Original Article Text

Click to Toggle View

Victoria court recordings exposed in reported ransomware attack. Australia's Court Services Victoria (CSV) is warning that video recordings of court hearings were exposed after suffering a reported Qilin ransomware attack. CSV is an independent statutory authority that provides services to Victoria's court systems, including case management systems and administrative solutions. In a statement published today on its website, CSV says it detected a cyberattack on December 21, 2023, that allowed hackers to disrupt operations and access its audio-visual archive containing sensitive hearing recordings. The impacted system was immediately isolated and disabled, but the ensuing investigation revealed that the breach occurred at an earlier date, December 8th, 2023, with the exposed recordings going as far back as November 1, 2023. "The cyber incident led to unauthorised access leading to the disruption of the audio visual in-court technology network, impacting video recordings, audio recordings and transcription services," reads the CSV statement. "Recordings of some hearings in courts between 1 November and 21 December 2023 may have been accessed. It is possible some hearings before 1 November are also affected." Specifically, the following courts and jurisdictions have been impacted by the security incident: The above recordings contain a mix of public and confidential information, so depending on the case, they may expose sensitive information regarding court cases. Where possible, impacted courts will send out breach notices to those deemed impacted by the incident. CSV has also notified the authorities about the potential data breach, including the Victoria Police, Victorian Department of Government Services, and Australia's National Identity and Cyber Support Community Service (IDCARE). Though CSV is still in the process of restructuring the impacted system with more focus on security, court operations in Victoria will not be affected, and all cases scheduled for January 2024 are expected to proceed normally. The authority's does not name the cybercriminals responsible for the attack, but sources speaking to ABC News report that the Qilin ransomware gang carried out the attack. The Qilin ransomware operation was launched under the name "Agenda" in August 2022 but was later rebranded as Qilin. Since its launch, the ransomware operation has had a steady stream of victims but has seen increased activity towards the end of 2023. BleepingComputer has not been able to independently confirm if Qilin is behind the attack, and there is no mention of CSV on their data leak site.

Daily Brief Summary

DATA BREACH // Court Services Victoria Falls Victim to Ransomware Data Breach

Court Services Victoria (CSV) detected and announced a cyberattack on December 21, 2023, that compromised video recordings of court hearings.

Attackers gained access to CSV's audio-visual archive, potentially exposing sensitive information from hearings conducted between November 1 and December 21, 2023.

The breach was later discovered to have occurred on December 8, 2023, raising concerns over the extent and duration of the exposure.

CSV has isolated the affected system and notified relevant authorities, including Victoria Police and Australia's IDCARE.

Individuals potentially impacted by the breach will receive notifications from the affected courts.

Despite the cybersecurity incident, CSV ensures that court operations will continue as scheduled, with additional security measures being implemented.

The Qilin ransomware group, previously known as "Agenda", is allegedly responsible for the attack on CSV according to sources, but this has not been officially confirmed.

CSV has not disclosed whether a ransom demand was made or if any data was stolen and published by the threat actors.