Legal Practice Board of WA hit by cyber attack

The Legal Practice Board of WA has become the latest target of a cyber attack, after hackers accessed bank details and other information of legal professionals.
The independent statutory body confirmed it was investigating a cyber attack reportedly launched by relatively new ransomware gang Dire Wolf, which is claiming to have stolen 300 gigabytes of data.
The legal board said the information taken included minimum contact information, bank account details for the board and some legal practices and some operational and resourcing information.
“From our investigation to date, we have confirmed that a small amount of information was taken from the board’s IT environment by an unknown third party which has now been disclosed,” the board said in a statement on its website.
The Legal Practice Board of WA said it had obtained an injunction to prevent any access, dissemination or sharing of data impacted by this incident.
The board said it was prioritising an investigation with support from external experts, including Cyber Security Western Australia- a state government body.
The Legal Practice Board of WA's remit spans issuing Western Australian legal practicalities with their annual practicing certificates to assisting the Supreme Court with new admissions.
The attack comes as cyber and security professionals ramp up their warnings to local businesses to take measures to further protect their data.
Cyber security company Darktrace's vice president field CISO Tony Jarvis said Dire Wolf’s attack on the LPBWA highlighted just how targeted ransomware attacks had become.
“With AI-automation, these targeted attacks can be carried out at scale, while crime-as-a-service packages offer literal off-the-shelf ransomware packages – in this case, the relatively unknown group Dire Wolf is threatening to publish 300 gigabytes of stolen data from the Legal Practice Board of Western Australia,” he said.
“Email remains the primary point of entry for ransomware, but by no means is it the only one. Collaboration tools like Microsoft Teams, Slack, and Dropbox are the new phishing battlegrounds, further complicating the job of security teams.
“Cybersecurity today demands a forward-looking approach, constant vigilance, and the ability to adapt to ever more sophisticated attack patterns.
“Organisations must understand that if you detect a threat after damage becomes visible, it’s already too late.”
Similarly, RSM Australia cyber security and privacy risk services partner Riaan Bronkhorst issued a stark warning to businesses on cyber threats.
He said failing to invest in robust protection now risks crippling businesses with losses potentially reaching hundreds of thousands of dollars, even into the millions.
By RSM’s count, the average cost of a cyber attack is $4.17 million, with a business targeted every six minutes.
Among the recent cyberattacks in Perth was on Genea Fertility Clinic, one of Australia’s largest IVF treatment providers, by ransomware gang Termite group in February.