Free tool · Updated weekly
The Australian data breach tracker.
A running list of the data breaches, ransomware attacks and extortion cases hitting Australian organisations. Search it, filter it, and see which sectors and groups are most active right now.
Each entry is checked before it appears here. Where an incident is only an attacker's claim and the organisation has not confirmed it, we label it as claimed rather than reporting it as fact.
46
Incidents tracked
8
In the last 30 days
Other
Most affected sector
Storm
Most active group
46 incidents
- Investigating
DigiGround
Technology / App DevelopmentThe Qilin ransomware group has listed the Sydney-based bespoke app developer DigiGround on its darknet leak site, but the company says it has so far found no evidence that its systems or data were compromised and is treating the claim as unverified while it investigates.
- Threat actor
- Qilin ransomware group
- Attack type
- Ransomware (leak-site claim)
- Confirmed
Sharp Motor Group
Automotive retailThe Storm ransomware group listed the Tweed Heads-based Sharp Motor Group on its leak site on 23 August, publishing files it claims were stolen; the dealership has confirmed its third-party IT provider was involved in a cyber incident and is actively investigating, but has not verified the attacker's claims about the scope of data stolen.
- Threat actor
- Storm
- Attack type
- Ransomware / third-party (supply chain) compromise
Data exposed
Employee passport and driver's licence scansFinancial dataCustomer invoicesPasswords and user IDs - Confirmed
Hachette Australia & New Zealand / Alliance Distribution Services (ADS)
Publishing / logisticsHachette Australia confirmed that its distribution subsidiary, Alliance Distribution Services, detected unauthorised activity on its computer systems believed to have begun on 18 July, severely disrupting national book distribution; the company has notified authorities but has not disclosed whether data was compromised or named an attacker.
- Attack type
- Unauthorised network access (suspected ransomware)
- Confirmed
Oz Hair and Beauty
Retail (beauty and personal care e-commerce)Oz Hair and Beauty confirmed that its online purchase and order platform was briefly accessed by an unauthorised third party, with limited personal information tied to purchases made before August 2026 affected. The xpl0itrs group has separately claimed on a dark web leak site to have obtained about 2.1 million customer records, a figure the retailer has not confirmed.
- Threat actor
- xpl0itrs
- Attack type
- Data breach via unauthorised access to online ordering platform (cyber extortion/leak)
Data exposed
namesemail addressesorder/purchase details - Confirmed
Quest Apartment Hotels
HospitalityQuest Apartment Hotels confirmed that unauthorised access to a database system operated by a third-party service provider compromised guests' names, emails and dates of birth, and warned customers to watch for scam attempts.
- Attack type
- Third-party/supply chain breach
Data exposed
NamesEmail addressesDates of birth - Claimed
Ramsey Bros
Agriculture / farm machinery distributionThe newly emerged Storm ransomware group has listed South Australian farm machinery supplier Ramsey Bros as a victim on its leak site, publishing sample documents and threatening full data release on 4 September; the company has not confirmed the intrusion.
- Threat actor
- Storm
- Attack type
- Ransomware / data theft
Data exposed
InvoicesCustomer correspondenceVehicle inspection reportsVehicle identification numbersDriver details and contact information - Claimed
Mighty Kingdom
Video game developmentThe Direwolf ransomware group has claimed on its darknet leak site to have accessed more than 260 code repositories belonging to Adelaide-based game studio Mighty Kingdom; the claim is unverified by the company.
- Threat actor
- Direwolf
- Attack type
- Ransomware / data theft
Data exposed
Source codeCode repositories - Claimed
Westco Motors Cairns
Automotive retailThe Storm ransomware group publicly claimed responsibility for an attack on Queensland automotive dealership Westco Motors Cairns, posting a notice threatening to leak stolen data unless negotiations occur; the dealership has not publicly confirmed the incident.
- Threat actor
- Storm
- Attack type
- Ransomware (leak-site claim)
Data exposed
customer databusiness data - Claimed
LR Reed
OtherThe Kairos group listed Melbourne property management firm LR Reed, claiming 335 gigabytes of data. LR Reed said it was aware of the claims and investigating, had notified the Australian Signals Directorate and AFP, and believed customer data was safe.
