Free tool · Updated daily
The Australian data breach tracker.
A running list of the data breaches, ransomware attacks and extortion cases hitting Australian organisations. Search it, filter it, and see which sectors and groups are most active right now.
Each entry is checked before it appears here. Where an incident is only an attacker's claim and the organisation has not confirmed it, we label it as claimed rather than reporting it as fact.
5
Incidents tracked
2
In the last 30 days
Energy & utilities
Most affected sector
2019
Most active group
5 incidents
- Investigating
Origin Energy
Energy & utilitiesOrigin told the ASX it was investigating potential unauthorised access to customer data. An individual emailed the extortion demand to 7NEWS, gave The Australian a 50-record sample, and started a 14-day public countdown. Origin says it does not believe credit card or bank details were involved.
- Attack type
- Data theft & extortion
- Scale
- Attacker claims 2M+ customer records; Origin has ~4.8M accounts
Data exposed
NamesContact detailsDates of birthBilling history - Confirmed
Lifeline
Not-for-profitLifeline confirmed staff and volunteer data was accessed and posted to a forum for free by an actor using the handle 2019. Some of the released data was found to be falsified. Lifeline says no help-seeker data or financial information was compromised.
- Threat actor
- 2019
- Attack type
- Data theft (free leak)
- Scale
- 10,600+ staff and volunteer records claimed
Data exposed
NamesEmail addressesDates of birthClient IDsPhone numbers - Confirmed
Mackay Sugar
Food & agricultureA ransomware attack claimed by The Gentlemen forced two of Mackay Sugar's three Queensland mills offline at the start of the cane crushing season, halting harvesting across around 1,300 family farms. The company ran limited manual crushing while restoring systems.
- Threat actor
- The Gentlemen
- Attack type
- Ransomware
- Scale
- Operational disruption; two of three mills offline
- Confirmed
Tripod Farmers Group
Food & agricultureThe Qilin ransomware group listed the fresh-produce supplier Tripod Farmers after unauthorised access detected around February. The company confirmed a breach affecting part of its systems but said production and customer operations were not disrupted.
- Threat actor
- Qilin
- Attack type
- Ransomware / data theft
- Scale
- Part of systems affected
- Claimed
Energy Action
Energy & utilitiesThe SafePay ransomware group listed the energy-management consultancy Energy Action on its leak site, claiming roughly 470 GB of stolen data. Energy Action says it manages more than 10 per cent of Australia's commercial energy spend, so the data reaches many corporate clients.
- Threat actor
- SafePay
- Attack type
- Ransomware / data theft
- Scale
- Attacker claims ~470 GB of data
Data exposed
Commercial contractsUsage dataAccount information
If you are the one on the list
A breach is a bad week, not the end of one.
If your organisation is dealing with an incident right now, our Australian incident response team is available around the clock. The first hours decide how much can be saved.
