IronSights

Free tool · Updated daily

The Australian data breach tracker.

A running list of the data breaches, ransomware attacks and extortion cases hitting Australian organisations. Search it, filter it, and see which sectors and groups are most active right now.

Each entry is checked before it appears here. Where an incident is only an attacker's claim and the organisation has not confirmed it, we label it as claimed rather than reporting it as fact.

36

Incidents tracked

6

In the last 30 days

Other

Most affected sector

Kairos

Most active group

36 incidents

  1. Claimed

    LR Reed

    Other

    The Kairos group listed Melbourne property management firm LR Reed, claiming 335 gigabytes of data. LR Reed said it was aware of the claims and investigating, had notified the Australian Signals Directorate and AFP, and believed customer data was safe.

    Threat actor
    Kairos
    Attack type
    Data theft / extortion
    Scale
    Attacker claims 335 GB
  2. Confirmed

    GO2 Health

    Healthcare

    Brisbane clinic GO2 Health confirmed a limited data breach after its main mailbox was accessed in April through a phishing attack, exposing information in the prior year's emails including some patients' Department of Veterans' Affairs ID numbers. Its main patient records system was not accessed; patients were notified almost three months later.

    Attack type
    Email compromise (phishing)

    Data exposed

    Email contentsDepartment of Veterans' Affairs ID numbers
  3. Investigating

    Origin Energy

    Energy & utilities

    Origin told the ASX it was investigating potential unauthorised access to customer data. An individual emailed the extortion demand to 7NEWS, gave The Australian a 50-record sample, and started a 14-day public countdown. Origin says it does not believe credit card or bank details were involved.

    Attack type
    Data theft & extortion
    Scale
    Attacker claims 2M+ customer records; Origin has ~4.8M accounts

    Data exposed

    NamesContact detailsDates of birthBilling history
  4. Confirmed

    Partnered Health

    Healthcare

    GP network Partnered Health disclosed on 15 July that a malicious actor had accessed its network around 23 June, potentially compromising patient data across roughly 21 clinics. Exposed information may include Medicare numbers, Veteran Card numbers, private health insurance details and medical records.

    Attack type
    Cyber attack
    Scale
    Around 21 clinics

    Data exposed

    NamesDates of birthAddressesMedicare numbersVeteran Card / DVA numbersPrivate health insurance detailsMedical information
  5. Confirmed

    Royal Foods

    Food & agriculture

    Queensland gourmet food supplier Royal Foods confirmed it was investigating an incident in which an unauthorised third party accessed part of its internal IT environment. The Gentlemen ransomware group, also behind the Mackay Sugar attack, listed the company on 7 July.

    Threat actor
    The Gentlemen
    Attack type
    Ransomware
  6. Confirmed

    Lifeline

    Not-for-profit

    Lifeline confirmed staff and volunteer data was accessed and posted to a forum for free by an actor using the handle 2019. Some of the released data was found to be falsified. Lifeline says no help-seeker data or financial information was compromised.

    Threat actor
    2019
    Attack type
    Data theft (free leak)
    Scale
    10,600+ staff and volunteer records claimed

    Data exposed

    NamesEmail addressesDates of birthClient IDsPhone numbers
  7. Claimed

    AC Small Maxwell & Co

    Professional services

    Threat actors linked to SafePay claimed a cyber attack on NSW accounting and advisory firm AC Small Maxwell & Co, threatening to leak allegedly stolen data.

    Threat actor
    SafePay
    Attack type
    Ransomware
  8. Confirmed

    Generation Life

    Financial services

    Investment firm Generation Life confirmed customer information was affected by a cyber incident first identified in April, involving an attacker reaching its systems through a third-party provider. It said the issue was contained and client investments and funds remained secure.

    Attack type
    Third-party breach
  9. Investigating

    NSW Rural Fire Service

    Government

    The NSW Rural Fire Service said historical data was likely compromised in a security incident, while its operational response was unaffected. The Nova ransomware group declared the breach in mid-June and shared samples; it is understood to have involved a third-party vendor supporting RFS radio and telecommunications infrastructure.

