Qilin leaks 37.6 GB of data from music publisher Hal Leonard Australia
- Organization
- Hal Leonard Australia
- Exploit
- Ransomware
- Industry
- Music Publishing
The Qilin ransomware group listed Hal Leonard Australia, the local arm of the United States print music publisher Hal Leonard Corporation, on its dark web leak site on January 8, 2024. The post gave the company about a week to make contact before the stolen files would be released.
When the deadline passed, Qilin published the material. Cyber Daily reported on January 15 that the gang had posted 37.6 gigabytes of internal company data. The files included financial documentation, a full list of Hal Leonard employees with business and private email addresses and the names of their reporting managers, and email correspondence covering credit arrangements with third-party customers, debt notices and banking summaries. Qilin's own posting claimed the haul also contained private contracts, agreements and project files.
Hal Leonard Australia did not comment publicly. Cyber Daily said it had approached the company without receiving a response, and The Cyber Express reported that no official statement had been issued and that the company's website continued to operate normally. The scope of the incident therefore rested on Qilin's claims and the files the group published.
Qilin operates as a ransomware-as-a-service scheme, recruiting affiliates through Russian-language forums and offering them a large share of ransom payments. Hal Leonard distributes printed music for artists and catalogues including The Beatles, Miles Davis, Stevie Wonder and Irving Berlin.