IronSights
←All insights

threat intelligence

Passports, licences and a TFN declaration

Three Australian businesses were listed by three different ransomware groups in ten days. The proof files had one thing in common: they were staff documents, not customer ones. The week on the breach tracker.

Ryan BallootBy Ryan Balloot, Managing Director25 September 20263 min read
ByRyan Balloot25 September 20263 min read

Every listing comes with proof. A handful of files, chosen to show the victim that the attacker really has what it says it has. Look at what got chosen in the past ten days.

Leisure Coast Kitchens, a kitchen design and renovation business in Oak Flats near Shellharbour, was listed by the Kairos group on 16 September with a claim of 540 gigabytes. The proof: two employees' driver's licence scans, a completed tax file number declaration, staff bank account numbers and emergency contacts, a balance sheet and customer correspondence.

Thorndale Foundation, a disability support provider in Werrington that runs six group homes and day programs for more than 200 participants across the lower Blue Mountains, Nepean and Hawkesbury, was listed by Qilin on 15 September. The proof: passport scans, a signed confidentiality agreement, an invoice and a list of names. Thorndale says the matter has been reported to the and is under investigation.

And on 15 September Auto-IT confirmed that the Storm group's month of listings against car dealerships and machinery suppliers traced back to its own environment, a story we covered on Wednesday. The samples in that campaign included staff passport and licence scans too.

Why the HR folder goes first

Attackers choose proof files for impact. A passport scan proves the point faster than a spreadsheet. But the deeper reason staff documents keep appearing is that they are the easiest thing to find. Every business collects identity documents at onboarding. A TFN declaration on day one, a bank form for payroll, a driver's licence for the company car. They go into a folder called HR or Staff or Onboarding, on a shared drive that every domain account can read, and they stay there for the length of the employment plus however long nobody gets round to deleting them.

Customer data at least tends to live in a system with a login. Staff documents live in a folder.

Three different groups picked three different small businesses in ten days, and the first thing each of them showed the world was somebody's identity document. For the employee, that is a real problem. A licence, a TFN declaration and a bank account number together are most of what identity fraud needs, and the person it happens to did not choose the vendor or the backup policy.

What is worth doing about it

Find the folder. Every business has one, and most owners do not know what is in it. Check who can open it. If the answer is everyone, change it today. That is a permissions change, not a project.

Then reduce it. Identity documents collected for a right-to-work or police check often do not need to be kept as images once the check itself is recorded. Bank details belong in the payroll system, not in a scanned form beside it. The data you delete cannot be leaked, and staff identity documents are the clearest case of data that never needed to stay.

If you are one of the Thorndale participants, a Leisure Coast customer, or an employee of either: a listing is a claim, not a confirmation. Watch for messages that know something about you and ask for something in return. We wrote about that pattern yesterday.

Also this week

Qantas Hotels guests began receiving WhatsApp messages asking them to verify bookings and hand over card details. Qantas and Capella Sydney are investigating. No source has been identified.

Mathspace's individual notifications, covering 1,079,819 students, parents and school staff across Australia and New Zealand, have been landing in inboxes since 6 September. If your child's school uses the platform and you have not seen one, it may still be coming.

Macquarrie Corporation's publication deadline on Storm's leak site passed on 16 September. The company has said it is investigating and has not confirmed the claims.

The full list, including everything approved from earlier in the year, is on the Australian Data Breach Tracker. It is updated weekly, and a person reviews every entry before it goes live.

Keep reading

More from the IronSights team.