- Threat actor
- Kairos
- Attack type
- Data theft / extortion
- Scale
- Attacker claims 335 GB
- Confirmed
GO2 Health
HealthcareBrisbane clinic GO2 Health confirmed a limited data breach after its main mailbox was accessed in April through a phishing attack, exposing information in the prior year's emails including some patients' Department of Veterans' Affairs ID numbers. Its main patient records system was not accessed; patients were notified almost three months later.
- Attack type
- Email compromise (phishing)
Data exposed
Email contentsDepartment of Veterans' Affairs ID numbers - Investigating
Origin Energy
Energy & utilitiesOrigin told the ASX it was investigating potential unauthorised access to customer data. An individual emailed the extortion demand to 7NEWS, gave The Australian a 50-record sample, and started a 14-day public countdown. Origin says it does not believe credit card or bank details were involved.
- Attack type
- Data theft & extortion
- Scale
- Attacker claims 2M+ customer records; Origin has ~4.8M accounts
Data exposed
NamesContact detailsDates of birthBilling history - Confirmed
Partnered Health
HealthcareGP network Partnered Health disclosed on 15 July that a malicious actor had accessed its network around 23 June, potentially compromising patient data across roughly 21 clinics. Exposed information may include Medicare numbers, Veteran Card numbers, private health insurance details and medical records.
- Attack type
- Cyber attack
- Scale
- Around 21 clinics
Data exposed
NamesDates of birthAddressesMedicare numbersVeteran Card / DVA numbersPrivate health insurance detailsMedical information - Confirmed
Royal Foods
Food & agricultureQueensland gourmet food supplier Royal Foods confirmed it was investigating an incident in which an unauthorised third party accessed part of its internal IT environment. The Gentlemen ransomware group, also behind the Mackay Sugar attack, listed the company on 7 July.
- Threat actor
- The Gentlemen
- Attack type
- Ransomware
- Confirmed
Lifeline
Not-for-profitLifeline confirmed staff and volunteer data was accessed and posted to a forum for free by an actor using the handle 2019. Some of the released data was found to be falsified. Lifeline says no help-seeker data or financial information was compromised.
- Threat actor
- 2019
- Attack type
- Data theft (free leak)
- Scale
- 10,600+ staff and volunteer records claimed
Data exposed
NamesEmail addressesDates of birthClient IDsPhone numbers - Claimed
AC Small Maxwell & Co
Professional servicesThreat actors linked to SafePay claimed a cyber attack on NSW accounting and advisory firm AC Small Maxwell & Co, threatening to leak allegedly stolen data.
- Threat actor
- SafePay
- Attack type
- Ransomware
- Confirmed
Generation Life
Financial servicesInvestment firm Generation Life confirmed customer information was affected by a cyber incident first identified in April, involving an attacker reaching its systems through a third-party provider. It said the issue was contained and client investments and funds remained secure.
- Attack type
- Third-party breach
- Investigating
NSW Rural Fire Service
GovernmentThe NSW Rural Fire Service said historical data was likely compromised in a security incident, while its operational response was unaffected. The Nova ransomware group declared the breach in mid-June and shared samples; it is understood to have involved a third-party vendor supporting RFS radio and telecommunications infrastructure.
- Threat actor
- Nova
- Attack type
- Third-party breach / ransomware
- Investigating
Elina Medical Weight Loss Clinic
HealthcareMelbourne clinic Elina Medical Weight Loss said it was investigating after the actor 2019 claimed to have stolen data on more than 28,000 patients. Two of the clinic's HotDoc accounts were accessed by an unknown third party; the clinic said the incident was contained and activity was limited to those accounts.
- Threat actor
- 2019
- Attack type
- Account compromise
- Scale
- Actor claims data on 28,000+ patients
- Confirmed
Kennedy McLaughlin
Professional servicesBrisbane accounting firm Kennedy McLaughlin confirmed a cyber incident after a Qilin ransomware affiliate listed it and published a dataset including clients' financial details. The firm notified affected individuals, the ACSC and the OAIC.
