CSIDB logo
Incident

Harry Perkins Institute of Medical Research

Incident posture

Attack window
Jul 2024
Location
Australia
Status
Historical
CIA posture
Available to members
Updated
2025-12-29 18:44

Linked entities

Victim
Harry Perkins Institute of Medical Research
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Harry Perkins Institute of Medical Research experienced a cyber incident affecting its internal servers, prompting an investigation with external cybersecurity experts to restore secure network access. While the organization has not confirmed reports of a ransomware group demanding $500,000, it is collaborating with law enforcement and privacy regulators to address the breach. The full scope and nature of compromised data remain undetermined, though the institute emphasized protecting the privacy and safety of employees, researchers, tenants, and supporters as its primary concern. Further details are expected to emerge in the coming days.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Harry Perkins Institute of Medical Research in Perth confirmed on July 1, 2024, that it was investigating a significant cyber security breach affecting its internal servers. The institute detected unauthorized activity compromising its network infrastructure, though specific technical details about the intrusion method or initial access vectors were not disclosed publicly. Upon identifying the incident, management immediately engaged external cyber security experts and advisors to assist in containment and forensic analysis. The primary response objectives included securing compromised systems and restoring safe network access across the institute’s facilities. While the investigation remained in early stages, officials acknowledged potential operational disruptions but did not specify whether research activities or clinical data systems were impaired. No definitive timeline for full system restoration was provided at this initial disclosure phase.

The institute formally notified law enforcement agencies and privacy regulators in accordance with standard breach protocols, though it did not identify specific collaborating entities. A spokesperson emphasized that determining the nature and scope of affected data—including potential exposure of employee, researcher, tenant, or supporter information—remained an active priority for investigators. The organization stated that safeguarding personal privacy constituted its foremost concern during the remediation process. No evidence confirming data exfiltration or ransomware deployment was officially verified, despite external reports alleging a $500,000 ransom demand from threat actors. Daily operational updates were deferred pending further forensic examination, with the institute anticipating additional clarity within days. Response teams continued working to isolate compromised systems while maintaining critical research functions through alternative protocols where feasible.

Sources

Sources available to members: 1 source.

CSIDB