IronSights

Free tool · Updated daily

The Australian data breach tracker.

A running list of the data breaches, ransomware attacks and extortion cases hitting Australian organisations. Search it, filter it, and see which sectors and groups are most active right now.

Each entry is checked before it appears here. Where an incident is only an attacker's claim and the organisation has not confirmed it, we label it as claimed rather than reporting it as fact.

5

Incidents tracked

2

In the last 30 days

Energy & utilities

Most affected sector

2019

Most active group

5 incidents

  1. Investigating

    Origin Energy

    Energy & utilities

    Origin told the ASX it was investigating potential unauthorised access to customer data. An individual emailed the extortion demand to 7NEWS, gave The Australian a 50-record sample, and started a 14-day public countdown. Origin says it does not believe credit card or bank details were involved.

    Attack type
    Data theft & extortion
    Scale
    Attacker claims 2M+ customer records; Origin has ~4.8M accounts

    Data exposed

    NamesContact detailsDates of birthBilling history
  2. Confirmed

    Lifeline

    Not-for-profit

    Lifeline confirmed staff and volunteer data was accessed and posted to a forum for free by an actor using the handle 2019. Some of the released data was found to be falsified. Lifeline says no help-seeker data or financial information was compromised.

    Threat actor
    2019
    Attack type
    Data theft (free leak)
    Scale
    10,600+ staff and volunteer records claimed

    Data exposed

    NamesEmail addressesDates of birthClient IDsPhone numbers
  3. Confirmed

    Mackay Sugar

    Food & agriculture

    A ransomware attack claimed by The Gentlemen forced two of Mackay Sugar's three Queensland mills offline at the start of the cane crushing season, halting harvesting across around 1,300 family farms. The company ran limited manual crushing while restoring systems.

    Threat actor
    The Gentlemen
    Attack type
    Ransomware
    Scale
    Operational disruption; two of three mills offline
  4. Confirmed

    Tripod Farmers Group

    Food & agriculture

    The Qilin ransomware group listed the fresh-produce supplier Tripod Farmers after unauthorised access detected around February. The company confirmed a breach affecting part of its systems but said production and customer operations were not disrupted.

    Threat actor
    Qilin
    Attack type
    Ransomware / data theft
    Scale
    Part of systems affected
  5. Claimed

    Energy Action

    Energy & utilities

    The SafePay ransomware group listed the energy-management consultancy Energy Action on its leak site, claiming roughly 470 GB of stolen data. Energy Action says it manages more than 10 per cent of Australia's commercial energy spend, so the data reaches many corporate clients.

    Threat actor
    SafePay
    Attack type
    Ransomware / data theft
    Scale
    Attacker claims ~470 GB of data

    Data exposed

    Commercial contractsUsage dataAccount information

If you are the one on the list

A breach is a bad week, not the end of one.

If your organisation is dealing with an incident right now, our Australian incident response team is available around the clock. The first hours decide how much can be saved.