- 0:23to call it heavy. We are diving into the intersection
- 0:26of elite education, cyber vulnerability, and
- 0:29the very strict rules that are supposed to be
- 0:31keeping our data safe. So let's set the scene.
- 0:33It is August 2025. We are talking about Scotch
- 0:37College in Melbourne. This isn't just any school.
- 0:40This is one of the most elite private schools
- 0:42in the country, charging over $34 ,000 a year
- 0:45for tuition with a history spanning 174 years.
- 0:48And then over a single weekend. The lights go
- 0:51out. It was a significant breach. And our mission
- 0:54today is to analyze this event, not just as a
- 0:56piece of news, but to understand why the education
- 0:58sector is suddenly under such heavy fire. We
- 1:01need to contrast the chaotic reality of a hack
- 1:03like this against the rigid privacy frameworks
- 1:05these schools operate under. It really is a crazy
- 1:08story. How does an institution with that kind
- 1:11of prestige, that kind of resource base, get
- 1:13taken offline by an unknown third party? And
- 1:16more importantly, what happens to the data of
- 1:18alumni who include former premiers and high court
- 1:22judges? That is the multi -million dollar question.
- 1:25When you look at the source materials, specifically
- 1:27the reporting from Peter A. Clark and the Cyber
- 1:29News Center, the details of the Scotch College
- 1:32incident reveal a lot about the current threat
- 1:35landscape. Let's get into the timeline then.
- 1:37It was August 15th, 2025. The principal... Dr.
- 1:41Scott Marsh sends out a letter confirming that
- 1:44over the weekend, an unauthorized third party
- 1:46accessed their IT systems. Now, usually you hear
- 1:50about these things weeks later, but this seemed
- 1:51immediate. The response described in the sources
- 1:54was incredibly drastic. I call it the nuclear
- 1:56option. The nuclear option, you mean because
- 1:58of how they reacted? Essentially, yes. Dr. Marsh
- 2:00stated that they shut down all servers and disabled
- 2:03all accounts. Everything. They even postponed
- 2:06non -essential online events. But isn't that...
- 2:09Isn't that overkill? I mean, shutting down the
- 2:12entire school's digital infrastructure email,
- 2:15learning platforms, admin records for a breach
- 2:18that paralyzes the institution. It does. And
- 2:22it is a controversial move. But think about it
- 2:24from a containment perspective. In a ransomware
- 2:26scenario or an active intrusion, the fog of war
- 2:29is real. If you don't know exactly which account
- 2:32is compromised or which server is patient zero,
- 2:35you have to assume they all are until proven
- 2:37otherwise. Sometimes the only way to stop the
- 2:40bleeding is to stop the heart. That is a terrifying
- 2:43thought. And they immediately engaged the Australian
- 2:45Cybersecurity Center and forensic experts, which
- 2:48is standard procedure. But the disruption must
- 2:50have been massive. And the stakes here are incredibly
- 2:53high. We aren't just talking about grade eight
- 2:55math homework or, you know, the cafeteria menu.
- 2:58The sources point out that the breach exposed
- 2:59records of old Scotch collegians and families.
- 3:02Right. I saw the list of alumni mentioned. We're
- 3:04talking about people like Jeff Kennett, the former
- 3:06Victorian premier. Andrew Holmes, former president
- 3:09of the Australian Academy of Science. Kenneth
- 3:11Hain, a former high court judge. Exactly. This
- 3:13isn't just student data. It's a trove of information
- 3:16on some of Australia's most influential families.
- 3:19If you are a threat actor, that is leverage.
- 3:22That is high value data. So why are schools such
- 3:25targets? Peter A. Clark had an interest. interesting
- 3:27take on this in his article. He mentioned that
- 3:29schools often have hallowed halls, but basic
- 3:33IT maintenance. It is a systemic contradiction.
- 3:37Clark points out that schools are entrepots.
- 3:39They have numerous entry points. You have hundreds
- 3:41of new students joining every year, others leaving,
- 3:44parents needing access, contractors coming in.
- 3:46The authorizations are constantly changing. It
- 3:49sounds like a logistical nightmare to secure.
- 3:51It is. And unlike a bank, which is a fortress
- 3:53by design, a school is designed for sharing and
- 3:56openness. Plus, they are often running legacy
- 3:59systems, old servers, outdated software with
- 4:02inbuilt weaknesses that modern hackers can exploit
- 4:04in minutes. It's the classic. link problem. You
- 4:07can have great gates at the front of the school,
- 4:09but if the digital back door is held open by
- 4:11an old server, you're in trouble. And looking
- 4:14at the sources, Scotch College wasn't an isolated
- 4:16case, was it? Not at all. If we zoom out and
- 4:19look at the trend analysis provided by Weber
- 4:21Insurance Services, the picture gets much darker.
