Year2018 |
MonthOctober |
Reference number20181001 |
Impact areaShore |
Incident locationPerth |
Incident countryAustralia |
Victim countryAustralia |
Victim identityAustal |
Victim TypeShip Building Company |
MethodHacking, Ransomware |
In October 2018, Austal shipbuilder in Australia got hit by a hacking/ransomware attack. Hackers located in the Middle East used login credentials purchased on a dark web forum to get into the system. The criminals walked around the ‘virtual rooms’ in the company's systems, and collected things as they went. The attackers also triggered an alarm as they stockpiled data for exfiltration. They also made an attempt to extortion by demanding ransom. The attack led to data theft, including some staff email addresses, mobile phone numbers and ship drawings. The attackers threatened to offer certain materials for sale on the internet and tried to extort the company. IT had to shut down all external ports to contain the attack. It appeared the stolen credentials were also relatively weak, being either ‘Password123’ or ‘Austal123’. The stolen ship drawings were designs for customers and sub-contractors, but the company insists neither commercially-sensitive nor details that affect national security were compromised. Austal has confirmed "some staff email addresses and mobile phone numbers" were accessed in the hack. The company was keen to point out the breach had no impact on its ongoing operations. The government will continue to actively deter and respond to malicious cyber activity.