In May 2021, criminals attacked a United States company,
Colonial Pipeline, which carries almost half the fuel
supplies that power the east coast of the United States.
This ransomware attack resulted in the company’s decision
to shut down the pipeline. Fuel distribution was disrupted
for over a week, during which time the United States
experienced fuel shortages, panic buying, and impacts
on transport services and air flight schedules.
Criminals have launched ransomware attacks against
Australia’s critical infrastructure, businesses and members
of the community. For example, during the height of the
COVID-19 pandemic in 2020, ransomware campaigns
targeted Australia’s aged care and healthcare sectors.
The ‘Maze’ ransomware encrypted valuable information,
such as sensitive personal and medical information,
so that it could no longer be used. This reckless activity
threatened the operation of health facilities and caused
very real health and safety risks to our community.
These incidents demonstrate the importance of strong
cyber security, particularly in the protection of critical
infrastructure.
Case study: Ransomware attacks against the Australian health sector
In early 2019, a specialist unit within a Melbourne hospital was the target of a significant ransomware attack.
15,000 patients’ worth of sensitive health information was encrypted and made inaccessible to staff for a duration
of three weeks. The perpetrators demanded a ransom be paid in cryptocurrency in exchange for the files to be
decrypted and to allow staff to regain access to the information.
It was reported that a payment was made however not all files were recovered.
Assistance is available
Advice on mitigating the threat of ransomware can be found at cyber.gov.au.
If Australian organisations are impacted by ransomware, they can seek assistance from the Australian
Cyber Security Centre (ACSC) via 1300 CYBER1. Reporting cyber security incidents enables the ACSC to
alert and assist a broader range of organisations, and understand the scope and nature of cyber intrusions.
All Australians can report a cybercrime by visiting cyber.gov.au
4
RANSOMWARE ACTION PLAN