Select Page

Incident: Russian ransomware gang AlphV breaches Core Desktop, a South Melbourne IT services company | ABC News (Australia)

Incident: Russian ransomware gang AlphV breaches Core Desktop, a South Melbourne IT services company | ABC News (Australia)

Australian IT Services Ransomware Attack, 05 September 2023

Russian ransomware gang AlphV breaches Core Desktop, a South Melbourne IT services company

TissuPath, Strata Plan and Barry Plant Blackburn were all clients of Core Desktop

Source: Russian ransomware gang AlphV breaches Core Desktop, a South Melbourne IT services company | ABC News (Australia)

View more incidents from Managed Services sector, and Victorian incident reports.

This attack is one of the Australian Service Provider “Core Desktop” that was reportedly breached by the Russian cybercriminal group AlphV, which is also known as BlackCat, view the AlphV Australian Ransomware Attacks.

Core Desktop is the third-party supplier involved in last week’s TissuPath hack, which saw diagnostic and patient records posted on the dark web leak site of notorious ransomware gang LockBit.

TissuPath, Strata Plan and Barry Plant Blackburn were all clients of Core Desktop, a company based in South Melbourne which was hired to provide IT services.

The ABC has obtained a letter that Core Desktop sent to its clients which revealed it became aware of the hack on 22 August 2023.

“Our cyber forensic team do not have a firm understanding of the origins of the entry but initial suggestions are that it was from a targeted client-side phishing attack which infiltrated our control systems, impersonated privileged accounts and encrypted some servers,” the letter said.

“They appear to have acted in a focused fashion and threatened a small number of Core Desktop clients.”

Core Desktop’s managing director, Rod Bloom, confirmed his company was the victim of a cyber-attack.

“We’ve communicated with all of our clients about the attack,” he said.

“We’re not really aware of what information has been compromised … it’s not our data so we don’t know.”

Mr Bloom said the company had reported the data breach to the Office of the Australian Information Commissioner and the Australian Cyber Security Centre.

Core Desktop has since regained control of its systems after shutting down access to all affected accounts, resetting login details for administrators, resetting client passwords and hiring forensic cybersecurity specialists.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

ATO employee charged over alleged disclosure of information to organised crime groups

A Gold Coast man who worked with the Australian Taxation Office (ATO) has been charged over the alleged disclosure of information to organised crime … [...]

Cyber Wardens program to shut down as government funding ends

COSBOA CEO says lessons learned from the program “will help shape what comes next” as she celebrates assisting 23,150 small businesses. • Fri, 11 Sep … [...]

Nick Scali security breach: What it means for customer information

Furniture giant Nick Scali has confirmed New Zealand customers’ personal details were held on systems affected by a security breach last month. In an … [...]

Data breach exposes millions of students, teachers and parents | 9 News Australia

Millions of people, including school students, have had their data exposed in a data breach on an education website. | Subscribe and 🔔: http://9Soci.al/KM6e50GjSK9 | Get more breaking news at [...]

AI transforms cyber crime threat in Australia | 7NEWS

There's a new warning tonight: artificial intelligence is about to make cyber criminals far more dangerous. One of Australia's most respected cyber security figures has told 7NEWS, AI has transformed [...]

Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation

A ransomware group claims to have hacked a Broadmeadow-based office technology supplier that works with Newcastle Airport and Royal Life Saving … [...]

Australian Cyber Aware - As It Was 2608 - August 2026

This monthly review provides a curated summary of cybersecurity, privacy, AI, fraud, governance, risk, and compliance developments in Australia and … [...]

Australians to gain greater control over compromised identity documents with new IDLock scheme

The Albanese government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]

Digital platforms to be targeted as part of NSW crackdown on organised crime operations

NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • … [...]

Late patching of Metabase SQLi bug claims Sydney's Mathspace

Key points Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance … [...]

ACMA fines Telstra for SIM swapping prevention misses

Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud … [...]

Vocus hit by Australia Singapore Cable break

Key points Vocus is grappling with a cable break on its Australia Singapore Cable (ASC) system between Perth and Singapore, following a shunt fault on … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading