Tech Talks With Kinsoft

Tech Talks With Kinsoft

por Steven Kinnas

France's FICOBA Registry Breach – 1.2M Bank Accounts

IA
An attacker used the stolen credentials of a French government employee to access the national bank account registry FICOBA for about 16 days (late January–February 2026), exposing data linked to roughly 1.2 million bank accounts — IBANs, names, addresses and in some cases tax identifiers. Account balances were not accessed. FICOBA tracks nearly 300 million accounts for around 80 million people; the episode highlights how stolen-credential access (not hacking) enabled it and the fraud risk when an IBAN is paired with identity data. Concerned about credential theft and insider access to sensitive systems? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Help Net Security.

WA Government – Systemic Microsoft 365 Security Failures

IA
A WA Office of the Auditor-General report (released 6 March 2026) found systemic Microsoft 365 security failures across seven state entities. Two concrete incidents: sensitive information about 32 people (including minors) was emailed to a third party who uploaded it to a later-compromised Dropbox; and a senior officer's M365 account was phished (weak MFA), leading to a business email compromise and a $71,000 fraudulent-invoice theft. The audit flagged weak governance, identity/access management, no broad DLP, poor logging and phishable SMS-based MFA. We turn it into practical guidance: phishing-resistant MFA, DLP, controlling unmanaged cloud storage, and BEC defences. Worried about M365 hardening and BEC? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: iTnews; Computer Weekly.

Last Week in Tech – GPT-5.4's Computer-Use Leap, and a Brutal Week for Healthcare Data

IA
Your Monday catch-up, with a security lens. This week: OpenAI ships GPT-5.4 with a native computer-use capability, and Nvidia's CEO signals its AI-lab investing spree may be done. But the dominant theme is breaches in healthcare and data brokers — a cancer centre, a health-claims processor, and LexisNexis all disclose major losses of sensitive records. Hold sensitive health or customer records? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: TechCrunch; OpenAI; CNBC; SecurityAffairs; BleepingComputer; The Record.

UNC3886 – China-Linked Espionage Hits Singapore's Telcos

IA
Singapore's Cyber Security Agency attributed a sophisticated espionage campaign against all four major telcos — M1, SIMBA, Singtel and StarHub — to the China-nexus group UNC3886. Active since around July 2025, the attackers exploited Fortinet and VMware zero-days plus advanced Linux rootkits to hold persistent access for close to a year before being evicted. The response, Operation Cyber Guardian, ran more than eleven months with 100+ defenders. Officials found no evidence that customer personal data was exfiltrated and services were not disrupted — the goal was intelligence-gathering on critical infrastructure. Want to understand whether your network has uninvited long-term guests? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: TechCrunch; The Record (Recorded Future News).

Australian Court Files Sent Offshore – A Data-Sovereignty Failure

IA
In February 2026 it emerged (ABC News, 16 Feb; VIQ statement, 20 Feb) that Canadian transcription provider VIQ Solutions had subcontracted Australian court transcription to India-based e24 Technologies in breach of its Commonwealth contracts, resulting in sensitive Federal Court and Federal Circuit and Family Court files being accessed offshore. Staff had reportedly raised offshoring concerns since 2025 but were dismissed; access logs showed files viewed outside Australian hours. The matter went to the ACSC and was called a national-security risk. The episode focuses on data sovereignty, subcontractor risk and contractual data-handling controls — not the contents of any case. Need to know where your data is actually processed? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: ACS Information Age; Cyber Daily.

Last Week in Tech – Nvidia's Record Quarter, OpenAI's $110B Raise, and Washington Blacklists Anthropic

IA
Your Monday catch-up, with a security lens. A blockbuster week for AI money: Nvidia posts a record quarter, OpenAI closes a $110B round, and the Trump administration blacklists Anthropic over its refusal to drop weapons and surveillance restrictions. On security: a Russian-speaking actor uses AI to mass-compromise Fortinet firewalls, ShinyHunters hits CarGurus and Wynn Resorts, and AI-generated code shows up in an attack on Mexican government systems. Wondering whether your firewalls' management interfaces are exposed? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: CNBC; TechCrunch; Bloomberg; CNN; The Record; SecurityAffairs.

UMMC Ransomware – 35 Clinics Shut Across Mississippi

IA
Detected on 19 February 2026, a ransomware attack on the University of Mississippi Medical Center disrupted its network and IT systems, including the Epic electronic medical record system. UMMC closed most of its clinics statewide (kidney dialysis excepted), cancelled outpatient surgeries, procedures and imaging, and reverted to pen-and-paper documentation. Clinics stayed closed about nine days, reopening around 2 March 2026, with the FBI and CISA involved. Worried about ransomware and operational resilience in your organisation? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BleepingComputer; NPR.

Hazeldenes – Cyberattack Halts an Aussie Poultry Giant

IA
Victoria-based Hazeldenes, one of Australia's largest poultry producers (roughly 900,000 birds a week at its Lockwood South facility), detected a cyberattack on 19 February 2026 and shut down its IT systems, halting processing and packaging. The result was immediate chicken shortages for wholesalers, butchers and supermarkets across Victoria, with some deliveries failing without notice. Hazeldenes engaged external experts, notified Australian authorities and began a phased return to production from around 25 February; it had not yet confirmed whether customer or employee data was compromised. We discuss the operational and food-supply-chain impact of attacks on manufacturers and why rapid IT shutdowns are sometimes necessary. Could your operations survive an unplanned IT shutdown? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily; The Cyber Express.

Last Week in Tech – Gemini 3.1 and Claude 4.6 Land, OpenAI's Agent Hire, and the Figure Fintech Breach

IA
Your Monday catch-up, with a security lens. This week the model race sped up — Google ships Gemini 3.1 Pro, Anthropic ships Claude Sonnet 4.6, and OpenAI hires a star open-source developer to build personal agents. On the breach desk: fintech lender Figure is hit by the ShinyHunters crew (nearly a million customers), France's national bank-account registry is accessed via stolen credentials, and a PayPal software bug quietly exposes some users' data. Concerned about credential theft and the AI tools your team is adopting? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: TechCrunch; Google; Anthropic; SecurityWeek; The Record; BleepingComputer.

Odido Data Breach – 6.2 Million Customers Exposed

IA
In February 2026, Dutch telecom Odido (formerly T-Mobile Netherlands) disclosed a breach affecting roughly 6.2 million customers across Odido and its Ben brand. Attackers linked to ShinyHunters used social engineering — phishing and impersonating IT staff to bypass MFA — to reach a customer contact system, taking names, addresses, bank account numbers, phone and email, and ID document numbers (passport/driver's licence); passwords, call logs and billing were not affected. We cover the extortion attempt, that Odido reportedly learned of the theft when the attackers made contact, and the regulatory and legal fallout. Concerned about social engineering and account takeover? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BleepingComputer; SecurityWeek.
10 de 14