IronSights

Free tool · Updated weekly

The Australian data breach tracker.

A running list of the data breaches, ransomware attacks and extortion cases hitting Australian organisations. Search it, filter it, and see which sectors and groups are most active right now.

Each entry is checked before it appears here. Where an incident is only an attacker's claim and the organisation has not confirmed it, we label it as claimed rather than reporting it as fact.

46

Incidents tracked

8

In the last 30 days

Other

Most affected sector

Storm

Most active group

46 incidents

  1. Investigating

    DigiGround

    Technology / App Development

    The Qilin ransomware group has listed the Sydney-based bespoke app developer DigiGround on its darknet leak site, but the company says it has so far found no evidence that its systems or data were compromised and is treating the claim as unverified while it investigates.

    Threat actor
    Qilin ransomware group
    Attack type
    Ransomware (leak-site claim)
  2. Confirmed

    Sharp Motor Group

    Automotive retail

    The Storm ransomware group listed the Tweed Heads-based Sharp Motor Group on its leak site on 23 August, publishing files it claims were stolen; the dealership has confirmed its third-party IT provider was involved in a cyber incident and is actively investigating, but has not verified the attacker's claims about the scope of data stolen.

    Threat actor
    Storm
    Attack type
    Ransomware / third-party (supply chain) compromise

    Data exposed

    Employee passport and driver's licence scansFinancial dataCustomer invoicesPasswords and user IDs
  3. Confirmed

    Hachette Australia & New Zealand / Alliance Distribution Services (ADS)

    Publishing / logistics

    Hachette Australia confirmed that its distribution subsidiary, Alliance Distribution Services, detected unauthorised activity on its computer systems believed to have begun on 18 July, severely disrupting national book distribution; the company has notified authorities but has not disclosed whether data was compromised or named an attacker.

    Attack type
    Unauthorised network access (suspected ransomware)
  4. Confirmed

    Oz Hair and Beauty

    Retail (beauty and personal care e-commerce)

    Oz Hair and Beauty confirmed that its online purchase and order platform was briefly accessed by an unauthorised third party, with limited personal information tied to purchases made before August 2026 affected. The xpl0itrs group has separately claimed on a dark web leak site to have obtained about 2.1 million customer records, a figure the retailer has not confirmed.

    Threat actor
    xpl0itrs
    Attack type
    Data breach via unauthorised access to online ordering platform (cyber extortion/leak)

    Data exposed

    namesemail addressesorder/purchase details
  5. Confirmed

    Quest Apartment Hotels

    Hospitality

    Quest Apartment Hotels confirmed that unauthorised access to a database system operated by a third-party service provider compromised guests' names, emails and dates of birth, and warned customers to watch for scam attempts.

    Attack type
    Third-party/supply chain breach

    Data exposed

    NamesEmail addressesDates of birth
  6. Claimed

    Ramsey Bros

    Agriculture / farm machinery distribution

    The newly emerged Storm ransomware group has listed South Australian farm machinery supplier Ramsey Bros as a victim on its leak site, publishing sample documents and threatening full data release on 4 September; the company has not confirmed the intrusion.

    Threat actor
    Storm
    Attack type
    Ransomware / data theft

    Data exposed

    InvoicesCustomer correspondenceVehicle inspection reportsVehicle identification numbersDriver details and contact information
  7. Claimed

    Mighty Kingdom

    Video game development

    The Direwolf ransomware group has claimed on its darknet leak site to have accessed more than 260 code repositories belonging to Adelaide-based game studio Mighty Kingdom; the claim is unverified by the company.

    Threat actor
    Direwolf
    Attack type
    Ransomware / data theft

    Data exposed

    Source codeCode repositories
  8. Claimed

    Westco Motors Cairns

    Automotive retail

    The Storm ransomware group publicly claimed responsibility for an attack on Queensland automotive dealership Westco Motors Cairns, posting a notice threatening to leak stolen data unless negotiations occur; the dealership has not publicly confirmed the incident.

    Threat actor
    Storm
    Attack type
    Ransomware (leak-site claim)

    Data exposed

    customer databusiness data
  9. Claimed

    LR Reed

    Other

    The Kairos group listed Melbourne property management firm LR Reed, claiming 335 gigabytes of data. LR Reed said it was aware of the claims and investigating, had notified the Australian Signals Directorate and AFP, and believed customer data was safe.