    Threat actor
    Nova
    Attack type
    Third-party breach / ransomware
  10. Investigating

    Elina Medical Weight Loss Clinic

    Healthcare

    Melbourne clinic Elina Medical Weight Loss said it was investigating after the actor 2019 claimed to have stolen data on more than 28,000 patients. Two of the clinic's HotDoc accounts were accessed by an unknown third party; the clinic said the incident was contained and activity was limited to those accounts.

    Threat actor
    2019
    Attack type
    Account compromise
    Scale
    Actor claims data on 28,000+ patients
  11. Confirmed

    Kennedy McLaughlin

    Professional services

    Brisbane accounting firm Kennedy McLaughlin confirmed a cyber incident after a Qilin ransomware affiliate listed it and published a dataset including clients' financial details. The firm notified affected individuals, the ACSC and the OAIC.

    Threat actor
    Qilin
    Attack type
    Ransomware

    Data exposed

    Client financial dataBanking details
  12. Confirmed

    Ochre Health (Tuggeranong)

    Healthcare

    Ochre Health confirmed that patient data from its Tuggeranong clinic was potentially compromised after an actor using the handle 2019 breached a third-party provider. Records of more than 25,000 patients, including Medicare and DVA numbers, were offered for sale on a hacking forum.

    Threat actor
    2019
    Attack type
    Third-party breach / data theft
    Scale
    More than 25,000 patients

    Data exposed

    Medicare numbersDVA numbersPatient records
  13. Confirmed

    Goodstone Group

    Other

    Tasmanian hospitality group Goodstone Group, which runs hotels, bars and bottleshops around Devonport, confirmed a ransomware attack by the newly emerged CMD Organization. The group published evidence including employee passport scans and bank reconciliation records.

    Threat actor
    CMD Organization
    Attack type
    Ransomware

    Data exposed

    Employee passportsBank reconciliation details
  14. Confirmed

    Mackay Sugar

    Food & agriculture

    A ransomware attack claimed by The Gentlemen forced two of Mackay Sugar's three Queensland mills offline at the start of the cane crushing season, halting harvesting across around 1,300 family farms. The company ran limited manual crushing while restoring systems.

    Threat actor
    The Gentlemen
    Attack type
    Ransomware
    Scale
    Operational disruption; two of three mills offline
  15. Confirmed

    Melbourne International Film Festival

    Not-for-profit

    About 26,782 Melbourne International Film Festival customer records were exposed after its third-party ticketing platform Ferve was breached. MIFF disputed a threat actor's separate claim of 340,000 affected customers, saying its database does not hold that many records.

    Attack type
    Third-party breach (Ferve ticketing)
    Scale
    About 26,782 customer records

    Data exposed

    NamesEmail addressesPhone numbersResidential addresses
  16. Investigating

    Australian Computer Society

    Not-for-profit

    The Australian Computer Society said it was investigating a possible breach after ShinyHunters claimed to have accessed its data.

    Threat actor
    ShinyHunters
    Attack type
    Data breach (claimed)
  17. Confirmed

    Tripod Farmers Group

    Food & agriculture

    The Qilin ransomware group listed the fresh-produce supplier Tripod Farmers after unauthorised access detected around February. The company confirmed a breach affecting part of its systems but said production and customer operations were not disrupted.

    Threat actor
    Qilin
    Attack type
    Ransomware / data theft
    Scale
    Part of systems affected
  18. Confirmed

    Queensland Department of Education

    Government

    The Queensland Department of Education confirmed students and staff were affected by a breach of Instructure, the third-party provider behind its QLearn platform. The ShinyHunters group claimed the data and set a ransom deadline. Exposed fields included names, email addresses and school locations.

