Latitude Financial says it won't pay ransomware fee

Latitude Financial, an Australian consumer finance firm, has said that it will refuse to pay a ransomware fee after being attacked last month.

In a statement published on Tuesday, the firm said that its stance is "consistent with the position of the Australian government" and that paying the fee would "be detrimental to our customers and cause harm to the broader community by encouraging further criminal attacks."

The company last month confirmed that hackers had stolen nearly 8 million drivers licence numbers from customers in Australia and New Zealand in what was one of the country’s biggest confirmed data breaches. It said that it does not believe that paying a ransom will result in the return or destruction of the stolen information.

Latitude Financial, which provides consumer finance services to retailers including Harvey Norman and JB Hi-Fi, has taken its platforms offline in the period since the attack.

In a statement, the company said that it is in the process of contacting all affected customers, past and present, and that it will complete its support and remediation processes “as quickly as we can.”

Commenting on the update, Latitude Financial chief executive officer Bob Belan said: "Latitude will not pay a ransom to criminals. Based on the evidence and advice, there is simply no guarantee that doing so would result in any customer data being destroyed and it would only encourage further extortion attempts on Australian and New Zealand businesses in the future.

"I apologise personally and sincerely for the distress that this cyber-attack has caused and I hope that in time we are able to earn back the confidence of our customers."

    Share Story:

Recent Stories


The human firewall: Activating employees to safeguard financial data
As financial services increasingly embrace SaaS and cloud-based technologies, they face emerging threats to safeguard sensitive customer data. While comprehensive IT security measures are essential, the active involvement of employees across organisations is pivotal in ensuring the protection of sensitive data.

Building a secure financial future for instant payments: The convergence of ISO 20022 and fraud detection
The financial landscape is rapidly evolving its approach to real-time transactions under the ISO 20022 standard, and financial institutions must take note. With examples such as the accelerated adoption of SEPA Instant Credit Transfers in Europe and proposed New Payment Architecture (NPA) programme in the UK, the need for swift and effective fraud detection is more crucial than ever.

Data Streaming and Consumer Duty: Transforming customer experience in banking
Introduced at the end of July, the Consumer Duty is a game-changing new set of rules and guidance for financial services institutions in the UK, and companies must look to modernise their systems in adherence with it in mind to create the best customer experience possible.

From insight to action: Empowering financial institutions through advanced technology and collaborative information sharing
The use of Information sharing in enhancing financial crime prevention has been universally agreed as being beneficial. However no-one has been able to agree on how information can be shared safely without breaching data protection laws or having the right systems to facilitate this, Information sharing has re-emerged as a major consideration for financial institutions (FIs) ahead of the Economic Crime and Corporate Transparency Bill being made into law in the UK.