Ban looms for data breach ransom payments

November 13, 2022 02:44 PM NZDT | By AAPNEWS
Image source: AAPNEWS

It could soon be illegal for companies that fall victim to data breaches to pay ransoms to the hackers.

Home Affairs Minister Clare O'Neil has confirmed the government is examining whether new laws are needed to stop ransom payments in the wake of the Medibank and Optus data breaches.

While short-term successes were needed in cyber security reform following the mass hacks, she said on Sunday, other long-term outcomes were being considered including banning ransom payments.

It follows the government launching a high-tech policing operation targeting the network of hackers behind the Medibank attack, which stole the medical histories and private information of customers.

"The way we're thinking about the reform task ... is a bunch of quick wins, things that we can do fast, and the standing up for the new police operation is one of those," Ms O'Neil told the ABC's Insiders.

"There's some really big policy questions that we're going to need to think about and consult on, and we're going to do that in the context of the cyber security strategy.

"We'll have a look at (making ransom payments illegal)."

Ms O'Neil said Medibank was right not to pay the ransom demanded by the hackers, with those behind the breach threatening to release more data if the amount was not paid.

"I have never seen people that lack a moral code so clearly than the hackers who are releasing data about Australians online," she said.

"The idea we're going to ... trust these people to delete data they have taken off and may have copied a million times is just, frankly, silly ... we don't want to fuel the ransomware business model."

Federal police confirmed on Friday Russian criminals were behind the attack on Australia's largest private health insurer.

A 100 officer-strong, standing cybercrime operation targeting hackers will be led by the AFP and Australian Signals Directorate.

"This is Australia standing up and punching back," Ms O'Neil said.

"We are not going to sit back while our citizens are treated this way and allow there to be no consequences for that.

"We are offensively going to find these people, hunt them down and debilitate them before they can attack our country."

The minister said the response to cyber offences needed to be improved, due to their number.

She said institutions like NAB received 50 million attacks a month and the tax office three million.

"I don't think anyone can promise cyber attacks are going to go away and one of the things people need to understand is really how relentless this is," she said.

Almost 500,000 health claims were stolen along with personal information, as part of the Medibank breach.

The insurer has created a one-stop shop of mental health and other support services affected customers can access via its website.

Nationals leader David Littleproud said he wanted to work closely with the government to speed up passage of legislation to ensure better cyber security measures and larger fines for companies.

"Let's work together and get this right because this is people's private data being shared on the dark web for reasons that shouldn't be put out there," he told the Nine Network.

"There's an opportunity to actually expedite it. We're saying to the government let's see the urgency in this."

Ms O'Neil said there needed to be a mechanism to make sure companies only held data while it was useful and then dispose of it.


Disclaimer

The content on this website, including, but not limited to, any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations, and video (“Content”) is a service provided by Kalkine Media New Zealand Limited, Company Number 8107196 and NZBN 9429018590709 (“Kalkine Media, we or us”) and is available for personal and non-commercial use only. The principal purpose of the Content is to educate and inform. The Content does not contain or imply any recommendation or opinion intended to influence your financial decisions and must not be relied upon by you as such. Some of the Content on this website may be sponsored/non-sponsored, as applicable, but is NOT a solicitation or recommendation to buy, sell or hold the stocks of the company(s) or engage in any investment activity under discussion. Kalkine Media is neither licensed nor qualified to provide financial advice through this platform. Users should make their own enquiries about any investments and Kalkine Media strongly suggests users seek financial advice from a financial advice provider, stockbroker or other professional (including taxation and legal advice), as necessary. Kalkine Media hereby disclaims any and all liability to any user for any direct, indirect, implied, punitive, special, incidental or other consequential damages arising from any use of the Content on this website, which is provided without any express or implied warranties of any kind. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media.
The content published on Kalkine Media also includes feeds sourced from third-party providers. Kalkine does not assert any ownership rights over the content provided by these third-party sources. The inclusion of such feeds on the Website is for informational purposes only. Kalkine does not guarantee the accuracy, completeness, or reliability of the content obtained from third-party feeds. Furthermore, Kalkine Media shall not be held liable for any errors, omissions, or inaccuracies in the content obtained from third-party feeds, nor for any damages or losses arising from the use of such content. Some of the images/music that may be used on this website are copyrighted to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music used on this website unless stated otherwise. The images/music that may be used on this website are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have used reasonable efforts to accredit a source wherever it is indicated or is found to be necessary or desirable.
This disclaimer is subject to change without notice. Users are advised to review this disclaimer periodically for any updates or modifications.

Sponsored Articles


We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.