- Threat actor
- Qilin
- Attack type
- Ransomware
Data exposed
Client financial dataBanking details - Confirmed
Ochre Health (Tuggeranong)
HealthcareOchre Health confirmed that patient data from its Tuggeranong clinic was potentially compromised after an actor using the handle 2019 breached a third-party provider. Records of more than 25,000 patients, including Medicare and DVA numbers, were offered for sale on a hacking forum.
- Threat actor
- 2019
- Attack type
- Third-party breach / data theft
- Scale
- More than 25,000 patients
Data exposed
Medicare numbersDVA numbersPatient records - Confirmed
Goodstone Group
OtherTasmanian hospitality group Goodstone Group, which runs hotels, bars and bottleshops around Devonport, confirmed a ransomware attack by the newly emerged CMD Organization. The group published evidence including employee passport scans and bank reconciliation records.
- Threat actor
- CMD Organization
- Attack type
- Ransomware
Data exposed
Employee passportsBank reconciliation details - Confirmed
Mackay Sugar
Food & agricultureA ransomware attack claimed by The Gentlemen forced two of Mackay Sugar's three Queensland mills offline at the start of the cane crushing season, halting harvesting across around 1,300 family farms. The company ran limited manual crushing while restoring systems.
- Threat actor
- The Gentlemen
- Attack type
- Ransomware
- Scale
- Operational disruption; two of three mills offline
- Confirmed
Melbourne International Film Festival
Not-for-profitAbout 26,782 Melbourne International Film Festival customer records were exposed after its third-party ticketing platform Ferve was breached. MIFF disputed a threat actor's separate claim of 340,000 affected customers, saying its database does not hold that many records.
- Attack type
- Third-party breach (Ferve ticketing)
- Scale
- About 26,782 customer records
Data exposed
NamesEmail addressesPhone numbersResidential addresses - Investigating
Australian Computer Society
Not-for-profitThe Australian Computer Society said it was investigating a possible breach after ShinyHunters claimed to have accessed its data.
- Threat actor
- ShinyHunters
- Attack type
- Data breach (claimed)
- Confirmed
Tripod Farmers Group
Food & agricultureThe Qilin ransomware group listed the fresh-produce supplier Tripod Farmers after unauthorised access detected around February. The company confirmed a breach affecting part of its systems but said production and customer operations were not disrupted.
- Threat actor
- Qilin
- Attack type
- Ransomware / data theft
- Scale
- Part of systems affected
- Confirmed
Queensland Department of Education
GovernmentThe Queensland Department of Education confirmed students and staff were affected by a breach of Instructure, the third-party provider behind its QLearn platform. The ShinyHunters group claimed the data and set a ransom deadline. Exposed fields included names, email addresses and school locations.
- Threat actor
- ShinyHunters
- Attack type
- Third-party breach (Instructure / QLearn)
Data exposed
NamesEmail addressesSchool locations - Confirmed
Champion Homes
OtherSydney home builder Champion Homes confirmed a cyber attack that exposed a limited amount of employee and customer data. The DragonForce ransomware group had listed the company on 21 April and published a roughly 44 gigabyte dataset.
- Threat actor
- DragonForce
- Attack type
- Ransomware
- Scale
- Attacker published ~44 GB
- Investigating
Gregory Jewellers
Retail & consumerFine jewellery retailer Gregory Jewellers said it was investigating after the Kairos group claimed on 22 April to have stolen about 574 gigabytes of data. The company had not confirmed whether customer or employee information was affected.
- Threat actor
- Kairos
- Attack type
- Ransomware / data theft
- Scale
- Attacker claims 574 GB
- Resolved
Scope Systems
TechnologyPerth-based Scope Systems, an IT provider to the mining sector, confirmed a malicious actor accessed its network for under 24 hours, disrupting hosted services including Pronto Xi. The company said no data loss occurred and no group claimed responsibility.
- Attack type
- Cyber incident (service disruption)
- Confirmed
ALS Global
Professional servicesTesting and inspection firm ALS Global disclosed a cyber incident in May. In June the Aur0ra group published employee data, banking details and testing records to the dark web.
