Data leak ⛓ Supply Chain

HWL Ebsworth Law Firm — ALPHV/BlackCat Ransomware, Australian Government Data Exposed

📅 2023-04-01 🏢 HWL Ebsworth (Australian law firm, one of the largest in Australia) 🦠 ALPHV/BlackCat ransomware
Primary Source ↗

Incident Details

HWL Ebsworth, one of Australia’s largest law firms with over 2,500 staff and a significant federal and state government client base, was attacked by the ALPHV/BlackCat ransomware group in April 2023. ALPHV claimed responsibility in May 2023 and began publishing stolen data after HWL Ebsworth declined to pay the ransom. The group published approximately 1.1 terabytes of data including confidential legal documents, financial statements, HR records, and — most significantly — sensitive data relating to HWL Ebsworth’s government clients. The Australian Cyber Security Centre (ACSC) and Australian Federal Police (AFP) were engaged. Up to 65 Australian government agencies were identified as potentially having sensitive data exposed through the breach, including the Department of Home Affairs, the National Disability Insurance Agency (NDIA), the Reserve Bank of Australia, the Australian Taxation Office (ATO), the Australian Federal Police (AFP), and numerous state government departments. The breach prompted an emergency whole-of-government response from the Australian government. The exposure of sensitive legal advice and government contracts through a law firm breach demonstrated the particular risk of legal service providers as a vector for government data exposure. An Australian court granted an injunction preventing Australian media from publishing specific documents from the leaked data that contained sensitive government material. The incident led to significant reviews of how Australian government agencies manage data shared with external legal advisors.

Technical Details

Initial Attack Vector
ALPHV/BlackCat ransomware group gained access to HWL Ebsworth's network; the group subsequently published 1.1 terabytes of stolen data on its dark web leak site after HWL Ebsworth refused to pay a ransom; the initial access vector was not publicly disclosed
Vendor / Product
HWL Ebsworth (Australian law firm, one of the largest in Australia)
Malware Family
ALPHV/BlackCat ransomware
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2023-04-01 Breach occurred
  2. 2023-05-10 Publicly disclosed
  3. 2023-06-01 Customers notified