Scope Systems cyber attack: resilience and risk lessons for mining IT teams
Reviewed by Tom Sullivan

First reported on MINING.com
30 Second Briefing
A ransomware attack on Perth-based Scope Systems’ Pronto Xi ERP cloud stack disrupted dozens of mining customers, including Northern Star Resources and Evolution Mining, in what MM‑ISAC’s Rob Labbe calls the broadest single third‑party cyber event the sector has seen. Scope says client servers were restored from backups and not directly accessed, but admits internal data was exfiltrated and has not disclosed the attack vector, raising questions about visibility at hypervisor, storage and backup layers. The incident spotlights how multi‑tenant vCenter/ESXi environments, VM cloning and snapshot abuse—already used by groups like Akira—could expose integrated exploration, production and maintenance data across more than 400 Pronto Xi‑reliant mining operations.
Technical Brief
- Scope reported the threat actor maintained network access for “less than 24 hours” before containment.
- Multi‑tenant vCenter/ESXi architecture means hypervisor‑level compromise could enable VM snapshotting, cloning or VMDK export without guest‑OS logs.
- Akira’s documented vCenter exploit path involved creating an attacker VM, powering down a domain controller, copying VMDKs, then mounting them to extract NTDS.dit and SYSTEM hives for offline credential cracking.
Our Take
With around 400 mining companies depending on Pronto Xi ERP and at least 180 of those historically tied to Scope Systems, the incident underlines how a single Perth-based integrator can represent a concentrated operational risk node for gold and critical‑mineral producers across multiple jurisdictions.
Australia features heavily in our Mining safety‑tagged coverage for physical hazards, but cyber incidents like this one show that operational safety for gold and critical‑mineral operations is now tightly coupled to the resilience of third‑party digital providers rather than just on‑site controls.
For operators such as Northern Star Resources and Evolution Mining, which run complex multi‑site gold portfolios, a compromise at an ERP specialist like Scope Systems can disrupt not only finance and inventory but also mine planning and maintenance scheduling, effectively turning a short network breach into a material production‑planning risk.
Prepared by collating external sources, AI-assisted tools, and Geomechanics.io’s proprietary mining database, then reviewed for technical accuracy & edited by our geotechnical team.
Related Articles
Related Industries & Products
Mining
Geotechnical software solutions for mining operations including CMRR analysis, hydrogeological testing, and data management.
CMRR-io
Streamline coal mine roof stability assessments with our cloud-based CMRR software featuring automated calculations, multi-scenario analysis, and collaborative workflows.
HYDROGEO-io
Comprehensive hydrogeological testing platform for managing, analysing, and reporting on packer tests, lugeon values, and hydraulic conductivity assessments.
GEODB-io
Centralised geotechnical data management solution for storing, accessing, and analysing all your site investigation and material testing data.


