A notorious Russian ransomware gang which infiltrated one of Australia’s largest law firms has now targeted a string of Victorian businesses, which it is extorting over terabytes of stolen data.
The cybercriminal group AlphV, which is also known as BlackCat, has claimed responsibility over attacks on several companies including:
- TissuPath, a pathology company
- Strata Plan, an owners corporation service provider
- Barry Plant Blackburn, a real estate agency
- Tisher Liner FC Law, a business and property law firm
AlphV claims to have stolen at least 4.95 terabytes of data, which it has threatened to publish.
The attack comes after the same group went through with a threat to publish 1.45 terabytes of data on the dark web in June after one of Australia’s largest law firms, HWL Ebsworth, refused to bend to its ransom demands.
The group has also attacked FIIG securities, an Australian bond broker.
“Due to your representatives’ refusal to negotiate, we are launching a campaign involving email distribution and calls to your clients,” the hackers said in a post on their dedicated leak site, which was documented by FalconFeeds.io, a threat intelligence platform.
“Your clients will be offered the option to pay a fee for the removal of their data from the public leak. You still have a chance to prevent a catastrophe,” they said.
It is unclear what type of data the hackers claim to have, but TissuPath, the pathology company, said patient names, dates of birth, contact details, Medicare numbers and private health insurance details were exposed.
A spokesman said it was in the process of contacting everyone affected by the breach and that it took its privacy obligations “extremely seriously”.
“We can confirm that we are investigating a data breach at a third-party IT supplier involving pathology referrals issued to TissuPath between 2011 and 2020,” the spokesman said.
“Importantly, TissuPath’s main database and reporting system that stores patient diagnoses was not compromised. Further, we do not store patient financial details and other personal information documents, such as drivers licence numbers.
“We are very sorry this has happened, and we sincerely apologise to our patients who may have been affected.”
Hacks connected to Melbourne IT firm
TissuPath, Strata Plan and Barry Plant Blackburn were all clients of Core Desktop, a company based in South Melbourne which was hired to provide IT services.
The ABC has obtained a letter that Core Desktop sent to its clients which revealed it became aware of the hack on 22 August 2023.
“Our cyber forensic team do not have a firm understanding of the origins of the entry but initial suggestions are that it was from a targeted client-side phishing attack which infiltrated our control systems, impersonated privileged accounts and encrypted some servers,” the letter said.
“They appear to have acted in a focused fashion and threatened a small number of Core Desktop clients.”


