Firstmac confirms breach after EMBARGO ransomware attack
- Organization
- Firstmac Limited
- Exploit
- Ransomware
- Industry
- Financial Services
Firstmac, one of Australia's largest non-bank lenders, told customers on 30 April 2024 that it had suffered a cyber incident in which an unauthorized third party accessed part of its IT system. The Brisbane based mortgage and investment firm said it moved to secure its systems as soon as the intrusion was detected and brought in external forensic investigators.
The same day, a newly formed extortion crew calling itself EMBARGO listed Firstmac on its darknet leak site and claimed to hold more than 500 gigabytes of company data, including full databases, source code and sensitive customer records. Cyber Daily, which broke the story, reported that Firstmac was only the group's second named victim after a US construction company in April, and that the gang had set a ransom deadline of 8 May.
When the deadline passed, the group published the material. Security Affairs and Bitdefender reported that the leaked customer data included names, dates of birth, residential and email addresses, phone numbers, driver's license numbers, and external bank account details limited to BSB and account numbers. Documents, source code and data backups were also taken.
Firstmac told affected customers there was no evidence their accounts had been touched and that their funds were secure. The lender said it had notified the relevant authorities, offered access to the identity support service IDCARE, and pointed to additional controls including biometric and two-factor authentication for account changes.