Powered by MOMENTUM MEDIA
  • subs-bellGet the latest news! Subscribe to the ifa bulletin

Iress denies statements made by ‘threat actor’ following data breach

Iress has issued an update denying the validity of “certain statements” made today by an alleged threat actor.

In an ASX announcement on Friday morning, Iress said it has become aware of “certain statements made today by the alleged threat actor”. The update comes after the technology firm confirmed that the incident involving the unauthorised access reported on Monday extends to OneVue.

“The statements made today do not align with the investigations made by Iress to date,” it said.

“Iress refers shareholders to announcements previously made. Investigations are ongoing and we will continue to keep the market informed.”

At the present moment, it is unclear what statements Iress is referring to.

ifa has contacted the firm for more information.

Momentum Media’s Cyber Daily senior journalist David Hollingworth said he is not aware of any threats publicly made in connection to the Iress breach.

==
==

On Wednesday, Iress said that during its investigation regarding the earlier reported unauthorised access to its user space on GitHub, it discovered that a credential within Iress’ GitHub user space was stolen and used to gain access to the OneVue production environment.

While this production environment is isolated to the OneVue businesses – MFA, Platform and OneVue Super – it contains client data, Iress confirmed.

It added that it is investigating the “extent and nature of the data accessed”.

“Investigations have substantially progressed across Iress’ other business lines and at this time, we have found no evidence that the remainder of Iress’ production environment, software or client data has otherwise been compromised,” the firm said.

“Iress will continue to keep the market informed as the investigation continues.”