    Threat actor
    Kairos
    Attack type
    Data theft / extortion
    Scale
    Attacker claims 335 GB
  10. Confirmed

    GO2 Health

    Healthcare

    Brisbane clinic GO2 Health confirmed a limited data breach after its main mailbox was accessed in April through a phishing attack, exposing information in the prior year's emails including some patients' Department of Veterans' Affairs ID numbers. Its main patient records system was not accessed; patients were notified almost three months later.

    Attack type
    Email compromise (phishing)

    Data exposed

    Email contentsDepartment of Veterans' Affairs ID numbers
  11. Investigating

    Origin Energy

    Energy & utilities

    Origin told the ASX it was investigating potential unauthorised access to customer data. An individual emailed the extortion demand to 7NEWS, gave The Australian a 50-record sample, and started a 14-day public countdown. Origin says it does not believe credit card or bank details were involved.

    Attack type
    Data theft & extortion
    Scale
    Attacker claims 2M+ customer records; Origin has ~4.8M accounts

    Data exposed

    NamesContact detailsDates of birthBilling history
  12. Confirmed

    Partnered Health

    Healthcare

    GP network Partnered Health disclosed on 15 July that a malicious actor had accessed its network around 23 June, potentially compromising patient data across roughly 21 clinics. Exposed information may include Medicare numbers, Veteran Card numbers, private health insurance details and medical records.

    Attack type
    Cyber attack
    Scale
    Around 21 clinics

    Data exposed

    NamesDates of birthAddressesMedicare numbersVeteran Card / DVA numbersPrivate health insurance detailsMedical information
  13. Confirmed

    Royal Foods

    Food & agriculture

    Queensland gourmet food supplier Royal Foods confirmed it was investigating an incident in which an unauthorised third party accessed part of its internal IT environment. The Gentlemen ransomware group, also behind the Mackay Sugar attack, listed the company on 7 July.

    Threat actor
    The Gentlemen
    Attack type
    Ransomware
  14. Confirmed

    Lifeline

    Not-for-profit

    Lifeline confirmed staff and volunteer data was accessed and posted to a forum for free by an actor using the handle 2019. Some of the released data was found to be falsified. Lifeline says no help-seeker data or financial information was compromised.

    Threat actor
    2019
    Attack type
    Data theft (free leak)
    Scale
    10,600+ staff and volunteer records claimed

    Data exposed

    NamesEmail addressesDates of birthClient IDsPhone numbers
  15. Claimed

    AC Small Maxwell & Co

    Professional services

    Threat actors linked to SafePay claimed a cyber attack on NSW accounting and advisory firm AC Small Maxwell & Co, threatening to leak allegedly stolen data.

    Threat actor
    SafePay
    Attack type
    Ransomware
  16. Confirmed

    Generation Life

    Financial services

    Investment firm Generation Life confirmed customer information was affected by a cyber incident first identified in April, involving an attacker reaching its systems through a third-party provider. It said the issue was contained and client investments and funds remained secure.

    Attack type
    Third-party breach
  17. Investigating

    NSW Rural Fire Service

    Government

    The NSW Rural Fire Service said historical data was likely compromised in a security incident, while its operational response was unaffected. The Nova ransomware group declared the breach in mid-June and shared samples; it is understood to have involved a third-party vendor supporting RFS radio and telecommunications infrastructure.

    Threat actor
    Nova
    Attack type
    Third-party breach / ransomware
  18. Investigating

    Elina Medical Weight Loss Clinic

    Healthcare

    Melbourne clinic Elina Medical Weight Loss said it was investigating after the actor 2019 claimed to have stolen data on more than 28,000 patients. Two of the clinic's HotDoc accounts were accessed by an unknown third party; the clinic said the incident was contained and activity was limited to those accounts.

    Threat actor
    2019
    Attack type
    Account compromise
    Scale
    Actor claims data on 28,000+ patients
  19. Confirmed

    Kennedy McLaughlin

    Professional services

    Brisbane accounting firm Kennedy McLaughlin confirmed a cyber incident after a Qilin ransomware affiliate listed it and published a dataset including clients' financial details. The firm notified affected individuals, the ACSC and the OAIC.

