Free tool · Updated daily
The Australian data breach tracker.
A running list of the data breaches, ransomware attacks and extortion cases hitting Australian organisations. Search it, filter it, and see which sectors and groups are most active right now.
Each entry is checked before it appears here. Where an incident is only an attacker's claim and the organisation has not confirmed it, we label it as claimed rather than reporting it as fact.
36
Incidents tracked
6
In the last 30 days
Other
Most affected sector
Kairos
Most active group
36 incidents
- Claimed
LR Reed
OtherThe Kairos group listed Melbourne property management firm LR Reed, claiming 335 gigabytes of data. LR Reed said it was aware of the claims and investigating, had notified the Australian Signals Directorate and AFP, and believed customer data was safe.
- Threat actor
- Kairos
- Attack type
- Data theft / extortion
- Scale
- Attacker claims 335 GB
- Confirmed
GO2 Health
HealthcareBrisbane clinic GO2 Health confirmed a limited data breach after its main mailbox was accessed in April through a phishing attack, exposing information in the prior year's emails including some patients' Department of Veterans' Affairs ID numbers. Its main patient records system was not accessed; patients were notified almost three months later.
- Attack type
- Email compromise (phishing)
Data exposed
Email contentsDepartment of Veterans' Affairs ID numbers - Investigating
Origin Energy
Energy & utilitiesOrigin told the ASX it was investigating potential unauthorised access to customer data. An individual emailed the extortion demand to 7NEWS, gave The Australian a 50-record sample, and started a 14-day public countdown. Origin says it does not believe credit card or bank details were involved.
- Attack type
- Data theft & extortion
- Scale
- Attacker claims 2M+ customer records; Origin has ~4.8M accounts
Data exposed
NamesContact detailsDates of birthBilling history - Confirmed
Partnered Health
HealthcareGP network Partnered Health disclosed on 15 July that a malicious actor had accessed its network around 23 June, potentially compromising patient data across roughly 21 clinics. Exposed information may include Medicare numbers, Veteran Card numbers, private health insurance details and medical records.
- Attack type
- Cyber attack
- Scale
- Around 21 clinics
Data exposed
NamesDates of birthAddressesMedicare numbersVeteran Card / DVA numbersPrivate health insurance detailsMedical information - Confirmed
Royal Foods
Food & agricultureQueensland gourmet food supplier Royal Foods confirmed it was investigating an incident in which an unauthorised third party accessed part of its internal IT environment. The Gentlemen ransomware group, also behind the Mackay Sugar attack, listed the company on 7 July.
- Threat actor
- The Gentlemen
- Attack type
- Ransomware
- Confirmed
Lifeline
Not-for-profitLifeline confirmed staff and volunteer data was accessed and posted to a forum for free by an actor using the handle 2019. Some of the released data was found to be falsified. Lifeline says no help-seeker data or financial information was compromised.
- Threat actor
- 2019
- Attack type
- Data theft (free leak)
- Scale
- 10,600+ staff and volunteer records claimed
Data exposed
NamesEmail addressesDates of birthClient IDsPhone numbers - Claimed
AC Small Maxwell & Co
Professional servicesThreat actors linked to SafePay claimed a cyber attack on NSW accounting and advisory firm AC Small Maxwell & Co, threatening to leak allegedly stolen data.
- Threat actor
- SafePay
- Attack type
- Ransomware
- Confirmed
Generation Life
Financial servicesInvestment firm Generation Life confirmed customer information was affected by a cyber incident first identified in April, involving an attacker reaching its systems through a third-party provider. It said the issue was contained and client investments and funds remained secure.
- Attack type
- Third-party breach
- Investigating
NSW Rural Fire Service
GovernmentThe NSW Rural Fire Service said historical data was likely compromised in a security incident, while its operational response was unaffected. The Nova ransomware group declared the breach in mid-June and shared samples; it is understood to have involved a third-party vendor supporting RFS radio and telecommunications infrastructure.
- Threat actor
- Nova
- Attack type
- Third-party breach / ransomware
- Investigating
Elina Medical Weight Loss Clinic
HealthcareMelbourne clinic Elina Medical Weight Loss said it was investigating after the actor 2019 claimed to have stolen data on more than 28,000 patients. Two of the clinic's HotDoc accounts were accessed by an unknown third party; the clinic said the incident was contained and activity was limited to those accounts.
- Threat actor
- 2019
- Attack type
- Account compromise
- Scale
- Actor claims data on 28,000+ patients
- Confirmed
Kennedy McLaughlin
Professional servicesBrisbane accounting firm Kennedy McLaughlin confirmed a cyber incident after a Qilin ransomware affiliate listed it and published a dataset including clients' financial details. The firm notified affected individuals, the ACSC and the OAIC.
- Threat actor
- Qilin
- Attack type
- Ransomware
Data exposed
Client financial dataBanking details - Confirmed
Ochre Health (Tuggeranong)
HealthcareOchre Health confirmed that patient data from its Tuggeranong clinic was potentially compromised after an actor using the handle 2019 breached a third-party provider. Records of more than 25,000 patients, including Medicare and DVA numbers, were offered for sale on a hacking forum.