- Threat actor
- Aur0ra
- Attack type
- Ransomware / data theft
Data exposed
Employee dataBanking detailsPasswordsTesting records - Claimed
Earth Systems
Professional servicesThe INC Ransom group listed environmental and engineering consultancy Earth Systems, claiming around 600 gigabytes of stolen data.
- Threat actor
- INC Ransom
- Attack type
- Ransomware / data theft
- Scale
- Attacker claims around 600 GB
- Claimed
Energy Action
Energy & utilitiesThe SafePay ransomware group listed the energy-management consultancy Energy Action on its leak site, claiming roughly 470 GB of stolen data. Energy Action says it manages more than 10 per cent of Australia's commercial energy spend, so the data reaches many corporate clients.
- Threat actor
- SafePay
- Attack type
- Ransomware / data theft
- Scale
- Attacker claims ~470 GB of data
Data exposed
Commercial contractsUsage dataAccount information - Confirmed
NSW Government (Treasury)
GovernmentA NSW Treasury staff member was charged after internal monitoring detected the alleged transfer of more than 5,600 restricted government documents to an external server. The NSW Government declared a significant cyber incident; the data was later located and secured, and there was no evidence of an external hack.
- Attack type
- Insider data breach
- Scale
- More than 5,600 documents
- Confirmed
Bendigo & District Aboriginal Co-operative
Not-for-profitThe Bendigo & District Aboriginal Co-operative, which delivers health, education and community services to the Dja Dja Wurrung community, confirmed a cyber incident after being listed by INC Ransom. It said the incident was detected and secured the same day, limiting impact.
- Threat actor
- INC Ransom
- Attack type
- Ransomware
- Investigating
Mastercom
TelecommunicationsThe INC Ransom group listed Granville, NSW communications firm Mastercom, which operates Australia's largest commercial two-way radio network, and published customer, HR and financial data. Mastercom said it was aware of the claims.
- Threat actor
- INC Ransom
- Attack type
- Ransomware
Data exposed
Customer dataHR dataFinancial data - Confirmed
Smile Team Orthodontics
HealthcareThe SafePay ransomware group listed NSW dental practice Smile Team Orthodontics and published stolen data, including staff details, personal emails, medical certificates and hundreds of DentiCare patient payment plans. The practice notified the OAIC and the ACSC.
- Threat actor
- SafePay
- Attack type
- Ransomware
Data exposed
Staff listingsHome addressesPersonal emailsMedical certificatesPatient payment plans - Confirmed
Hazeldenes
Food & agricultureA February cyber attack on major Victorian poultry processor Hazeldenes caused production disruption and regional chicken shortages. In March the DragonForce ransomware group published a roughly 79 gigabyte dataset stolen from the company to its leak site.
- Threat actor
- DragonForce
- Attack type
- Ransomware
- Scale
- Attacker published ~79 GB
- Confirmed
Australian federal and state courts (via VIQ Solutions)
Government / justice (third-party transcription services)Canadian transcription provider VIQ Solutions confirmed a security incident that exposed sensitive Australian court files after it subcontracted work to an Indian firm, e24 Technologies, allegedly in breach of its Commonwealth contracts. Exposed material reportedly included documents from the Federal Circuit and Family Court and the Federal Court.
- Attack type
- Third-party / supply-chain data exposure
Data exposed
court filesFederal Circuit and Family Court documentsFederal Court documents - Confirmed
youX
Financial services (fintech / asset finance)Sydney-based finance-broking platform youX confirmed unauthorised access to its systems after a threat actor released data it claims to have taken from an unsecured database. youX acknowledged personal information of borrowers may have been compromised; the attacker claims to hold roughly 141GB covering about 444,538 borrowers and has threatened staged release unless paid.
- Attack type
- Data breach and extortion (unsecured MongoDB Atlas cluster)
- Scale
- 444,538 borrowers
Data exposed
loan applicationsdriver's licencesresidential addressesincome and debt detailsgovernment identifiersbroker banking detailspassword hashes - Confirmed
youX
Financial servicesSydney fintech platform youX confirmed a data breach exposing the personal and financial records of 444,538 Australians. The actor FulcrumSec claimed to have taken data spanning roughly 629,597 loan applications and hundreds of broker organisations.
