Recently, ABC News featured an interview with a hacker who claimed responsibility for a cyber-attack that is still fresh in our memories: the hack on Medibank. The hacker, who confirmed to have worked for the highly successful cyber gang "REvil," revealed some intriguing insights into the mindset of cyber criminals and the strategies they use to target businesses.
The interview shows the recklessness and lack of empathy from hackers and serves as a reminder to all business owners that the potential exposure, reputational damage, business interruption and financial costs following a cyber incident are too great to ignore.
REvil - short for “Ransomware Evil” were highly prolific in 2020 and 2021, carrying out multiple high-profile attacks, earning themselves over USD200M. Those who have monitored the group for years, say they have made the “double extortion” method famous and loved to create a media frenzy. Double extortion is the act of stealing sensitive data and then encrypting an organisation’s files using a gang’s ransomware application. The gang then carries out the ransom negotiation and if a victim agrees to pay, both the hacker and the gang take a cut.
The interview reveals that hackers often use a combination of sophisticated social engineering and technical skills to gain access to a company's systems. This can include tactics such as phishing emails or exploiting vulnerabilities in software. Once inside, the hackers can see which servers contain the most important information or the way the backups are arranged. From here, they can decide whether they can make more money by stealing and reselling confidential information or by encrypting everything with ransomware.
In the case of the Medibank attack, REvil demanded a ransom payment of $270 million in exchange for not releasing sensitive data that had been stolen from the company's servers. It’s a typical example of the ‘double extortion’ method that has helped this group make recent headlines. Unfortunately for the hackers, Medibank did not pay the ransom. Whether companies should pay ransom demands is another topic and one for public debate as the government is considering making cyber ransom payments unlawful.
Cyber defence must be a priority for all Australian businesses. To find out how Honan can help you manage these risks and learn more about cyber insurance, reach out directly to discuss your business’s unique needs.
Nathan Mauriello
Senior Client Executive – Professional & Executive Risks