- 4:25The education sector is being hammered. I was
- 4:28looking at that list and it is startling. August
- 4:302025 was a bad month, generally. INET and Tassie
- 4:34Aged Care got hit, too. But the education pattern
- 4:36is undeniable. Just look at the precedent. December
- 4:392024, Waverly Christian College gets hit by the
- 4:42Fogg Ransomware Group. They stole 5GB of data.
- 4:46And then in April 2025, Western Sydney University
- 4:50has 10 ,000 students impacted. Now, that wouldn't
- 4:54surprise me. You'd think a university with all
- 4:56its research grants and tech departments would
- 4:58be harder to crack than a high school. You would
- 5:00think so, but it goes back to that entrepot concept.
- 5:03Universities have even more transient populations
- 5:05and often even older legacy systems buried in
- 5:08research departments. It forces the question,
- 5:10if these breaches are happening left and right,
- 5:12are these schools just being careless or is the
- 5:14bar set too high? Well, surely there are rules
- 5:16they have to follow. They can't just operate
- 5:18on a handshake agreement regarding our data.
- 5:20That is where it gets fascinating. We have access
- 5:23to the Privacy Compliance Manual produced by
- 5:25Independent Schools Australia and the Catholic
- 5:28Education Commission. This is the rulebook. I
- 5:30have to say, reading this manual was a bit of
- 5:33an eye -opener. You assume there are rules, but
- 5:35seeing them written down, they are incredibly
- 5:38strict. They are. The manual is built around
- 5:41the Australian Privacy Principles, or APPs, specifically
- 5:44APP11, which covers data security. Right. And
- 5:48the core phrase there is reasonable steps. Schools
- 5:52must take reasonable steps to protect information
- 5:54from misuse, interference, and loss. But reasonable
- 5:58feels vague. What does the manual actually require
- 6:01when it comes to, say, getting rid of data? The
- 6:04destruction standards are surprisingly specific.
- 6:06It's not enough to just scrunch up a piece of
- 6:08paper and throw it in the bin. The manual literally
- 6:10specifies shredding, pulping, or disintegration.
- 6:14Disintegration? Yeah. That sounds like something
- 6:15out of a spy movie. I need this report disintegrated
- 6:17immediately. It does sound intense, but it highlights
- 6:20the standard. If a document can be pieced back
- 6:23together, it hasn't been destroyed. And for electronic
- 6:26data, it says it must be put beyond use. What
- 6:29does beyond use actually mean in IT terms? It
- 6:32is a critical definition. Beyond use means the
- 6:36school cannot access it. They cannot give anyone
- 6:38else access. And crucially, they must have audit
- 6:41trails proving it was destroyed. You can't just
- 6:44hit delete and hope for the best. If you can
- 6:46recover it from a recycle bin or a backup tape,
- 6:48it's not. beyond use. This is like a high bar
- 6:51for a school IT admin who might also be teaching
- 6:54a math class. And then there's the cloud. This
- 6:57is where I got a bit confused and I'm hoping
- 6:59you can clarify. The manual has a whole section
- 7:01part D discussing Google Apps for Education and
- 7:04Office 356. Yes, this is a very nuanced area,
- 7:07but it's vital for understanding liability. The
- 7:10manual debates whether using a service like Google
- 7:13Drive, where servers might be overseas, constitutes
- 7:15a disclosure of data or just a use of data. Why
- 7:18does that distinction matter? Is it just semantics?
- 7:20It is a massive legal distinction. Think about
- 7:23it. If you disclose data to a server in California,
- 7:27you are technically handing over control to a
- 7:30foreign entity. That triggers APP aid, meaning
- 7:33the school is responsible if that U .S. company
- 7:36breaches Australian privacy laws. It's a liability
- 7:39nightmare. Right. So if Google messes up, the
- 7:41school's on the hook. Exactly. But the manual
- 7:43offers an escape hatch. If the contract explicitly
- 7:46says the vendor can only store the data, no mining
- 7:49for ads, no AI training, no accessing it for
- 7:52their own purposes, then it's treated as use,
- 7:55not disclosure. It keeps the data technically
- 7:58within the school's control, even if the hard
- 8:00drive is physically in San Francisco. So it's
- 8:02all about the contract language. Precisely. But
- 8:04the takeaway for parents and listeners is that
- 8:06schools are warned to check where those servers
- 8:08are. Often they are overseas. And the manual
- 8:11explicitly says schools should update their privacy
- 8:13policies to warn parents that their child's essay
- 8:15or their medical record might be sitting on a
- 8:18server in Singapore or the U .S. That is wild.
