Security Market Segment LS
Saturday, 04 July 2020 13:00

Third batch of Toll documents leaked online after Windows ransomware attack Featured

Third batch of Toll documents leaked online after Windows ransomware attack Image by falco from Pixabay

Cyber criminals who attacked Australian logistics and transport provider Toll Group in May have now released a third batch of documents which they exfiltrated from the company's website during the attack.

Toll was attacked using the Nefilim ransomware that runs only on Windows systems.

Among the documents, released as one text file and one zipped file, are many files dealing with compliance requirements for other countries, financial documents, tax invoices and the like.

Toll announced on 5 May that it had been compromised by the ransomware. This was the second attack on Toll this year, with the first in February being through use of the Mailto ransomware.

The company's last update on the attacks was on 29 May when it said in a statement it was "making good progress with the restoration of our key online systems".

toll part three

A screenshot of the announcement about the Toll documents on the dark web. Supplied

It appears that the company, a huge business, had pretty good back-ups as there has been no sign of any communication with the attackers.

The second lot of documents related to Toll's dealings with Samsung, the South Korean conglomerate, and were posted on 5 June.

There were two links that time too, one being a text file that listed the names of the documents. The second, coming in at 4.6 gigabytes, included the documents themselves.

Contacted for comment, iTWire's regular commentator Brett Callow, a threat researcher with the New Zealand-headquartered security outfit Emsisoft, said: “Toll’s decision not to pay was a smart one. Law enforcement agencies everywhere advise against paying, and they do so for a reason: paying keeps the criminals in business.

"If every company were to stop paying tomorrow, ransomware would cease to be a problem tomorrow. It’s that simple.”

Contacted for comment, a Toll spokesperson said: "We're aware that certain information has been published to the dark web. We're investigating the precise nature of the information, with the support of our cyber security partners. We continue to work closely with relevant federal authorities on the matter."

Subscribe to Newsletter here

WEBINAR 12 AUGUST - Why is Cyber Security PR different?

This webinar is an introduction for cyber security companies and communication professionals on the nuances of cyber security public relations in the Asia Pacific.

Join Code Red Security PR Network for a virtual conversation with leading cyber security and ICT journalists, Victor Ng and Stuart Corner, on PR best practices and key success factors for effective communication in the Asian Pacific cyber security market.

You will also hear a success story testimonial from Claroty and what Code Red Security PR has achieved for the brand.

Please register here by 11 August 2020 and a confirmation email, along with instructions on how to join the webinar will be sent to you after registration.

Aug 12, 2020 01:00 PM in Canberra, Melbourne, Sydney. We look forward to seeing you there!



It's all about Webinars.

These days our customers Advertising & Marketing campaigns are mainly focussed on Webinars.

If you wish to promote a Webinar we recommend at least a 2 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site and prominent Newsletter promotion and Promotional News & Editorial.

For covid-19 assistance we have extended terms, a Webinar Business Booster Pack and other supportive programs.

We look forward to discussing your campaign goals with you. Please click the button below.


Sam Varghese

website statistics

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.





Guest Opinion

Guest Interviews

Guest Reviews

Guest Research & Case Studies

Channel News