Australian Financial Services Company is Sued for Repeatedly Being Hacked… and Doing Zero About It

Stu Sjouwerman | Aug 27, 2020

australian ransomware hackThe Australian Securities and Investments Commission (ASIC) is suing RI Advice Group for being hacked multiple times over a year’s time that includes 155 hours of undetected hacker activity.

If you are the victim of ransomware once, it’s probably inevitable. But if you’re a ransomware victim again, and then hacked on a third occasion, you’re probably not paying attention to the need to properly secure your environment.

According to a notice filed earlier this month in Australian federal court, RI Advice Group was the victim of two remote access-turned-ransomware attacks in December 2016 and May 2017, and a third successful attack on a server containing sensitive financial information and client identification documents in December of 2017. The last one’s the kicker: in a port-mortem analysis, it was determined there were nearly 28K logon attempts – none, of which, were detected – and the hacker stayed logged in using compromised credentials for a total of 155 hours over a period of months leaving behind cryptomining software, a peer-to-peer sharing application, hacking tools, and brute-force password-cracking software. To add insult to injury, a trojan malware attack also occurred in May of 2018.

This company either isn’t paying attention or doesn’t care about their cybersecurity stance.

Because RI Advice Group is a financial services firm, they are subject to the ASIC, who are suing them for failing to establish and maintain compliance measures that include security controls.

I write a lot about the monetary impacts cyber attacks have on organizations, such as paying ransoms. But it’s important to note that there are additional repercussions – like being sued for non-compliance – that can put an organization out of business.

Pay attention – and when the first cybersecurity incident happens, take note, do an analysis of your security controls, and take steps to implement stronger measures that will ensure you’re less vulnerable in the future.

Topics: Ransomware

Ransomware Simulator

Free downloadable software tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the installer and run it
  • Results in a few minutes!

Get RanSim!

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.