- 8:21You just assume your kid's work stays in the
- 8:23classroom, or at least in the country. So we
- 8:25have the breach and we have these complex rules.
- 8:28But what happens when the worst case scenario
- 8:30actually hits? The manual has a data breach response
- 8:34plan template. It does. And looking at the Scotch
- 8:37College response, they seemingly followed the
- 8:39textbook approach. The manual outlines mandatory
- 8:42steps. Step one, contain. That's the pull the
- 8:45plug move we saw. Exactly. Step two is assess.
- 8:47The team has to determine if the breach is what's
- 8:50called an eligible data breach or EDB. And this
- 8:53leads to the serious harm test. This part really
- 8:56stood out to me because it defines harm much
- 8:59more broadly than I expected. It is the most
- 9:02human part of the compliance manual. The school
- 9:04has to evaluate if the breach could cause physical,
- 9:07psychological, emotional, financial or reputational
- 9:10harm. Emotional and psychological harm. I think
- 9:13we often forget that. We worry about credit cards.
- 9:15But for a student having behavioral records,
- 9:18counseling notes or family court orders leaked,
- 9:20it's devastating. Absolutely. The manual actually
- 9:23lists risk factors in annexure three, it asks.
- 9:26Who is affected? Is it students? Is it contractors?
- 9:29And crucially. Is the info intelligible? Right.
- 9:32Is it encrypted or is it just plain text? There
- 9:35was an interesting detail in the manual about
- 9:37considering if the data is protected by a security
- 9:40measure. And this is key, how likely it is that
- 9:43the hackers can circumvent it. Which brings us
- 9:45to the reality check. Because you can have this
- 9:47pristine 160 -page manual demanding military
- 9:50-grade encryption and disintegration of documents.
- 9:53But then you walk into the server room or the
- 9:55staff room, and the reality is very different.
- 9:58There's a huge gap between the policy and the
- 10:00practice. And actually, we saw this play out
- 10:02in real time on a Reddit thread discussing these
- 10:04Victorian breaches. The users there, mostly IT
- 10:08admins and students, weren't quoting compliance
- 10:11manuals. They were talking about the messy reality
- 10:13of school IT. The community reaction is always
- 10:16a good barometer. You had users like CubeZera
- 10:18commenting on consultancy bonuses. Yeah, that
- 10:20comment stung. Basically saying organizations
- 10:23won't admit fault because they don't want the
- 10:25vendor to sue them. So instead, they hire consultants,
- 10:28everyone pats themselves on the back, and the
- 10:30hackers walk away with the data. There is a pervasive
- 10:32feeling that big companies and the government
- 10:34simply aren't doing enough. One user noted they
- 10:38use these breaches as a lesson to their kids
- 10:40that none of their info is safe online. It's
- 10:44a sad lesson to have to teach. But there was
- 10:46a specific technical debate in that thread that
- 10:49I want to drill into. It was about passwords.
- 10:51Users Sep Underpants and Appealing Genitals,
- 10:55classic Reddit usernames, were arguing about
- 10:59hashing and salting. Yes, the usernames are colorful,
- 11:02but the advice is actually very sound. This is
- 11:05a concept everyone should understand because
- 11:07it explains why some breaches are catastrophic
- 11:08and others aren't. So break it down for us. Most
- 11:10people have heard of hashing. That's scrambling
- 11:12the password, right? Correct. Imagine you have
- 11:15a password, say bluey123. You don't want to store
- 11:19that as plain text in your database. So you run
- 11:22it through a mathematical algorithm, a hash function.
- 11:24It turns blue123 into a long, scrambled string
- 11:27of characters, like that SHA3 example in the
- 11:29source, 32459, and so on. Okay, so it's scrambled.
- 11:34That sounds secure. If a hacker steals the database,
- 11:37they just see gobbledygook. It used to be secure.
- 11:39But computers are fast now. Hackers have what
- 11:42are called rainbow tables. These are massive
- 11:45pre -computed lists of millions of common passwords
- 11:47and their corresponding hash strings. So if they
- 11:50see that specific scrambled string in the stolen
- 11:52database, they can just look it up on their table
- 11:54and see that it equals bluey123. Exactly. It's
- 11:57like a reverse phone book. If you just use simple
- 11:59hashing, your password is cracked in milliseconds.