- Threat actor
- 2019
- Attack type
- Third-party breach / data theft
- Scale
- More than 25,000 patients
Data exposed
Medicare numbersDVA numbersPatient records - Confirmed
Goodstone Group
OtherTasmanian hospitality group Goodstone Group, which runs hotels, bars and bottleshops around Devonport, confirmed a ransomware attack by the newly emerged CMD Organization. The group published evidence including employee passport scans and bank reconciliation records.
- Threat actor
- CMD Organization
- Attack type
- Ransomware
Data exposed
Employee passportsBank reconciliation details - Confirmed
Mackay Sugar
Food & agricultureA ransomware attack claimed by The Gentlemen forced two of Mackay Sugar's three Queensland mills offline at the start of the cane crushing season, halting harvesting across around 1,300 family farms. The company ran limited manual crushing while restoring systems.
- Threat actor
- The Gentlemen
- Attack type
- Ransomware
- Scale
- Operational disruption; two of three mills offline
- Confirmed
Melbourne International Film Festival
Not-for-profitAbout 26,782 Melbourne International Film Festival customer records were exposed after its third-party ticketing platform Ferve was breached. MIFF disputed a threat actor's separate claim of 340,000 affected customers, saying its database does not hold that many records.
- Attack type
- Third-party breach (Ferve ticketing)
- Scale
- About 26,782 customer records
Data exposed
NamesEmail addressesPhone numbersResidential addresses - Investigating
Australian Computer Society
Not-for-profitThe Australian Computer Society said it was investigating a possible breach after ShinyHunters claimed to have accessed its data.
- Threat actor
- ShinyHunters
- Attack type
- Data breach (claimed)
- Confirmed
Tripod Farmers Group
Food & agricultureThe Qilin ransomware group listed the fresh-produce supplier Tripod Farmers after unauthorised access detected around February. The company confirmed a breach affecting part of its systems but said production and customer operations were not disrupted.
- Threat actor
- Qilin
- Attack type
- Ransomware / data theft
- Scale
- Part of systems affected
- Confirmed
Queensland Department of Education
GovernmentThe Queensland Department of Education confirmed students and staff were affected by a breach of Instructure, the third-party provider behind its QLearn platform. The ShinyHunters group claimed the data and set a ransom deadline. Exposed fields included names, email addresses and school locations.
- Threat actor
- ShinyHunters
- Attack type
- Third-party breach (Instructure / QLearn)
Data exposed
NamesEmail addressesSchool locations - Confirmed
Champion Homes
OtherSydney home builder Champion Homes confirmed a cyber attack that exposed a limited amount of employee and customer data. The DragonForce ransomware group had listed the company on 21 April and published a roughly 44 gigabyte dataset.
- Threat actor
- DragonForce
- Attack type
- Ransomware
- Scale
- Attacker published ~44 GB
- Investigating
Gregory Jewellers
Retail & consumerFine jewellery retailer Gregory Jewellers said it was investigating after the Kairos group claimed on 22 April to have stolen about 574 gigabytes of data. The company had not confirmed whether customer or employee information was affected.
- Threat actor
- Kairos
- Attack type
- Ransomware / data theft
- Scale
- Attacker claims 574 GB
- Resolved
Scope Systems
TechnologyPerth-based Scope Systems, an IT provider to the mining sector, confirmed a malicious actor accessed its network for under 24 hours, disrupting hosted services including Pronto Xi. The company said no data loss occurred and no group claimed responsibility.
- Attack type
- Cyber incident (service disruption)
- Confirmed
ALS Global
Professional servicesTesting and inspection firm ALS Global disclosed a cyber incident in May. In June the Aur0ra group published employee data, banking details and testing records to the dark web.
- Threat actor
- Aur0ra
- Attack type
- Ransomware / data theft
Data exposed
Employee dataBanking detailsPasswordsTesting records - Claimed
Earth Systems
Professional servicesThe INC Ransom group listed environmental and engineering consultancy Earth Systems, claiming around 600 gigabytes of stolen data.
- Threat actor
- INC Ransom
- Attack type
- Ransomware / data theft
- Scale
- Attacker claims around 600 GB
- Claimed
Energy Action
Energy & utilitiesThe SafePay ransomware group listed the energy-management consultancy Energy Action on its leak site, claiming roughly 470 GB of stolen data. Energy Action says it manages more than 10 per cent of Australia's commercial energy spend, so the data reaches many corporate clients.
- Threat actor
- SafePay
- Attack type
- Ransomware / data theft
- Scale
- Attacker claims ~470 GB of data
Data exposed
Commercial contractsUsage dataAccount information - Confirmed
NSW Government (Treasury)
GovernmentA NSW Treasury staff member was charged after internal monitoring detected the alleged transfer of more than 5,600 restricted government documents to an external server. The NSW Government declared a significant cyber incident; the data was later located and secured, and there was no evidence of an external hack.
