Court Services Victoria breach exposed years of court hearing recordings

Organization
Court Services Victoria
Exploit
Ransomware
Industry
Government

Court Services Victoria (CSV), the agency that administers the courts of the Australian state of Victoria, identified a cyber incident on December 21, 2023 affecting the network that manages audio and video recordings of hearings. The agency isolated and disabled that network and made the incident public in early January 2024.

CSV initially said the recordings potentially accessed covered hearings held between November 1 and December 21, 2023. Further forensic work in early January widened that considerably. The agency later said affected recordings included Supreme Court hearings dating back to April 2016, County Court hearings from April 2016 and May 2019, Coroners Court hearings from August 2019, and Magistrates' Court recordings from November and December 2023. The Children's Court was affected to a limited extent and the Victorian Civil and Administrative Tribunal was not affected.

Access was confined to the audio-visual recording network. CSV said other court records, along with employee and financial data, were not involved. The agency worked with Victoria Police and other justice bodies, set up a dedicated contact address, offered identity support through IDCARE and rebuilt the network with additional security controls. Video conferencing was restored by January 16, 2024.

Cyber Daily reported that cyber security expert Robert Potter told ABC News that evidence showed the attack used Qilin commercial ransomware, a Russia based operation that Potter said works by double extortion. CSV did not name Qilin as responsible, and BleepingComputer found no mention of CSV on the Qilin leak site. CSV said it was not aware of any of the recordings being published.

Sources