Tech Talks With Kinsoft

Tech Talks With Kinsoft

by Steven Kinnas

Brightspeed – Crimson Collective Claims 1M+ Records

AI
In early January 2026, fiber-broadband provider Brightspeed opened a cybersecurity investigation after a group calling itself Crimson Collective claimed via Telegram (4 January) to have stolen data on more than 1 million customers, sharing screenshots and small samples as purported proof. The claimed data included account master records — names, emails, phone numbers, billing and service addresses and account metadata — with the group alleging payment histories and masked card details may have been accessed. As of mid-January the company had not confirmed exfiltration or a production-system compromise; the claims remained unverified, and class actions followed. We cover how to assess unverified extortion claims. Unsure whether a leak claim against you is real? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: SecurityWeek; eSecurity Planet.

Goodstone Group Breach – Passport Scans Leaked in CMD Ransomware Attack

AI
In May 2026, Tasmanian hospitality group Goodstone Group — which runs hotels, restaurants, bars and bottleshops across northern Tasmania — confirmed it was responding to a cyber incident after the CMD Organization ransomware group listed it on a dark web leak site. In this episode of Tech Talks with Kinsoft, we cover the sensitive material the attackers published as proof, including employee passport scans, a confidentiality agreement and bank reconciliation details, the roughly $1 million (9 BTC) extortion demand, and the company's response as it engaged security experts and authorities. Worried about ransomware hitting your business? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily.

Last Week in Tech – AI Writes Its First Zero-Day, OpenAI's Deployment Play, and the Canvas Mega-Breach

AI
Your Monday catch-up on the week that was, with a security lens. This week: researchers document the first known case of attackers using AI to develop a working zero-day exploit. OpenAI launches a $4B Deployment Company and buys consultancy Tomoro to get AI into enterprises faster, while SoftBank pours money into AI data centres and batteries. On the breach desk: ShinyHunters complete what's now called the largest education-sector breach on record, defacing Canvas login portals at around 330 institutions — including Harvard and Princeton — before Instructure paid up. Plus Washington turns up the heat on AI, with the Pentagon flagging a major AI lab as a supply-chain risk. Worried about AI-accelerated attacks on your own systems? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Tech Startups; Coaio; cm-alliance; SharkStriker; TechCrunch.

McGraw Hill – 13.5M Exposed via Salesforce Misconfig

AI
Edtech giant McGraw Hill confirmed a breach (dated around 10 April 2026, surfacing mid-April) after ShinyHunters' extortion threat; about 13.5 million accounts were exposed — emails, names, phone numbers and physical addresses — via a Salesforce misconfiguration. When negotiations failed, the group published over 100 GB of data. McGraw Hill said the exposed data was limited and did not include Social Security numbers, financial information or student data from its learning platforms. We discuss misconfiguration risk and the limits of non-sensitive data. Need a configuration and exposure review of your SaaS estate? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: BleepingComputer; The Register.

Energy Action Breach – SafePay Ransomware Targets an Energy Giant

AI
In early May 2026, the SafePay ransomware group listed Energy Action — an Australian firm that manages energy procurement for a large share of the country's commercial businesses — on its dark web leak site, threatening to release stolen data. In this episode of Tech Talks with Kinsoft, we cover what Energy Action does, the kind of data potentially at risk, the fact that the volume and specifics had not been confirmed, and background on SafePay, an active global threat that notably does not operate as ransomware-as-a-service. Throughout, we flag where claims are alleged rather than confirmed. Concerned about ransomware exposure in your business or supply chain? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Cyber Daily.

Last Week in Tech – Microsoft's Agents Go GA, the Canvas Mega-Breach Escalates, and DigiCert's Cert Compromise

AI
Your Monday catch-up, with a security lens. This week: Microsoft makes its AI agents generally available at Build, and the ShinyHunters Canvas breach escalates into what's being called the largest education-sector breach on record. On security: certificate authority DigiCert is socially engineered into issuing fraudulent code-signing certs, and Zara and an NVIDIA cloud-gaming partner are breached. Confident your staff can't be talked into handing over access? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: Microsoft; The Hacker News; CNN; Comparitech; CM-Alliance.

Medtronic – ShinyHunters Hits a Medical-Device Giant

AI
ShinyHunters listed Medtronic on its leak site on 17 April 2026, claiming more than 9 million records; Medtronic confirmed the breach on 24 April alongside an SEC Form 8-K, stating an unauthorized party accessed data in certain corporate IT systems. Potentially affected data included names, addresses, certain medical details, billing and health-insurance information, demographics and Social Security numbers. Medtronic said it found no impact to products, patient safety, manufacturing and distribution or financial-reporting systems. We place it in ShinyHunters' wider Salesforce and SSO extortion campaign. Worried about corporate-IT and Salesforce exposure? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: SecurityWeek; Infosecurity Magazine.

Canvas LMS Data Breach – Australian Schools and Universities Hit

AI
In May 2026, Instructure disclosed a cyber security incident affecting Canvas, the learning management platform used widely across Australian universities, vocational providers and schools. In this episode of Tech Talks with Kinsoft, we cover the categories of data involved — names, email addresses, student ID numbers and messages between users — Instructure's statement that it found no evidence passwords, dates of birth, government IDs or financial information were taken, the scale of the impact on Australian education, and the OAIC and institutional response, including guidance for affected students and staff. Reviewing your own vendor and platform security? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: OAIC; University of Canberra.

Last Week in Tech – OpenAI Breaks Its Microsoft Lock-In, Big Tech's $650B AI Bill, and the Salesforce Breach Wave

AI
Your Monday catch-up, with a security lens. This week: OpenAI loosens its Microsoft exclusivity and goes live on AWS, and Big Tech's quarterly earnings push combined AI spending toward $650–700B for the year. On the breach desk: the ShinyHunters Salesforce-theft wave rolls on through Amtrak, Pitney Bowes and Vimeo, while a Hungarian media giant loses 8.5 terabytes. Worried about what's connected to your Salesforce or CRM? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: CNBC; TechCrunch; VentureBeat; Quartz; Fortune; CM-Alliance.

France's ANTS ID Registry – 11.7M Accounts Exposed

AI
France's ANTS (Agence nationale des titres sécurisés / France Titres), the Interior-Ministry body managing ID cards, passports, driver's licences and immigration documents, detected a security incident around 15 April 2026 on its ants.gouv.fr portal. ANTS confirmed about 11.7 million accounts were impacted (a threat actor claimed up to 19 million). Exposed data reportedly included full names, contact details, dates of birth, home addresses and civil-status information. Researchers traced it to a basic Insecure Direct Object Reference (IDOR) flaw in the ANTS API; ANTS notified the CNIL, ANSSI and the Paris prosecutor. We explain IDOR in plain terms and the identity-theft risk. Building or running citizen-facing portals and APIs? Visit www.kinsoft.com.au to talk through your security and IT needs. Sources: TechCrunch; Help Net Security.
7 of 14