auDA finds no evidence of breach after NoEscape claimed to hold its data
- Organization
- auDA (.au Domain Administration)
- Exploit
- Ransomware
- Industry
- Internet Infrastructure
In August 2023 the ransomware group NoEscape claimed on its leak site that it had stolen roughly 15GB of data from auDA, the administrator of Australia's .au domain space. The gang said the haul included passports, powers of attorney, legal documents, medical reports and other personal records.
auDA said on August 18 that it had been alerted to the claim and was investigating, and that it had so far found no evidence of such a breach. The group then published a small sample, described as screenshots of a file listing from a computer, which auDA acknowledged as evidence that a criminal held data of some kind.
auDA's completed investigation concluded that its own systems and data were not involved. In its resolution statement the organisation said the files shown in the leaked screenshots were not stored on auDA systems, and that the actual victim was an Australian sole trader operating a domain name whose server had been encrypted on August 10, 2023. According to auDA, when that individual did not respond to the ransom demand, the attackers attributed the stolen material to auDA instead.
auDA said it alerted authorities and engaged specialist incident response support. Reporting on the incident noted involvement from the Australian Cyber Security Centre, the Department of Home Affairs and the Office of the Australian Information Commissioner. NoEscape criticised auDA's public statement and shortened its countdown timer in response.