DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Australian Shipbuilder Hacked, Refuses to Pay Ransom

Posted on November 2, 2018 by Dissent

I thought I posted something on this already, but apparently I didn’t, so if you hadn’t heard already, an Australian shipbuilder who also has contracts with the U.S. Navy was hacked and the hacker made extortion demands that the firm has refused.

Jeremy Kirk reports:

Australia’s largest defense exporter says it hasn’t responded to an extortion attempt after ship design schematics were stolen by a hacker.

Austal, which is based in Henderson, Western Australia, is one of the country’s largest shipbuilders; it has built vessels for the U.S. Navy.

The company, which is listed on Australia’s ASX stock exchange, announced the breach late Thursday. The announcement came just a day after a security researcher in France posted screenshots on Twitter of the purported stolen data.

Austal says the material is neither sensitive nor classified and that it has taken steps to secure its data systems.

Read more on GovInfoSecurity.

Here is some of what appeared on Twitter a few days ago:

someone is selling @austal cad files on black a hat board ? pic.twitter.com/ToVC9w7S4m

— Xylitol (@Xylit0l) October 31, 2018

i contacted him, he sent me 4 random samples, timestamp from 2017 to 2006 pic.twitter.com/euIeNn153v

— Xylitol (@Xylit0l) October 31, 2018

Is TheDarkOverlord Behind This?

Because of the nature of the crime – a hack and extortion attempt – some people have wondered whether this might be the work of TheDarkOverlord.  The question is understandable, particularly since I reported almost exactly one year ago had TDO had attacked  U.S. Navy defense contractors, including ATS, whose METBENCH software was used on warships. Now another firm that does defense work for the U.S. Navy was attacked? It’s understandable that people would wonder, except if you look at the listings posted on Twitter, those listings are not consistent with TDO’s sales listings, although the April, 2016 join date is intriguing. But selling such important material for 1 BTC?  Would TDO sell for so little? It’s unlikely, but it would be a good way to put pressure on Austal – offer the data so cheaply that lots of people might buy it.

When asked directly whether they were behind the attack and extortion, a TDO spokesperson declined to confirm or deny. But they were willing to make a statement about attacking defense contractors, telling DataBreaches.net in an e-mailed statement:

U.S. Defence contractors are easy pickings and they always house very juicy materials that competing nation-states are very interested in. At some times they can be a tough nut to crack, but given enough time, we always crack the nut. Naval contractors are among the most important contractors to breach as surface and sub-surface warfare vessels allow nation-states to extend their attack capabilities in a very mobile and speedy way.

Category: Breach IncidentsHackNon-U.S.

Post navigation

← NJ Settles Charges Against Business Associate Responsible for Virtua Medical Patient Data Breach: Vendor Owner Pays $200,000 and is Barred From Owning or Managing Any Business in NJ Again
Data leak affects thousands of wealthy Moscow residents →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack
  • Sweden under cyberattack: Prime minister sounds the alarm
  • Former CIA Analyst Sentenced to Over Three Years in Prison for Unlawfully Transmitting Top Secret National Defense Information
  • FIN6 cybercriminals pose as job seekers on LinkedIn to hack recruiters
  • Dutch police identify users on Cracked.io
  • Help, please: Seeking copies of the PowerSchool ransom email(s)
  • RCMP thumb drive with informant, witness data obtained by criminals: watchdog
  • Evoke Wellness to Pay $1.9 Million to Settle FTC Claims That They Misled Consumers Seeking Substance Use Disorder Treatment

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Rules Proposed Under New Jersey Data Privacy Act
  • Using facial recognition? Three recent articles of interest.
  • India publishes consent management rules under Digital Personal Data Protection Act
  • Republicans Move A Step Closer To Repealing Protections For Abortion Clinics
  • Democrats introduce bill that aims to protect reproductive health data
  • Don’t Mind If I Do: Montana Says Hands Off Neural Data
  • 23andMe leadership grilled by lawmakers demanding answers about data security amid bankruptcy sale

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.