- Attack type
- Insider data breach
- Scale
- More than 5,600 documents
- Confirmed
Bendigo & District Aboriginal Co-operative
Not-for-profitThe Bendigo & District Aboriginal Co-operative, which delivers health, education and community services to the Dja Dja Wurrung community, confirmed a cyber incident after being listed by INC Ransom. It said the incident was detected and secured the same day, limiting impact.
- Threat actor
- INC Ransom
- Attack type
- Ransomware
- Investigating
Mastercom
TelecommunicationsThe INC Ransom group listed Granville, NSW communications firm Mastercom, which operates Australia's largest commercial two-way radio network, and published customer, HR and financial data. Mastercom said it was aware of the claims.
- Threat actor
- INC Ransom
- Attack type
- Ransomware
Data exposed
Customer dataHR dataFinancial data - Confirmed
Smile Team Orthodontics
HealthcareThe SafePay ransomware group listed NSW dental practice Smile Team Orthodontics and published stolen data, including staff details, personal emails, medical certificates and hundreds of DentiCare patient payment plans. The practice notified the OAIC and the ACSC.
- Threat actor
- SafePay
- Attack type
- Ransomware
Data exposed
Staff listingsHome addressesPersonal emailsMedical certificatesPatient payment plans - Confirmed
Hazeldenes
Food & agricultureA February cyber attack on major Victorian poultry processor Hazeldenes caused production disruption and regional chicken shortages. In March the DragonForce ransomware group published a roughly 79 gigabyte dataset stolen from the company to its leak site.
- Threat actor
- DragonForce
- Attack type
- Ransomware
- Scale
- Attacker published ~79 GB
- Confirmed
youX
Financial servicesSydney fintech platform youX confirmed a data breach exposing the personal and financial records of 444,538 Australians. The actor FulcrumSec claimed to have taken data spanning roughly 629,597 loan applications and hundreds of broker organisations.
- Threat actor
- FulcrumSec
- Attack type
- Data breach
- Scale
- 444,538 people; ~629,597 loan applications
Data exposed
Financial detailsDriver's licencesResidential addressesLoan applications - Confirmed
Seagrass Boutique Hospitality Group
OtherSeagrass Boutique Hospitality Group, the operator behind restaurant brands including The Meat & Wine Co and Hunter Barrel, confirmed a cyber incident involving unauthorised access to part of its network. The Kairos ransomware group claimed the attack on 12 February.
- Threat actor
- Kairos
- Attack type
- Ransomware
- Confirmed
Aeromedical Society of Australasia
Not-for-profitThe LockBit ransomware operation listed the Aeromedical Society of Australasia, an air-medical transport body for Australia and New Zealand, in an 11 February leak post and threatened to publish data. The society confirmed it was aware of a cyber incident.
- Threat actor
- LockBit
- Attack type
- Ransomware
- Claimed
Ansell Limited
ManufacturingThe 0apt group claimed a cyber attack on protective-equipment manufacturer Ansell Limited, threatening to release material it said included product formulas and supply-chain contracts.
- Threat actor
- 0apt
- Attack type
- Ransomware / data theft
- Confirmed
Victorian Department of Education
GovernmentAttackers reached a Victorian Department of Education database through a school's network, accessing names, email addresses, encrypted passwords and school details of current and former students across all 1,700 government schools. The department said home addresses, dates of birth and staff records were not accessed, and there was no evidence the data had been published.
- Attack type
- Unauthorised access via a school network
- Scale
- Current and former students across all ~1,700 government schools
Data exposed
NamesEmail addressesEncrypted passwordsYear levelSchool - Confirmed
Prosura
Financial servicesRental car insurer Prosura, which also trades as Hiccup, confirmed a cyber incident after attackers accessed its systems around 1 January and began contacting customers. Data on an estimated 300,000 customers, including driver's licences and claim details, was later offered for sale. Prosura said credit card details were not accessed.
- Attack type
- Data breach
- Scale
- Around 300,000 customers
Data exposed
NamesEmail addressesPhone numbersTravel detailsPolicy dataDriver's licences - Resolved
Regis Resources
OtherASX-listed gold producer Regis Resources confirmed a cyber incident first detected in mid-November 2025, after the Lynx ransomware group listed its McPhillamys Gold subsidiary on 5 January 2026. Automated isolation contained the intrusion, and a forensic investigation found no data was stolen and no ransom demand was made.
- Threat actor
- Lynx
- Attack type
- Attempted ransomware (contained)
About this list
This tracker is compiled from public reporting and official disclosures and is provided on a best-effort basis for general information only. Entries may contain errors or omissions, and details often change as incidents are investigated. Each entry links to its source so you can check the original report.
Where an incident reflects an unverified claim by an attacker and the organisation has not confirmed it, we label it claimed rather than stating it as fact. IronSights is not affiliated with, and does not endorse or make any allegation against, the organisations listed. If you represent a listed organisation and would like a correction or removal, contact us and we will review it promptly.
If you are the one on the list
A breach is a bad week, not the end of one.
If your organisation is dealing with an incident right now, our Australian incident response team is available around the clock. The first hours decide how much can be saved.
