Australia's disability agency assessed exposure from the HWL Ebsworth hack
- Organization
- National Disability Insurance Agency
- Exploit
- Third-Party Data Breach
- Industry
- Government Agency
Australia's National Disability Insurance Agency spent mid-2023 working out how much of its data had been caught in a ransomware attack on the law firm HWL Ebsworth, which handled legal matters for the agency including appeals brought by scheme participants over their NDIS plans.
HWL Ebsworth became aware on April 28, 2023 that the ALPHV group, also known as BlackCat, had posted on a dark web forum claiming to have taken data from the firm. The firm notified the Office of the Australian Information Commissioner on May 8. After HWL Ebsworth declined to pay, ALPHV published material over roughly three weeks in June, and the firm obtained an injunction from the Supreme Court of New South Wales restraining further publication or dissemination.
The firm told the NDIA on June 10 that participant data was in the published set, and gave the agency a copy of that data on June 13. The NDIA said its own systems had not been compromised, but confirmed that some NDIS participants, prospective participants, their families and carers, and staff had been affected.
HWL Ebsworth held contracts with at least 40 federal and state government bodies, among them the Office of the Australian Information Commissioner and Defence. The NDIA opened a dedicated support line and began notifying identified individuals in late July 2023.