In May 2021, criminals attacked a United States company, Colonial Pipeline, which carries almost half the fuel supplies that power the east coast of the United States. This ransomware attack resulted in the company’s decision to shut down the pipeline. Fuel distribution was disrupted for over a week, during which time the United States experienced fuel shortages, panic buying, and impacts on transport services and air flight schedules. Criminals have launched ransomware attacks against Australia’s critical infrastructure, businesses and members of the community. For example, during the height of the COVID-19 pandemic in 2020, ransomware campaigns targeted Australia’s aged care and healthcare sectors. The ‘Maze’ ransomware encrypted valuable information, such as sensitive personal and medical information, so that it could no longer be used. This reckless activity threatened the operation of health facilities and caused very real health and safety risks to our community. These incidents demonstrate the importance of strong cyber security, particularly in the protection of critical infrastructure. Case study: Ransomware attacks against the Australian health sector In early 2019, a specialist unit within a Melbourne hospital was the target of a significant ransomware attack. 15,000 patients’ worth of sensitive health information was encrypted and made inaccessible to staff for a duration of three weeks. The perpetrators demanded a ransom be paid in cryptocurrency in exchange for the files to be decrypted and to allow staff to regain access to the information. It was reported that a payment was made however not all files were recovered. Assistance is available Advice on mitigating the threat of ransomware can be found at cyber.gov.au. If Australian organisations are impacted by ransomware, they can seek assistance from the Australian Cyber Security Centre (ACSC) via 1300 CYBER1. Reporting cyber security incidents enables the ACSC to alert and assist a broader range of organisations, and understand the scope and nature of cyber intrusions. All Australians can report a cybercrime by visiting cyber.gov.au 4 RANSOMWARE ACTION PLAN

Select target paragraph3