Header illustration for INC Ransom and the Affiliate Model Hitting Australian Healthcare

INC Ransom and the Affiliate Model Hitting Australian Healthcare

INC Ransom and the Affiliate Model Hitting Australian Healthcare

When people picture ransomware hitting a hospital, they tend to imagine an exotic intrusion. The joint advisory on INC Ransom — issued by the Australian Cyber Security Centre with Tonga's CERT and New Zealand's NCSC — describes something more mundane and more preventable: affiliates buying or stealing credentials, logging in through the front door, and encrypting everything they can reach. Between 1 July 2024 and 31 December 2025, the ACSC responded to 11 reported INC Ransom-related incidents in Australia, predominantly in professional services and health care. The same campaign disrupted the Tongan Ministry of Health in June 2025 and a New Zealand health-sector organisation in May 2025, with stolen data published on the group's dark-web leak site.

Some context on the group itself, because the name gets thrown around loosely. INC Ransom emerged in mid-2023 as a ransomware-as-a-service operation — the core team builds and maintains the encryptor and leak site, and affiliates rent access and do the intrusions. It also operates under the names Tarnished Scorpion and GOLD IONIC. It previously concentrated on the United States and United Kingdom; the advisory's central warning is that since early 2025 the focus has shifted to Australia, New Zealand and the Pacific island states, which puts the region squarely in this group's business plan rather than in its collateral damage.

Why healthcare keeps taking the hit

Health data is valuable twice over: it is personally sensitive, which makes double-extortion leverage potent, and health services are operationally fragile, which raises the pressure to pay. A clinic that cannot open its booking system for a week is not in the same negotiating position as a manufacturer with a spare production line. Industry reporting on 2025 healthcare ransomware trends found INC was the most active strain targeting healthcare providers globally that year, with 39 attributed attacks — and a number of Australian organisations have been named as victims.

One of those was Compumedics, the Geelong-based medical device company whose sleep-study systems connect to hospitals and clinics. The company confirmed a ransomware attack and unauthorised access to systems between mid-February and late March 2025, and breach notifications eventually covered more than 318,000 individuals across nearly a dozen healthcare providers — one of the larger healthcare breaches of the period (SecurityWeek, HIPAA Journal). Worth a note on attribution, because press reports have attached different ransomware brands to the Compumedics incident at different times: what matters for defenders is not which brand claimed it, but that a medical-device vendor sitting inside health networks became the breach of hundreds of thousands of patient records. Vendor risk in healthcare is where the blast radius hides. The ACSC's advisory notes that since January 2025, INC Ransom affiliates have specifically targeted Australian health-sector entities using compromised accounts.

How the affiliates get in

The advisory maps the group's methods to the MITRE ATT&CK framework, and the entry points are unremarkable by design:

The picture across these techniques is a business with a cost structure, and every mitigation below targets a line item in it.

What to do, in order of leverage

  1. Phishing-resistant MFA on every externally reachable service. VPNs, remote access portals and administrative interfaces should never accept a password alone. This single control disrupts the credential-buying business model the advisory describes — if the commodity on sale is a username and password, making the password insufficient removes the commodity's value. Push-based MFA is better than nothing, but number-matching or FIDO2 keys resist the fatigue attacks that follow credential leaks.
  2. Clean up the account inventory. Audit legacy and service accounts, disable what is unused, and monitor for newly created admin accounts — the advisory lists this as a persistence technique observed in real incidents. Service accounts with interactive login rights are the quiet enabler here; they rarely need them.
  3. Patch internet-facing devices fast. Known vulnerabilities in edge devices remain a preferred entry point, consistent with broader ASD guidance. If your exposure management has a service level for edge devices at all, it should be measured in days for internet-facing CVEs with known exploitation, not in quarters.
  4. Watch for the exfiltration stage, not just encryption. Bulk compression followed by rclone traffic is a detection opportunity that arrives before any files are locked — the difference between an incident and a disaster. Egress monitoring and alerting on unusual uploads from servers (rclone from a file server is a strong signal by itself) can buy hours of lead time, and hours is what you need to pull the network segment off.
  5. Test restoration. Immutable, offline-tested backups remain the difference between a bad week and a catastrophic month, particularly for services with patient-safety implications. A backup that has never been restored under time pressure is a hypothesis, not a control.
  6. Report early. The ACSC responds to incidents and can be reached around the clock on 1300 CYBER1 (1300 292 371). Early reporting feeds the joint advisories that warn the rest of the sector — the document this post is built on exists because organisations reported. If personal information is exposed, notifiable breach obligations run through the OAIC; see our explainer on Australia's data breach notification scheme.

For smaller practices without a security team, the first two items do most of the work. MFA on the remote-access path and a quarterly account review are within reach of any practice manager with an afternoon and a managed IT provider; a SOC is not a prerequisite for the controls this campaign actually respects.

The lesson from the INC Ransom advisory is not that the threat is sophisticated beyond defence; it is that health organisations are being chosen because their basics are weak. Fixing identity controls, patch discipline and egress monitoring removes most of the runway this campaign depends on. The full advisory is written for general as well as technical readers, and New Zealand's NCSC carries the same guidance for trans-Tasman organisations that span both.

This post is general security guidance, not legal advice.

← All posts