Tech Talks With Kinsoft

Tech Talks With Kinsoft

by Steven Kinnas

Origin Energy – A 3:40am Email, an Extortionist Called "John Doe", and Millions of Customers in Limbo

AI
Australia's largest energy retailer confirmed unauthorised access to customer data after an extortionist calling themselves "John Doe" took the story to journalists first. We walk through the timeline — the 3:40am customer emails, the ASX statements of 22–23 July, CEO Frank Calabria's apology — and what was taken: names, addresses, dates of birth, phone numbers, account information and partial card/bank digits. The attacker's claim of two million affected customers remains unverified. We cover why partial financial digits are a scammer's best prop, the rise of media-driven extortion pressure, and three lessons for Australian organisations: brief your teams on impersonation risk immediately, plan for the lone-wolf extortionist, and rehearse your disclosure clock. AFP, ACSC and OAIC are all engaged. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Origin Energy ASX/investor statements (originenergy.com.au), Cyber Daily (24 Jul), BleepingComputer (23 Jul), SecurityWeek.

Last Week in Tech – The AI Capex Reckoning, AMD's Anthropic Deal, and WordPress Under Attack

AI
The market finally asks AI to show its receipts. This week: Alphabet and Tesla beat on revenue but get hammered for record capex — the Nasdaq's worst day since April — while Intel posts its best growth since 2011; AMD and Anthropic strike a 2-gigawatt GPU deal with up to US$5B in equity; the "wp2shell" WordPress core flaws go from patch to mass exploitation in 48 hours; a 7,600-repository GitHub campaign booby-traps fake AI agent integrations — and AI coding assistants recommend them to victims; Anubis claims the Fairlife ransomware attack (unverified); and DeepSeek V4 arrives with API surge pricing. Practical takeaways for Australian businesses throughout. Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: CNBC (Alphabet/Tesla/Intel earnings, AMD–Anthropic), AMD investor relations, SecurityWeek & Rapid7 & Qualys (wp2shell), The Hacker News & BleepingComputer (FakeGit/AgentBaiting, Anubis–Fairlife), DeepSeek API reporting.

Coca-Cola's Fairlife – The Ransomware Attack That Stopped the Milk

AI
This week's global deep-dive is about ransomware you can see on a supermarket shelf. On 16 July, Coca-Cola disclosed in a formal SEC filing that its billion-dollar dairy subsidiary Fairlife had been hit by a ransomware event that reached production-related systems — and that all US production of Fairlife products had been temporarily suspended, while Canadian lines kept running. No criminal group has claimed the attack, and whether data was stolen or a ransom demanded remains unknown. We use the incident to unpack the difference between IT and OT — office systems versus the systems that run machines — why ransomware that touches the factory floor is measured in stopped lines rather than encrypted files, what Coca-Cola's fast, formal disclosure got right, and how any business that makes, moves or sells physical things should think about segmentation, continuity and the "can we run without the computers?" question. Could your operations keep moving if ransomware reached the systems that run them? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: SEC 8-K filing (Coca-Cola); BleepingComputer; TechCrunch; Help Net Security.

Partnered Health – A GP Network Breach, 21 Clinics, and a Court Order Against Criminals

AI
This week's Australian deep-dive is a confirmed breach at Partnered Health, the operator of more than 60 medical, skin-cancer and allied-health clinics nationwide. An intruder detected on 23 June stole personal and health information tied to 21 named clinics across five states and territories — names, dates of birth, Medicare and health-insurance numbers, and in some cases consultation notes, referral letters and pathology results. Patients were notified from around 15 July, some 22 days after detection, and the company took the unusual step of obtaining a NSW Supreme Court injunction barring use or publication of the stolen data — a tactic security experts openly question. We walk the timeline, weigh what an injunction against anonymous offshore criminals can and can't achieve, and pull out the lessons: why health data is the crown jewel of stolen identity, what a good notification looks like, and the questions every practice — and every patient — should be asking. Does your organisation hold health or identity data it couldn't afford to lose? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: ACS Information Age; SBS News; DataBreaches.net; The Cyber Express; EFTM.

Last Week in Tech – China's Open-Source Shock, TSMC's Record Quarter, and a 570-Flaw Patch Tuesday

AI
Your Monday catch-up on the week in tech, with a security lens. China's Moonshot AI releases Kimi K3 — the largest open-weight model ever, at 2.8 trillion parameters — and chip stocks shudder in a DeepSeek-style sell-off. The AI build-out rolls on regardless: TSMC posts a record quarterly profit, up 77 per cent, and adds another 100 billion US dollars to its Arizona plans, a day after ASML lifts its full-year outlook. The first Nvidia H200 chips ship to China under new licences even as Nvidia halves its approved Asian buyer list. And a report says Meta is weighing leasing Anthropic up to 10 billion dollars of compute — early talks only, and we flag it as such. On the security desk: Microsoft's biggest-ever Patch Tuesday fixes 570 flaws including two zero-days under active attack, a separate perfect-storm SharePoint flaw (CVE-2026-58644) draws a three-day CISA patch deadline, and the US, EU and UK launch their first joint cyber-sanctions package against the Russian ransomware ecosystem. Wondering what any of this means for your patch queue or your AI plans? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Bloomberg; CNBC; Axios; SCMP; SEC filings; DigiTimes; Reuters; CNN Business; BleepingComputer; CrowdStrike; CISA; Rapid7; SecurityWeek; The Hacker News; The Record; Chainalysis.