    Threat actor
    ShinyHunters
    Attack type
    Third-party breach (Instructure / QLearn)

    Data exposed

    NamesEmail addressesSchool locations
  19. Confirmed

    Champion Homes

    Other

    Sydney home builder Champion Homes confirmed a cyber attack that exposed a limited amount of employee and customer data. The DragonForce ransomware group had listed the company on 21 April and published a roughly 44 gigabyte dataset.

    Threat actor
    DragonForce
    Attack type
    Ransomware
    Scale
    Attacker published ~44 GB
  20. Investigating

    Gregory Jewellers

    Retail & consumer

    Fine jewellery retailer Gregory Jewellers said it was investigating after the Kairos group claimed on 22 April to have stolen about 574 gigabytes of data. The company had not confirmed whether customer or employee information was affected.

    Threat actor
    Kairos
    Attack type
    Ransomware / data theft
    Scale
    Attacker claims 574 GB
  21. Resolved

    Scope Systems

    Technology

    Perth-based Scope Systems, an IT provider to the mining sector, confirmed a malicious actor accessed its network for under 24 hours, disrupting hosted services including Pronto Xi. The company said no data loss occurred and no group claimed responsibility.

    Attack type
    Cyber incident (service disruption)
  22. Confirmed

    ALS Global

    Professional services

    Testing and inspection firm ALS Global disclosed a cyber incident in May. In June the Aur0ra group published employee data, banking details and testing records to the dark web.

    Threat actor
    Aur0ra
    Attack type
    Ransomware / data theft

    Data exposed

    Employee dataBanking detailsPasswordsTesting records
  23. Claimed

    Earth Systems

    Professional services

    The INC Ransom group listed environmental and engineering consultancy Earth Systems, claiming around 600 gigabytes of stolen data.

    Threat actor
    INC Ransom
    Attack type
    Ransomware / data theft
    Scale
    Attacker claims around 600 GB
  24. Claimed

    Energy Action

    Energy & utilities

    The SafePay ransomware group listed the energy-management consultancy Energy Action on its leak site, claiming roughly 470 GB of stolen data. Energy Action says it manages more than 10 per cent of Australia's commercial energy spend, so the data reaches many corporate clients.

    Threat actor
    SafePay
    Attack type
    Ransomware / data theft
    Scale
    Attacker claims ~470 GB of data

    Data exposed

    Commercial contractsUsage dataAccount information
  25. Confirmed

    NSW Government (Treasury)

    Government

    A NSW Treasury staff member was charged after internal monitoring detected the alleged transfer of more than 5,600 restricted government documents to an external server. The NSW Government declared a significant cyber incident; the data was later located and secured, and there was no evidence of an external hack.

    Attack type
    Insider data breach
    Scale
    More than 5,600 documents
  26. Confirmed

    Bendigo & District Aboriginal Co-operative

    Not-for-profit

    The Bendigo & District Aboriginal Co-operative, which delivers health, education and community services to the Dja Dja Wurrung community, confirmed a cyber incident after being listed by INC Ransom. It said the incident was detected and secured the same day, limiting impact.

    Threat actor
    INC Ransom
    Attack type
    Ransomware
  27. Investigating

    Mastercom

    Telecommunications

    The INC Ransom group listed Granville, NSW communications firm Mastercom, which operates Australia's largest commercial two-way radio network, and published customer, HR and financial data. Mastercom said it was aware of the claims.

    Threat actor
    INC Ransom
    Attack type
    Ransomware

    Data exposed

    Customer dataHR dataFinancial data
  28. Confirmed

    Smile Team Orthodontics

    Healthcare

    The SafePay ransomware group listed NSW dental practice Smile Team Orthodontics and published stolen data, including staff details, personal emails, medical certificates and hundreds of DentiCare patient payment plans. The practice notified the OAIC and the ACSC.

    Threat actor
    SafePay
    Attack type
    Ransomware

    Data exposed

    Staff listingsHome addressesPersonal emailsMedical certificatesPatient payment plans
  29. Confirmed

    Hazeldenes

    Food & agriculture

    A February cyber attack on major Victorian poultry processor Hazeldenes caused production disruption and regional chicken shortages. In March the DragonForce ransomware group published a roughly 79 gigabyte dataset stolen from the company to its leak site.

