Northern Minerals mines and develops heavy rare earth elements like dysprosium and terbium. These materials end up used in electronics, batteries, and aircraft.
The miner revealed the threat actors stole data from its systems in late March and then published it on the dark web.
“Northern Minerals Limited (ASX: NTU) (Northern Minerals or Company) advises that it has been the subject of a cyber security breach and was today (June 4) advised by its cyber security consultant that some of the exfiltrated data has now been released on the dark web.
“Northern Minerals became aware in late March 2024 of the breach. In line with the Company’s governance practices and protocols, Northern Minerals immediately notified external stakeholders including the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. In addition, the Company engaged appropriate legal, technical and cyber security specialists to assist with the process.
“The exfiltrated data included corporate, operational and financial information and some details relating to current and former personnel and some shareholder information. The process of notifying relevant impacted individuals is underway and ongoing.
“The breach has not had a material impact on the Company’s operations or broader systems. Since the breach, the Company has reviewed its processes and implemented actions to further strengthen its systems,” the statement said.
The BianLian ransomware group claimed responsibility for the attack by adding Northern Minerals to its extortion page on the dark web, according to a BleepingComputer report.
This group started to move toward data-theft-based extortion over ransomware.
Within the release of data, it appears the victim refused to pay a ransom demand.