- Threat actor
- FulcrumSec
- Attack type
- Data breach
- Scale
- 444,538 people; ~629,597 loan applications
Data exposed
Financial detailsDriver's licencesResidential addressesLoan applications - Confirmed
Seagrass Boutique Hospitality Group
OtherSeagrass Boutique Hospitality Group, the operator behind restaurant brands including The Meat & Wine Co and Hunter Barrel, confirmed a cyber incident involving unauthorised access to part of its network. The Kairos ransomware group claimed the attack on 12 February.
- Threat actor
- Kairos
- Attack type
- Ransomware
- Confirmed
Aeromedical Society of Australasia
Not-for-profitThe LockBit ransomware operation listed the Aeromedical Society of Australasia, an air-medical transport body for Australia and New Zealand, in an 11 February leak post and threatened to publish data. The society confirmed it was aware of a cyber incident.
- Threat actor
- LockBit
- Attack type
- Ransomware
- Claimed
Ansell Limited
ManufacturingThe 0apt group claimed a cyber attack on protective-equipment manufacturer Ansell Limited, threatening to release material it said included product formulas and supply-chain contracts.
- Threat actor
- 0apt
- Attack type
- Ransomware / data theft
- Confirmed
Victorian Department of Education
GovernmentAttackers reached a Victorian Department of Education database through a school's network, accessing names, email addresses, encrypted passwords and school details of current and former students across all 1,700 government schools. The department said home addresses, dates of birth and staff records were not accessed, and there was no evidence the data had been published.
- Attack type
- Unauthorised access via a school network
- Scale
- Current and former students across all ~1,700 government schools
Data exposed
NamesEmail addressesEncrypted passwordsYear levelSchool - Confirmed
Prosura
Financial servicesRental car insurer Prosura, which also trades as Hiccup, confirmed a cyber incident after attackers accessed its systems around 1 January and began contacting customers. Data on an estimated 300,000 customers, including driver's licences and claim details, was later offered for sale. Prosura said credit card details were not accessed.
- Attack type
- Data breach
- Scale
- Around 300,000 customers
Data exposed
NamesEmail addressesPhone numbersTravel detailsPolicy dataDriver's licences - Resolved
Regis Resources
OtherASX-listed gold producer Regis Resources confirmed a cyber incident first detected in mid-November 2025, after the Lynx ransomware group listed its McPhillamys Gold subsidiary on 5 January 2026. Automated isolation contained the intrusion, and a forensic investigation found no data was stolen and no ransom demand was made.
- Threat actor
- Lynx
- Attack type
- Attempted ransomware (contained)
For your own organisation
The tracker shows what was disclosed. It cannot show what is circulating.
Credentials and data stolen from Australian businesses are traded through criminal marketplaces, hacker forums, Telegram channels and combolists, often months before a public disclosure and sometimes without one ever being made. A quiet result above says nothing about what is out there for your domain.
Ask us to run a dark web exposure search on your organisation. An analyst runs it, and you get a plain-English summary of what we found and what to do about it.
Request a dark web searchAbout this list
This tracker is compiled from public reporting and official disclosures and is provided on a best-effort basis for general information only. Entries may contain errors or omissions, and details often change as incidents are investigated. Each entry links to its source so you can check the original report.
Where an incident reflects an unverified claim by an attacker and the organisation has not confirmed it, we label it claimed rather than stating it as fact. IronSights is not affiliated with, and does not endorse or make any allegation against, the organisations listed. If you represent a listed organisation and would like a correction or removal, contact us and we will review it promptly.
If you are the one on the list
A breach is a bad week, not the end of one.
If your organisation is dealing with an incident right now, our Australian incident response team is available around the clock. The first hours decide how much can be saved.
Do we have to report it? Unauthorised access to personal information that is likely to cause serious harm has to be assessed within 30 days. Our guide to the Notifiable Data Breaches scheme covers the assessment and the statement, and the wider Australian cyber obligations hub covers the rest.
Nothing was encrypted, they just took data. That is extortion without encryption, and there is nothing to restore. See data theft extortion response.
Our files are locked. Start with ransomware recovery, which measures what survived before anyone talks about paying.