    Threat actor
    Qilin
    Attack type
    Ransomware

    Data exposed

    Client financial dataBanking details
  20. Confirmed

    Ochre Health (Tuggeranong)

    Healthcare

    Ochre Health confirmed that patient data from its Tuggeranong clinic was potentially compromised after an actor using the handle 2019 breached a third-party provider. Records of more than 25,000 patients, including Medicare and DVA numbers, were offered for sale on a hacking forum.

    Threat actor
    2019
    Attack type
    Third-party breach / data theft
    Scale
    More than 25,000 patients

    Data exposed

    Medicare numbersDVA numbersPatient records
  21. Confirmed

    Goodstone Group

    Other

    Tasmanian hospitality group Goodstone Group, which runs hotels, bars and bottleshops around Devonport, confirmed a ransomware attack by the newly emerged CMD Organization. The group published evidence including employee passport scans and bank reconciliation records.

    Threat actor
    CMD Organization
    Attack type
    Ransomware

    Data exposed

    Employee passportsBank reconciliation details
  22. Confirmed

    Mackay Sugar

    Food & agriculture

    A ransomware attack claimed by The Gentlemen forced two of Mackay Sugar's three Queensland mills offline at the start of the cane crushing season, halting harvesting across around 1,300 family farms. The company ran limited manual crushing while restoring systems.

    Threat actor
    The Gentlemen
    Attack type
    Ransomware
    Scale
    Operational disruption; two of three mills offline
  23. Confirmed

    Melbourne International Film Festival

    Not-for-profit

    About 26,782 Melbourne International Film Festival customer records were exposed after its third-party ticketing platform Ferve was breached. MIFF disputed a threat actor's separate claim of 340,000 affected customers, saying its database does not hold that many records.

    Attack type
    Third-party breach (Ferve ticketing)
    Scale
    About 26,782 customer records

    Data exposed

    NamesEmail addressesPhone numbersResidential addresses
  24. Investigating

    Australian Computer Society

    Not-for-profit

    The Australian Computer Society said it was investigating a possible breach after ShinyHunters claimed to have accessed its data.

    Threat actor
    ShinyHunters
    Attack type
    Data breach (claimed)
  25. Confirmed

    Tripod Farmers Group

    Food & agriculture

    The Qilin ransomware group listed the fresh-produce supplier Tripod Farmers after unauthorised access detected around February. The company confirmed a breach affecting part of its systems but said production and customer operations were not disrupted.

    Threat actor
    Qilin
    Attack type
    Ransomware / data theft
    Scale
    Part of systems affected
  26. Confirmed

    Queensland Department of Education

    Government

    The Queensland Department of Education confirmed students and staff were affected by a breach of Instructure, the third-party provider behind its QLearn platform. The ShinyHunters group claimed the data and set a ransom deadline. Exposed fields included names, email addresses and school locations.

    Threat actor
    ShinyHunters
    Attack type
    Third-party breach (Instructure / QLearn)

    Data exposed

    NamesEmail addressesSchool locations
  27. Confirmed

    Champion Homes

    Other

    Sydney home builder Champion Homes confirmed a cyber attack that exposed a limited amount of employee and customer data. The DragonForce ransomware group had listed the company on 21 April and published a roughly 44 gigabyte dataset.

    Threat actor
    DragonForce
    Attack type
    Ransomware
    Scale
    Attacker published ~44 GB
  28. Investigating

    Gregory Jewellers

    Retail & consumer

    Fine jewellery retailer Gregory Jewellers said it was investigating after the Kairos group claimed on 22 April to have stolen about 574 gigabytes of data. The company had not confirmed whether customer or employee information was affected.

    Threat actor
    Kairos
    Attack type
    Ransomware / data theft
    Scale
    Attacker claims 574 GB
  29. Resolved

    Scope Systems

    Technology

    Perth-based Scope Systems, an IT provider to the mining sector, confirmed a malicious actor accessed its network for under 24 hours, disrupting hosted services including Pronto Xi. The company said no data loss occurred and no group claimed responsibility.

    Attack type
    Cyber incident (service disruption)
  30. Confirmed

    ALS Global

    Professional services

    Testing and inspection firm ALS Global disclosed a cyber incident in May. In June the Aur0ra group published employee data, banking details and testing records to the dark web.

