Ransomware

Nine Entertainment Conti Ransomware β€” Australian Media Company, Sunday Telegraph Offline

πŸ“… 2021-03-28 🏒 Nine Entertainment Company IT and broadcast systems 🦠 Conti ransomware
Primary Source β†—

Incident Details

On 28 March 2021, Nine Entertainment β€” Australia’s largest media and entertainment company, operating the Nine Network (free-to-air TV), The Sydney Morning Herald, The Age, The Australian Financial Review, and radio stations β€” was hit by a Conti ransomware attack. The attack disrupted live television broadcasts and radio services, with The Today Show and Weekend Today unable to broadcast from Sydney. Newspaper printing was also affected, with some staff having to work remotely. Nine’s corporate email systems were taken offline. Nine detected the attack in the early hours of Sunday 28 March 2021 and immediately notified authorities including the Australian Cyber Security Centre (ACSC) and Australian Federal Police. The attack was characterised as sophisticated and deliberate. Nine’s response was coordinated with the ACSC and it continued broadcasting using contingency plans. The Australian Government’s Deputy Secretary for Home Affairs confirmed Nine had been attacked and that the ACSC was working with them. Notably, the attack occurred on the same day that the Australian Parliament’s networks were experiencing disruptions β€” though no connection was established between the two incidents. Nine Entertainment recovered operations over the following days. The incident demonstrated that media organisations β€” which operate under significant time pressure with live broadcasts β€” are attractive and impactful ransomware targets.

Technical Details

Initial Attack Vector
Conti ransomware group attacked Nine Entertainment via unknown initial access vector; the attack encrypted systems across Nine's network including broadcast and production systems
Vendor / Product
Nine Entertainment Company IT and broadcast systems
Malware Family
Conti ransomware

Timeline

  1. 2021-03-28 Breach occurred
  2. 2021-03-28 Publicly disclosed