Australia imposes cyber sanctions on Russian it says ransomwared health insurer
- Reference: 1705978868
- News link: https://www.theregister.co.uk/2024/01/23/australia_medibank_private_attacker_named/
- Source link:
The 2022 incident saw Medibank attacked by ransomware, and data on around ten million customers [1]leaked , some of it to the dark web. Stolen info included details of medical treatments undergone by around half a million Medibank Private customers. The names, dates of birth, addresses, phone numbers and email addresses of 9.7 million customers were also stolen.
The [2]REvil crime gang was named as the likely perpetrator of the attack, and Australian authorities [3]accused Russia of harboring the group.
[4]
On Tuesday the government went a step further, [5]naming Aleksandr Ermakov as linked to the incident, adding that Australia's Federal Police and sigint agency the Australian Signals Directorate "continue to pursue other leads."
[6]
[7]
Australia has slapped Ermakov with its significant cyber incidents sanctions – a [8]scheme launched in 2021 that allows travel bans and financial sanctions on folks felt to be involved in cyber incidents that aim to harm Australia or other nations.
Ermakov is not allowed to travel to Australia. Up to ten years' jail and big fines await anyone who deals with or provides him with assets, including through cryptocurrency wallets or ransomware payments.
[9]Google to lay Asia-Pacific to South America undersea cable
[10]X/Twitter booted out of Australia's disinformation-fighting club
[11]Australia declares 'nationally significant cyber incident' after port attack
[12]Data breach reveals distressing info: People who order pineapple on pizza
Australia's [13]list of sanctioned individuals gives the accused's full name as Aleksandr Gennadievich Ermakov and states that he's used the handles "aiiis_ermak," "blade_runner," "JimJones," and "GustaveDore."
The last is revealing: it's the name of a significant 19th-century French artist.
[14]
The name "Aleksandr Ermakov" is also shared: we found a Russian actor, footballer, and handball player with the same name.
Whoever Ermakov may be really, he's therefore likely unfazed by Australia using this handle. And of course Australian authorities have no way of having Moscow act against the alleged cyber villain.
Announcing the name of a suspect does, at least, offer some solace for Australians, who since late 2022 have endured several high-profile cyber incidents at major businesses.
[15]
Singapore-owned telco Optus has the worst record. After suffering a [16]data breach just before the Medibank incident, the carrier last year experienced a [17]nationwide outage so severe that its own execs acquired SIM cards for rival networks to ensure they could stay in touch. ®
Get our [18]Tech Resources
[1] https://www.theregister.com/2022/11/07/medibank_breach_n0_ransom_payment/
[2] https://www.theregister.com/2022/05/11/revil-returns-secureworks-samples/
[3] https://www.theregister.com/2022/11/11/russia_named_medibank_hack_source/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Za9H@Sk7BS90zuXJZOJrngAAAQE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://www.minister.defence.gov.au/media-releases/2024-01-23/cyber-sanction-response-medibank-private-cyber-attack
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Za9H@Sk7BS90zuXJZOJrngAAAQE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Za9H@Sk7BS90zuXJZOJrngAAAQE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.dfat.gov.au/international-relations/security/sanctions/sanctions-regimes/significant-cyber-incidents-sanctions-regime
[9] https://www.theregister.com/2024/01/12/first_asiapacific_to_south_america/
[10] https://www.theregister.com/2023/11/28/x_australia_trouble/
[11] https://www.theregister.com/2023/11/13/asia_tech_news_roundup/
[12] https://www.theregister.com/2023/09/21/pizza_hut_australia_data_breach/
[13] https://www.legislation.gov.au/F2024L00099/latest/text
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Za9H@Sk7BS90zuXJZOJrngAAAQE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Za9H@Sk7BS90zuXJZOJrngAAAQE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.theregister.com/2022/10/11/optus_acma_oaic_dual_probes/
[17] https://www.theregister.com/2023/11/21/optus_ceo_quits/
[18] https://whitepapers.theregister.com/
Re: Linked to ten-million-record leak
You know full well how this works - be perceived to be doing something by apportioning blame to someone who'll never be questioned (wouldn't want to risk spoiling the image, would we?), from whichever country is the flavour-du-jour of those hated by our puppet masters allies, the 'murikens.
Re: Linked to ten-million-record leak
'Cybercriminal' is the new 'terrorist' - and governments have been slapping sanctions on those without a trial for years.
Linked to ten-million-record leak
Whatever happened to being put on trial before a jury of ones peers. It also sets a dangerous precedent, linking a third party to any alleged cyber-perp.