- 12:01And that is where salting comes in. The Reddit
- 12:03users were adamant about this. Yes. Salting is
- 12:06the antidote to rainbow tables. Salting means
- 12:09adding a random string of unique data, the salt,
- 12:12to the password before you scramble it. So for
- 12:14student A, you might add x7z to bluey123 and
- 12:18scramble that combined string. For student B,
- 12:20you add 9qp to bluey123 and scramble that. So
- 12:24even though they have the same password, the
- 12:26result in the database looks completely different.
- 12:28Precisely. And because every user has a unique
- 12:31salt, The hacker's rainbow tables are useless.
- 12:34They would have to recalculate the hash for every
- 12:36single user individually. It turns a job that
- 12:39takes seconds into a job that could take centuries.
- 12:42It seems like such a basic step. Why isn't everyone
- 12:44doing it? Complexity, legacy systems, laziness,
- 12:47it varies. But the impact is real. There was
- 12:50that anecdote from the IT manager on Reddit who
- 12:52ran a have I been proud session for staff. Dow
- 12:55was telling. They asked staff to check their
- 12:58emails against the database of known breaches.
- 13:00Only three staff members out of the whole group
- 13:02hadn't suffered a breach. Only three. It really
- 13:05highlights how prevalent reused passwords are.
- 13:08If one site gets breached, say a shopping site
- 13:11you used five years ago, and you haven't salted
- 13:13your passwords or you reuse that password at
- 13:16school, the school is vulnerable. It connects
- 13:19everything back together. The hallowed halls,
- 13:21Clark mentioned, are being protected by people
- 13:23who are likely reusing passwords that were compromised
- 13:26in a completely different hack years ago. It
- 13:29creates a massive surface area for attack. So
- 13:32let's bring this all together. We've seen the
- 13:33Scotch College headline, which is scary. We've
- 13:36seen that it's part of a massive trend attacking
- 13:38the education sector. We've looked at the strict
- 13:41rules, shredding, pulping, serious harm tests
- 13:44that schools should be following. And we've learned
- 13:47that technical basics like salting passwords.
- 13:50really matter. I think the biggest takeaway is
- 13:52the disconnect. We have incredibly sophisticated
- 13:54compliance manuals. The privacy compliance manual
- 13:57is thorough. It covers everything from cloud
- 13:59servers to emotional harm. But the reality on
- 14:02the ground, as seen in the Reddit comments and
- 14:04the sheer volume of breaches, is that implementation
- 14:06is lagging. It feels like a race, doesn't it?
- 14:09The hackers are sprinting and the schools are
- 14:11trying to run with a 160 -page manual strapped
- 14:14to their backs. That's a good analogy. And we
- 14:17have to remember, schools hold the most sensitive
- 14:20data of our lives. We aren't just talking about
- 14:22credit cards. We are talking about medical records,
- 14:25behavioral reports, family court orders, learning
- 14:28disabilities. That brings us back to the serious
- 14:31harm test we discussed. It does. Compliance isn't
- 14:34just paperwork or ticking a box to avoid a fine.
- 14:37It isn't just about avoiding a headline. It's
- 14:40about protecting vulnerable people children from
- 14:43real world harm. When a school's data is breached,
- 14:46it's a breach of trust that can last a lifetime.
- 14:49That is a heavy thought, but an important one.
- 14:51We need to move beyond just reading the headlines
- 14:53and start asking the hard questions about how
- 14:55that data is actually being guarded. Absolutely.
- 14:58It really highlights that data security isn't
- 15:01a set -and -forget document. It's an active,
- 15:03daily, defensive posture. And that is a hard
- 15:07standard to maintain alone. Whether you're running
- 15:09a school with thousands of students or a business
- 15:11with sensitive IP, the gap between your manual
- 15:14and your server room is where the risk lives.
- 15:16If you need help closing that gap, or you just
- 15:19want a security audit that goes deeper than a
- 15:21checklist, go to www .kinsoft .com .au. They
- 15:25can help you bridge that gap between the manual
- 15:27and reality. Exactly. Check them out at www .kinsoft
- 15:31.com .au to discuss your security and IT needs.
- 15:35Thanks for listening to Tech Talks with Kinsoft.
- 15:37Stay safe out there, and we'll catch you next
- 15:39time.