Menu
Browse

Cyber Incident Victim: PH Property

Date:

Mar 2023

Location:

Australia

Summary

A Victorian real estate agency experienced a cyber attack compromising a staff email account, leading to unauthorized access and theft of customer data including bank details, identification documents, and contact information. The breach involved threat actors impersonating the staff member to send fraudulent communications to clients while potentially exfiltrating four months of email data. Despite having security protocols such as two-factor authentication and firewalls in place, the attackers bypassed defenses, prompting the agency to notify affected customers and regulators while engaging cybersecurity support. The incident reflects broader vulnerabilities among small and medium enterprises, which face rising targeting due to perceived weaker defenses compared to larger organizations.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On 15 March 2023, threat actors compromised a staff email account at Victorian real estate agency PH Property Bendigo, leading to a data breach affecting approximately 200 customers. Attackers bypassed existing security protocols including two-factor authentication, randomized passwords, firewall protections, and security software. The intrusion resulted in the theft of four months of data containing client bank details, names, contact information, and identity documentation. The breach was detected when fraudulent communications originating from the compromised email account—associated with a staff member named Kayla—were sent to clients requesting they open malicious attachments. On 29 March, PH Property notified affected clients via email, explicitly warning against interacting with these messages and disclosing that attackers might possess a local copy of Kayla’s entire email account, granting access to all sent and received correspondence. The agency immediately engaged cybersecurity professionals to secure its network and reported the incident to the Office of the Australian Information Commissioner.

Cyber Incident Image

PH Property advised clients to monitor bank accounts and update passwords as precautionary measures. Forensic analysis preserved affected devices to maintain evidence for insurance and investigative purposes, with security expert Brenton Johnson emphasizing the importance of retaining compromised hardware rather than wiping it. The incident highlighted heightened risks for small and medium enterprises, with industry data indicating 43% of cyber attacks in 2019 targeted businesses with fewer than 250 employees. FBI statistics from the Internet Crime Complaint Center further supported this trend, documenting 11,000 SME cyber attack reports totaling $217 million in losses prior to this breach. While PH Property’s implemented defenses exceeded typical SME standards, the successful breach demonstrated attackers’ evolving capabilities against multi-layered security architectures.

Sources
Sources available to members
1 source