    Threat actor
    Aur0ra
    Attack type
    Ransomware / data theft

    Data exposed

    Employee dataBanking detailsPasswordsTesting records
  31. Claimed

    Earth Systems

    Professional services

    The INC Ransom group listed environmental and engineering consultancy Earth Systems, claiming around 600 gigabytes of stolen data.

    Threat actor
    INC Ransom
    Attack type
    Ransomware / data theft
    Scale
    Attacker claims around 600 GB
  32. Claimed

    Energy Action

    Energy & utilities

    The SafePay ransomware group listed the energy-management consultancy Energy Action on its leak site, claiming roughly 470 GB of stolen data. Energy Action says it manages more than 10 per cent of Australia's commercial energy spend, so the data reaches many corporate clients.

    Threat actor
    SafePay
    Attack type
    Ransomware / data theft
    Scale
    Attacker claims ~470 GB of data

    Data exposed

    Commercial contractsUsage dataAccount information
  33. Confirmed

    NSW Government (Treasury)

    Government

    A NSW Treasury staff member was charged after internal monitoring detected the alleged transfer of more than 5,600 restricted government documents to an external server. The NSW Government declared a significant cyber incident; the data was later located and secured, and there was no evidence of an external hack.

    Attack type
    Insider data breach
    Scale
    More than 5,600 documents
  34. Confirmed

    Bendigo & District Aboriginal Co-operative

    Not-for-profit

    The Bendigo & District Aboriginal Co-operative, which delivers health, education and community services to the Dja Dja Wurrung community, confirmed a cyber incident after being listed by INC Ransom. It said the incident was detected and secured the same day, limiting impact.

    Threat actor
    INC Ransom
    Attack type
    Ransomware
  35. Investigating

    Mastercom

    Telecommunications

    The INC Ransom group listed Granville, NSW communications firm Mastercom, which operates Australia's largest commercial two-way radio network, and published customer, HR and financial data. Mastercom said it was aware of the claims.

    Threat actor
    INC Ransom
    Attack type
    Ransomware

    Data exposed

    Customer dataHR dataFinancial data
  36. Confirmed

    Smile Team Orthodontics

    Healthcare

    The SafePay ransomware group listed NSW dental practice Smile Team Orthodontics and published stolen data, including staff details, personal emails, medical certificates and hundreds of DentiCare patient payment plans. The practice notified the OAIC and the ACSC.

    Threat actor
    SafePay
    Attack type
    Ransomware

    Data exposed

    Staff listingsHome addressesPersonal emailsMedical certificatesPatient payment plans
  37. Confirmed

    Hazeldenes

    Food & agriculture

    A February cyber attack on major Victorian poultry processor Hazeldenes caused production disruption and regional chicken shortages. In March the DragonForce ransomware group published a roughly 79 gigabyte dataset stolen from the company to its leak site.

    Threat actor
    DragonForce
    Attack type
    Ransomware
    Scale
    Attacker published ~79 GB
  38. Confirmed

    Australian federal and state courts (via VIQ Solutions)

    Government / justice (third-party transcription services)

    Canadian transcription provider VIQ Solutions confirmed a security incident that exposed sensitive Australian court files after it subcontracted work to an Indian firm, e24 Technologies, allegedly in breach of its Commonwealth contracts. Exposed material reportedly included documents from the Federal Circuit and Family Court and the Federal Court.

    Attack type
    Third-party / supply-chain data exposure

    Data exposed

    court filesFederal Circuit and Family Court documentsFederal Court documents
  39. Confirmed

    youX

    Financial services (fintech / asset finance)

    Sydney-based finance-broking platform youX confirmed unauthorised access to its systems after a threat actor released data it claims to have taken from an unsecured database. youX acknowledged personal information of borrowers may have been compromised; the attacker claims to hold roughly 141GB covering about 444,538 borrowers and has threatened staged release unless paid.

    Attack type
    Data breach and extortion (unsecured MongoDB Atlas cluster)
    Scale
    444,538 borrowers

    Data exposed

    loan applicationsdriver's licencesresidential addressesincome and debt detailsgovernment identifiersbroker banking detailspassword hashes
  40. Confirmed

    youX

    Financial services

    Sydney fintech platform youX confirmed a data breach exposing the personal and financial records of 444,538 Australians. The actor FulcrumSec claimed to have taken data spanning roughly 629,597 loan applications and hundreds of broker organisations.