AssuranceAmerica – One Stolen Password, Seven Million Exposed

AI
A global breach that turned on the most ordinary failure there is — one stolen employee login. US auto insurer AssuranceAmerica has begun notifying almost seven million people that attackers used a single compromised staff credential to copy files containing names, policy details, driver's-licence numbers and — per state regulator filings — Social Security and tax ID numbers, in what's reportedly the largest exposure of American driver's-licence numbers this year. We walk the timeline from the 16 March credential theft to the 10 July notifications, weigh a nearly four-month disclosure gap and a notably lean response, and draw out the lessons: mandatory multi-factor authentication, collecting and keeping less identity data, and why how you treat people after a breach is part of security, not an afterthought. Do you know whether one stolen password could reach your crown jewels? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BleepingComputer; TechCrunch; Cybernews; SecurityWeek; Techlicious.

Teletrac Navman – 3,000 Fleets' Live GPS Data Allegedly Up for Sale

AI
An alleged Australian breach that turns a mundane operational tool into a physical-safety question. A criminal on a hacking forum claims to have captured a live, 48-hour feed of real-time GPS data from fleet-telematics provider Teletrac Navman — allegedly covering nearly 3,000 customer organisations across Australia and New Zealand, more than 30,000 vehicles, and thousands of named drivers, with a sample said to name councils, rail operators and a mining giant. Teletrac Navman has not confirmed the breach and the OAIC would not confirm a notification, so we hold a hard line between the seller's claims and confirmed fact — and use the story to unpack why location data is some of the most sensitive you hold, the risk of concentrating it in one shared platform, and the questions to put to your providers. Worried about the location and telematics data flowing through your business? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily; ACS Information Age; Daily Dark Web.

Last Week in Tech – The AI Boom's Memory-and-Power Bill, Microsoft's 4,800 Cuts, and a Perfect-10 ColdFusion Flaw

AI
Your Monday catch-up on the week in tech, with a security lens. This week the real AI story wasn't a model — it was the physical bill coming due. Samsung posts a record quarterly profit, up nearly nineteen-fold, on AI-memory demand; SK Hynix raises around 29 billion dollars in one of the biggest-ever US share listings; and Britain's National Grid tips 1.75 billion into a US power project built to feed a single Microsoft data centre. Microsoft cuts about 4,800 jobs and overhauls Xbox as it reallocates toward AI. Europe's top court makes Google's 4.1-billion-euro Android fine final. And on the security desk: a perfect-10 Adobe ColdFusion flaw (CVE-2026-48282) is exploited within two hours of disclosure and draws an emergency CISA patch order, Accenture confirms a breach after a criminal offers stolen data for sale, and INTERPOL's Operation First Light nets 5,811 arrests and 293 million dollars. Trying to work out what all this means for your hardware budget and your patch queue? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Reuters; CNBC; Bloomberg; Samsung; TechCrunch; DataCenterDynamics; Adobe; CISA; BleepingComputer; SecurityWeek; Help Net Security; INTERPOL.

DHS HSIN – When "Unclassified" Doesn't Mean "Low Risk"

AI
A breach at the heart of America's homeland-security apparatus - and a masterclass in why "unclassified" is not the same as "unimportant." The US Department of Homeland Security has confirmed that attackers broke into the Homeland Security Information Network, or HSIN - the platform it uses to share sensitive-but-unclassified information with thousands of federal, state, local and private-sector partners, and one currently helping coordinate security for the 2026 World Cup. Classified systems were untouched, but what the intruders took, and who they are, remains unknown. We dig into the danger of "sensitive-but-unclassified" data, why legacy collaboration systems are prime targets, and how to communicate honestly when you know attackers got in but not yet what they took. Do you know how your own data is classified - and protected accordingly? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BleepingComputer; Nextgov/FCW; TechCrunch; PYMNTS; UpGuard.

Reynella East College – Interlock's First Australian Victim Dumps 600GB of School Data

AI
A confronting Australian breach that puts schools squarely in the firing line. Reynella East College - a public preschool-to-Year-12 school in Adelaide's south with more than 1,900 students - took its computer systems offline for a week after a cyber security breach, and weeks later the ransomware group Interlock dumped what it claims is 610 gigabytes of stolen data on the dark web. It's Interlock's first known attack on an Australian organisation, and a review of the leak reportedly turned up passport scans of international students and staff and lists of passwords stored in plain text. We unpack how schools became fair game, why identity documents and cleartext passwords are the worst possible things to lose, and how to tell what's confirmed from what's just a criminal's claim. Worried about what's sitting in your own file shares? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily; Comparitech; Insurance Business Australia; EducationHQ; ransomware.live.
4 of 14