Vane3alga

Business
Focused
Technology

The Australian Securities and Investments Commission (ASIC) is suing RI Advice Group for being hacked multiple times over a year’s time that includes 155 hours of undetected hacker activity.

Internet Hacking Security

If you are the victim of ransomware once, it’s probably inevitable. But if you’re a ransomware victim again, and then hacked on a third occasion, you’re probably not paying attention to the need to properly secure your environment.

According to a notice filed earlier this month in Australian federal court, RI Advice Group was the victim of two remote access-turned-ransomware attacks in December 2016 and May 2017, and a third successful attack on a server containing sensitive financial information and client identification documents in December of 2017. The last one’s the kicker: in a port-mortem analysis, it was determined there were nearly 28K logon attempts – none, of which, were detected – and the hacker stayed logged in using compromised credentials for a total of 155 hours over a period of months leaving behind cryptomining software, a peer-to-peer sharing application, hacking tools, and brute-force password-cracking software. To add insult to injury, a trojan malware attack also occurred in May of 2018.

This company either isn’t paying attention or doesn’t care about their cybersecurity stance.

Because RI Advice Group is a financial services firm, they are subject to the ASIC, who are suing them for failing to establish and maintain compliance measures that include security controls.

I write a lot about the monetary impacts cyber attacks have on organizations, such as paying ransoms. But it’s important to note that there are additional repercussions – like being sued for non-compliance – that can put an organization out of business.

Pay attention – and when the first cybersecurity incident happens, take note, do an analysis of your security controls, and take steps to implement stronger measures that will ensure you’re less vulnerable in the future.


SOURCE: KnowBe4

Success Stories

Principal Owner, Law Firm

Our law firm uses IT360, Inc. for all of our technology needs. They not only provide outstanding service at a reasonable fee, but we consider them an integral part of our practice.

Principal Owner, Law Firm

Recent
Technology News

IT360 News
Summer Travel = Cyber Risk

How to stay secure on the go with it360 As summer kicks into full gear, many professionals find themselves working from new locations—whether it’s a vacation rental, a hotel lobby, or the occasional airport gate. While flexible work environments can boost morale and productivity, they also introduce a new wave of cybersecurity risks. We want […]

Read more
IT360 News
Halfway Through 2025: Is Your Tech Strategy on Track?

A mid-year check-in from it360 As we reach the midpoint of 2025, it’s a great time to pause and reflect: is your current IT strategy truly supporting your business goals? We encourage you to use this moment as a strategic checkpoint—to assess performance, identify gaps, and plan with purpose for the second half of the […]

Read more