Cyberattacks on Pharmacy, Brewer & UK Nursery

Show Links

In this episode of the Don’t Be A Sitting Duck Podcast, Leigh Kefford unpacks three alarming cyber incidents that reveal just how far attackers are willing to go:

  • Toowoomba Pharmacy Ransomware Attack – The Friendly Society Dispensary hit by the DragonForce group, with nearly 36GB of sensitive staff and patient data stolen.

  • Asahi Group Cyberattack in Japan – A global beverage giant forced to halt factory operations when IT systems collapsed, disrupting orders, shipping, and production.

  • UK Nursery Chain HackKido nurseries breached by hackers claiming to hold data on more than 8,000 children, including names, photos, and safeguarding reports.

These cases show a disturbing reality: no industry is off-limits, and cybercriminals are increasingly targeting healthcare, manufacturing, and even childcare. Leigh explains how the attacks unfolded, why they matter, and—most importantly—what actions your business can take to avoid becoming the next headline.

Key Takeaways

  • Ransomware gangs are moving toward double-extortion models, stealing and leaking data.

  • Cyber incidents don’t just hit IT systems—they can stop factories, disrupt supply chains, and cripple business operations.

  • Attackers are exploiting the most sensitive sectors, including childcare and healthcare, to pressure victims into paying.

  • Proactive measures like zero trust, 3-2-1 backups, vendor risk management, and incident response planning are critical.

Sources & Further Reading

What To Do Next

  • Book your free Empower Systems Assessmentnationalpc.com.au/empower

  • Listen to my audiobook: Sitting Duck – The Phone Call You Don’t Want to Receive → Available now on Spotify and leading audiobook platforms

  • Subscribe to the Don’t Be A Sitting Duck Podcast for daily insights

Episode Transcript

A regional Australian pharmacy becomes the victim of a ruthless ransomware gang, exposing tens of gigabytes of private health data. A top Japanese brewer halts its production lines when cyber attackers force core systems offline. And in the UK, a childcare provider has children’s names, photos, and safeguarding data held hostage — a chilling reminder that even our most vulnerable are not immune. These three incidents paint a clear picture: attackers are getting bolder, and no industry is off limits. Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford—let’s dive in.

In Toowoomba, the Friendly Society Dispensary was hit by DragonForce ransomware. The attackers claim to have exfiltrated ~35.82 GB of data, including staff and patient records.

How It Happened & Why It Matters
This is a classic double-extortion model: first encrypt systems, then publish stolen data to pressure payment. Healthcare data is highly sensitive — names, medical histories, prescriptions — and the fallout can include regulatory penalties, loss of trust, and long-term reputational damage.

Take Action
• Segment networks and isolate critical systems
• Use the 3-2-1 backup strategy and regularly test restores
• Apply least-privilege access and monitor for abnormal file access
• Conduct phishing training and simulated exercises
• Have ready incident response and forensic partners
• Report the incident quickly to law enforcement (AFP / ACSC)

In Japan, beverage giant Asahi suspended operations at its factories when a cyberattack took down its IT systems — order processing, shipping, and communications systems were all affected.

How It Happened & Why It Matters
While details are still emerging, the disruption suggests a breach of critical infrastructure — manufacturing, ERP, logistics. For Asahi, downtime isn’t just an IT problem — it ripples through supply chains, customer commitments, and brand trust. Cyber threats are evolving beyond data theft into operational sabotage.

Take Action
Map your system dependencies and conduct “blast radius” analysis
Enforce strict IT/OT network segmentation
Deploy anomaly detection and behavioural analytics, especially in ICS/OT environments
Prioritise patching for core infrastructure
Build redundancies and fallback processes
Run regular drills simulating full system outages

In London and across the UK, the Kido nursery chain (operating ~18 sites) was breached by hackers calling themselves Radiant. They claim to have stolen data on more than 8,000 children — names, photos, addresses, safeguarding reports, family contact data — and have already published some samples (10 children) as proof.

How It Happened & Why It Matters
The attackers say the breach stemmed from third-party systems (notably the Famly app used by many nurseries), though Famly denies any compromise.

Hackers claim they’ve been in Kido’s infrastructure for weeks. They’re now threatening to leak more — 30 more profiles per child plus 100 staff member records — unless demands are met.

This attack is especially jarring because it targets children and caregivers — “low-hanging fruit” in the eyes of criminals. It underscores how attackers are willing to exploit the emotional and moral boundaries to force payment.

Take Action
Treat every third-party / vendor system as a potential attack vector; demand strong security assurances, audits, and logs
Use zero-trust architecture — never automatically trust internal or external systems
Monitor for unusual access or data exfiltration, especially in environments containing sensitive personal data
Segment and vault highly sensitive data (e.g. safeguarding, child records)
Perform regular penetration tests, including by third-party systems
Prepare legal, communication, and disclosure plans (especially when vulnerable populations are involved)
Engage early with regulators, data protection authorities, and law enforcement

That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.

Until next time—stay safe, stay informed, and don’t be a sitting duck!

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.