ALPHV claimed theft of 385GB from Australian bond broker FIIG Securities
- Organization
- FIIG Securities
- Exploit
- Ransomware
- Industry
- Financial Services
FIIG Securities, an Australian fixed income specialist that advised on around five billion dollars for roughly 6,000 investors, was named on the leak site of the ALPHV ransomware group, also known as BlackCat, in June 2023.
The gang claimed it had taken about 385 gigabytes of data from the firm's main server. According to the listing, the material included employee curricula vitae, driver's licences, identity documents, tax file numbers, financial and accounting records, loan files and insurance documents, along with client identity documents, tax file numbers, payment card details and confidential agreements.
FIIG said it had engaged external cybersecurity specialists, isolated the affected systems and was contacting those involved. The firm notified current and former retail and institutional clients, current and former staff, shareholders and other stakeholders, by email where it held addresses and through website notices where it did not.
The company reported the incident to the Department of Home Affairs, the Australian Cyber Security Centre, the Australian Federal Police, the Australian Securities and Investments Commission, the Australian Prudential Regulation Authority, the Office of the Australian Information Commissioner and the Australian Taxation Office. FIIG said that as of July 19 the threat actor claimed it had commenced publishing FIIG data on the dark web.
Regulatory proceedings brought later by ASIC established that an intruder was inside FIIG systems undetected from May 19, 2023 until June 8, 2023, that the ACSC warned the firm on June 2, and that FIIG notified around 18,000 clients that their personal information may have been compromised. The March 2019 to June 8, 2023 window was the period over which the Federal Court found FIIG had failed to maintain adequate cyber security measures and risk management, not a period of intruder access.
Updates
-
The Federal Court ordered FIIG to pay a $2.5 million penalty and $500,000 towards ASIC's costs over the cyber security failures behind the intrusion. It was ASIC's second cyber security enforcement action, after its 2022 case against RI Advice.
Sources
- FIIG Securities, FIIG Securities Response to Cyber Incident
- The Cyber Express, Cyber Attack On FIIG: ALPHV/BlackCat Claims Responsibility
- Cyber Daily, FIIG Securities faces $2.5m fine following 2023 cyber attack
- ASIC, 25-035MR ASIC sues FIIG Securities for systemic and prolonged cybersecurity failures