    Threat actor
    DragonForce
    Attack type
    Ransomware
    Scale
    Attacker published ~79 GB
  30. Confirmed

    youX

    Financial services

    Sydney fintech platform youX confirmed a data breach exposing the personal and financial records of 444,538 Australians. The actor FulcrumSec claimed to have taken data spanning roughly 629,597 loan applications and hundreds of broker organisations.

    Threat actor
    FulcrumSec
    Attack type
    Data breach
    Scale
    444,538 people; ~629,597 loan applications

    Data exposed

    Financial detailsDriver's licencesResidential addressesLoan applications
  31. Confirmed

    Seagrass Boutique Hospitality Group

    Other

    Seagrass Boutique Hospitality Group, the operator behind restaurant brands including The Meat & Wine Co and Hunter Barrel, confirmed a cyber incident involving unauthorised access to part of its network. The Kairos ransomware group claimed the attack on 12 February.

    Threat actor
    Kairos
    Attack type
    Ransomware
  32. Confirmed

    Aeromedical Society of Australasia

    Not-for-profit

    The LockBit ransomware operation listed the Aeromedical Society of Australasia, an air-medical transport body for Australia and New Zealand, in an 11 February leak post and threatened to publish data. The society confirmed it was aware of a cyber incident.

    Threat actor
    LockBit
    Attack type
    Ransomware
  33. Claimed

    Ansell Limited

    Manufacturing

    The 0apt group claimed a cyber attack on protective-equipment manufacturer Ansell Limited, threatening to release material it said included product formulas and supply-chain contracts.

    Threat actor
    0apt
    Attack type
    Ransomware / data theft
  34. Confirmed

    Victorian Department of Education

    Government

    Attackers reached a Victorian Department of Education database through a school's network, accessing names, email addresses, encrypted passwords and school details of current and former students across all 1,700 government schools. The department said home addresses, dates of birth and staff records were not accessed, and there was no evidence the data had been published.

    Attack type
    Unauthorised access via a school network
    Scale
    Current and former students across all ~1,700 government schools

    Data exposed

    NamesEmail addressesEncrypted passwordsYear levelSchool
  35. Confirmed

    Prosura

    Financial services

    Rental car insurer Prosura, which also trades as Hiccup, confirmed a cyber incident after attackers accessed its systems around 1 January and began contacting customers. Data on an estimated 300,000 customers, including driver's licences and claim details, was later offered for sale. Prosura said credit card details were not accessed.

    Attack type
    Data breach
    Scale
    Around 300,000 customers

    Data exposed

    NamesEmail addressesPhone numbersTravel detailsPolicy dataDriver's licences
  36. Resolved

    Regis Resources

    Other

    ASX-listed gold producer Regis Resources confirmed a cyber incident first detected in mid-November 2025, after the Lynx ransomware group listed its McPhillamys Gold subsidiary on 5 January 2026. Automated isolation contained the intrusion, and a forensic investigation found no data was stolen and no ransom demand was made.

    Threat actor
    Lynx
    Attack type
    Attempted ransomware (contained)

About this list

This tracker is compiled from public reporting and official disclosures and is provided on a best-effort basis for general information only. Entries may contain errors or omissions, and details often change as incidents are investigated. Each entry links to its source so you can check the original report.

Where an incident reflects an unverified claim by an attacker and the organisation has not confirmed it, we label it claimed rather than stating it as fact. IronSights is not affiliated with, and does not endorse or make any allegation against, the organisations listed. If you represent a listed organisation and would like a correction or removal, contact us and we will review it promptly.

If you are the one on the list

A breach is a bad week, not the end of one.

If your organisation is dealing with an incident right now, our Australian incident response team is available around the clock. The first hours decide how much can be saved.