    Threat actor
    FulcrumSec
    Attack type
    Data breach
    Scale
    444,538 people; ~629,597 loan applications

    Data exposed

    Financial detailsDriver's licencesResidential addressesLoan applications
  41. Confirmed

    Seagrass Boutique Hospitality Group

    Other

    Seagrass Boutique Hospitality Group, the operator behind restaurant brands including The Meat & Wine Co and Hunter Barrel, confirmed a cyber incident involving unauthorised access to part of its network. The Kairos ransomware group claimed the attack on 12 February.

    Threat actor
    Kairos
    Attack type
    Ransomware
  42. Confirmed

    Aeromedical Society of Australasia

    Not-for-profit

    The LockBit ransomware operation listed the Aeromedical Society of Australasia, an air-medical transport body for Australia and New Zealand, in an 11 February leak post and threatened to publish data. The society confirmed it was aware of a cyber incident.

    Threat actor
    LockBit
    Attack type
    Ransomware
  43. Claimed

    Ansell Limited

    Manufacturing

    The 0apt group claimed a cyber attack on protective-equipment manufacturer Ansell Limited, threatening to release material it said included product formulas and supply-chain contracts.

    Threat actor
    0apt
    Attack type
    Ransomware / data theft
  44. Confirmed

    Victorian Department of Education

    Government

    Attackers reached a Victorian Department of Education database through a school's network, accessing names, email addresses, encrypted passwords and school details of current and former students across all 1,700 government schools. The department said home addresses, dates of birth and staff records were not accessed, and there was no evidence the data had been published.

    Attack type
    Unauthorised access via a school network
    Scale
    Current and former students across all ~1,700 government schools

    Data exposed

    NamesEmail addressesEncrypted passwordsYear levelSchool
  45. Confirmed

    Prosura

    Financial services

    Rental car insurer Prosura, which also trades as Hiccup, confirmed a cyber incident after attackers accessed its systems around 1 January and began contacting customers. Data on an estimated 300,000 customers, including driver's licences and claim details, was later offered for sale. Prosura said credit card details were not accessed.

    Attack type
    Data breach
    Scale
    Around 300,000 customers

    Data exposed

    NamesEmail addressesPhone numbersTravel detailsPolicy dataDriver's licences
  46. Resolved

    Regis Resources

    Other

    ASX-listed gold producer Regis Resources confirmed a cyber incident first detected in mid-November 2025, after the Lynx ransomware group listed its McPhillamys Gold subsidiary on 5 January 2026. Automated isolation contained the intrusion, and a forensic investigation found no data was stolen and no ransom demand was made.

    Threat actor
    Lynx
    Attack type
    Attempted ransomware (contained)

For your own organisation

The tracker shows what was disclosed. It cannot show what is circulating.

Credentials and data stolen from Australian businesses are traded through criminal marketplaces, hacker forums, Telegram channels and combolists, often months before a public disclosure and sometimes without one ever being made. A quiet result above says nothing about what is out there for your domain.

Ask us to run a dark web exposure search on your organisation. An analyst runs it, and you get a plain-English summary of what we found and what to do about it.

Request a dark web search

About this list

This tracker is compiled from public reporting and official disclosures and is provided on a best-effort basis for general information only. Entries may contain errors or omissions, and details often change as incidents are investigated. Each entry links to its source so you can check the original report.

Where an incident reflects an unverified claim by an attacker and the organisation has not confirmed it, we label it claimed rather than stating it as fact. IronSights is not affiliated with, and does not endorse or make any allegation against, the organisations listed. If you represent a listed organisation and would like a correction or removal, contact us and we will review it promptly.

If you are the one on the list

A breach is a bad week, not the end of one.

If your organisation is dealing with an incident right now, our Australian incident response team is available around the clock. The first hours decide how much can be saved.

Do we have to report it? Unauthorised access to personal information that is likely to cause serious harm has to be assessed within 30 days. Our guide to the Notifiable Data Breaches scheme covers the assessment and the statement, and the wider Australian cyber obligations hub covers the rest.

Nothing was encrypted, they just took data. That is extortion without encryption, and there is nothing to restore. See data theft extortion response.

Our files are locked. Start with ransomware recovery, which measures what survived before anyone talks about paying.