Ventia took key systems offline after weekend cyberattack

Organization
Ventia
Exploit
Hacking
Industry
Infrastructure Services

Ventia, a Sydney-headquartered infrastructure services company, disclosed over the weekend of July 8 and 9, 2023 that it had been hit by a cyberattack and had taken some key systems offline to contain it.

The company holds long-term maintenance and operations contracts across defence, electricity and gas, water, environmental services, telecommunications, rail, health and corrections sites in Australia and New Zealand. It employs more than 35,000 people across roughly 400 locations and, according to The Record, reported revenue of more than 5 billion dollars in 2022.

In its statements Ventia said it had taken decisive action to contain the incident, including shutting down an undisclosed number of key systems, and that it had engaged external cyber security experts and was working with regulators and law enforcement. It added that it would not hesitate to take further protective action as operations returned to normal in the days ahead.

Ventia did not confirm whether ransomware was involved or whether any data had been stolen. SecurityWeek and The Record both noted that taking systems offline is a typical response to a ransomware infection, but no group publicly claimed the attack at the time and the company declined to characterise it. Ventia said it continued to operate in some capacity while incident response work went on.

Sources