Read The Times Australia

Daily Bulletin

Hackers are now targeting councils and governments, threatening to leak citizen data

  • Written by: Roberto Musotto, Research Fellow in Cyber Security and Law, Edith Cowan University

In recent weeks, Johannesburg’s computer network was held for ransom by a hacker group called Shadow Kill Hackers. This was the second time in three months a ransomware attack has hit South Africa’s largest city. This time, however, hackers didn’t pose the usual threat.

Rather than denying the city access to its data, the standard blackmail in a ransomware attack, they threatened to publish it online. This style of attack, known as leakware, allows hackers to target more victims in a single attack – in this case the city’s citizens.

Read more: What is ransomware and how to protect your precious files from it

The latest Johannesburg attack was the second leakware attack of this type ever recorded, and a similar attack could hit Australia soon. And although our current cyberattack defences are more advanced than many countries, we could be taken by surprise because of the unique way leakware operates.

A new plan of attack

During the Johannesburg attack, city employees received a computer message saying hackers had “compromised all passwords and sensitive data such as finance and personal population information”. In exchange for not uploading the stolen data online, destroying it and revealing how they executed the breach, the hackers demanded four bitcoins (worth about A$52,663) - “a small amount of money” for a vast city council, they said.

Hackers are now targeting councils and governments, threatening to leak citizen data The hacker group operated a Twitter account, on which they posted a photo showing the directories they had access to. ShadowKillGroup/twitter

In this case, access to data was not denied. But the threat of releasing data online can put enormous pressure on authorities to comply, or they risk releasing citizens’ sensitive information, and in doing so, betraying their trust.

The city of Johannesburg decided not to pay the ransom and to restore systems on its own. Yet we don’t know whether the data has been released online or not. The attack suggests cybercriminals will continue to experiment and innovate in a bid to defeat current prevention and defence measures against leakware attacks.

Hackers are now targeting councils and governments, threatening to leak citizen data This login screen message was displayed on computers in Johannesburg following the attack. pule_madumo/twitter

Another notable leakware attack happened a decade ago against the US state of Virginia. Hackers stole prescription drug information from the state and tried obtaining a ransom by threatening to either release it online, or sell it to the highest bidder.

When to trust the word of a cybercriminal?

Ransomware attack victims face two options: pay, or don’t pay. If they choose the latter, they need to try other methods to recover the data being kept from them.

If a ransom is paid, criminals will often decrypt the data as promised. They do this to encourage compliance in future victims. That said, paying a ransom doesn’t guarantee the release or decryption of data.

The type of attack experienced in Johannesburg poses a new incentive for criminals. Once the attackers have stolen the data, and have been paid the ransom, the data still has extractive value to them. This gives them duelling incentives about whether to publish the data or not, as publishing it would mean they could continue to extort value from the city by targeting citizens directly.

Read more: Ransomware attacks on cities are rising – authorities must stop paying out

In cases where victims decide not to pay, the solution so far has been to have strong, separate and updated data backups, or use one of the passkeys available online. Passkeys are decryption tools that help regain access to files once they’ve been held at ransom, by applying a repository of keys to unlock the most common types of ransomware.

But these solutions don’t address the negative outcomes of leakware attacks, because the “hostage” data is not meant to be released to the victim, but to the public. In this way, criminals manage to innovate their way out of being defeated by backups and decryption keys.

The traditional ransomware attack

Historically, ransomware attacks denied users access to their data, systems or services by locking them out of their computers, files or servers. This is done through obtaining passwords and login details and changing them fraudulently through the process of phishing.

It can also be done by encrypting the data and converting it to a format that makes it inaccessible to the original user. In such cases, criminals contact the victim and pressure them into paying a ransom in exchange for their data. The criminal’s success depends on both the value the data holds for the victim, and the victim’s inability to retrieve the data from elsewhere.

Some cybercriminal groups have even developed complex online “customer support” assistance channels, to help victims buy cryptocurrency or otherwise assist in the process of paying ransoms.

Trouble close to home

Facing the risk of losing sensitive information, companies and governments often pay ransoms. This is especially true in Australia. Last year, 81% of Australian companies that experienced a cyberattack were held at ransom, and 51% of these paid.

Generally, paying tends to increase the likelihood of future attacks, extending vulnerability to more targets. This is why ransomware is a rising global threat.

Read more: When it comes to ransomware, it's sometimes best to pay up

In the first quarter of 2019, ransomware attacks went up by 118%. They also became more targeted towards governments, and the healthcare and legal sectors. Attacks on these sectors are now more lucrative than ever.

The threat of leakware attacks is increasing. And as they become more advanced, Australian city councils and organisations should adapt their defences to brace for a new wave of sophisticated onslaught.

As history has taught us, it’s better to be safe than sorry.

Authors: Roberto Musotto, Research Fellow in Cyber Security and Law, Edith Cowan University

Read more http://theconversation.com/hackers-are-now-targeting-councils-and-governments-threatening-to-leak-citizen-data-126190

Business News

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...