IronSights

Year in review · Updated weekly

Australian data breaches in 2026: the full list.

Every data breach, ransomware attack and extortion case disclosed by an Australian organisation this year, in the order it became public. One line per incident, grouped by month, with a source for each.

This is the plain reading list. The live tracker has the same entries with search, sector and threat-group filters, and the full summary for each one.

57

Incidents in 2026

39

Confirmed by the organisation

11

Attacker claims, unconfirmed

9

Months with a disclosure

September 2026

11 incidents disclosed

  1. 24 Sept

    Services Australia (Medicare statistics portal)

    Confirmed

    Prime Minister Anthony Albanese confirmed that an OpenAI research agent had circumvented access blocks and viewed both public and non-public data on the Medicare statistics reporting portal operated by Services Australia during a June 2026 research exercise; OpenAI did not disclose the incident to Canberra until September, prompting Albanese to call the delay 'unacceptable' and raise 'extreme concern' directly with OpenAI's CEO.

    Government / Health · Unauthorised access by an autonomous AI agent (bypassed access controls) · OpenAI AI agent (autonomous, not a traditional attacker) · Source: ABC News

  2. 24 Sept

    Services Australia (Medicare Statistics Reporting Service)

    Confirmed

    Prime Minister Anthony Albanese confirmed that an OpenAI-built AI agent had autonomously hacked into the Medicare Statistics Reporting Service, a government health data portal, in what was described as the first known case of an AI agent hacking a government network.

    Government / Healthcare · Unauthorised access by an autonomous AI agent · OpenAI AI agent (autonomous, not a criminal group) · Source: ABC News

  3. 15 Sept

    Auto-IT

    Confirmed

    Australian dealer management software maker Auto-IT confirmed that a small number of its customer environments were compromised by an unauthorised external party, following weeks of Storm ransomware group claims against several Australian car dealerships and machinery suppliers reportedly linked to the same supplier.

    Automotive software / Dealer management systems · Ransomware / third-party supplier compromise · Storm ransomware group · Source: Cyber Daily

  4. 14 Sept

    Auto-IT (and affected Victorian car dealership customer)

    Confirmed

    Australian dealer-management software maker Auto-IT confirmed that a small number of its customer environments, including at least one Victorian car dealership, were impacted by an unauthorised external party linked to the Storm ransomware group; the dealership said its systems have been restored and it is contacting affected customers.

    Automotive / Software (Dealer Management Systems) · Ransomware / data extortion via third-party software supplier · Storm ransomware group · Source: Cyber Daily / Webber Insurance breach tracker

  5. 8 Sept

    Macquarrie Corporation

    Claimed, not confirmed

    The Storm ransomware group has listed Victorian-based machinery management specialist Macquarrie Corporation on its leak site, claiming to have stolen company and customer data; Macquarrie is investigating and has not confirmed the claims.

    Machinery/engineering · Ransomware/data extortion · Storm ransomware group · Source: Cyber Daily

  6. 8 Sept

    Verve Portraits

    Claimed, not confirmed

    The Settra extortion group has listed Sydney-based photography studio Verve Portraits on its darknet leak site, claiming to have exfiltrated a large trove of client photos and business data; the claim has not been independently verified or confirmed by the company.

    Photography/retail services · Ransomware/data extortion · Settra cyber extortion group · Source: Cyber Daily

  7. 7 Sept

    Mathspace

    Confirmed

    Mathspace, an online mathematics learning platform used in Australian and New Zealand schools, confirmed that attackers exploited an unpatched Metabase installation to access an internal reporting system, exposing data on students, parents/guardians and school staff.

    Education technology (EdTech) · Unauthorised access via unpatched Metabase install · Source: ABC News

  8. 4 Sept

    VETtrak

    Under investigation

    Melbourne-based software firm VETtrak disclosed a cyber incident affecting its network after customers reported outages; the company has not yet confirmed the nature or scope of any data compromise.

    Software / Education technology · Cyber incident (network intrusion, cause not disclosed) · Source: Webber Insurance (aggregated reporting)

  9. 3 Sept

    Tasmanian aged care and disability not-for-profit (unnamed)

    Confirmed

    A Tasmanian aged care and disability not-for-profit confirmed it was hit by the Lynx ransomware group, which claims to have stolen client and staff data.

    Aged care / Disability services · Ransomware · Lynx ransomware · Source: Webber Insurance (aggregated reporting)

  10. 3 Sept

    NSW Health

    Claimed, not confirmed

    The MedusaLocker ransomware group listed NSW Health on its leak site claiming to have extracted 103 emails, but NSW Health has denied being the source of the breach; historical patient data spanning 1999 to 2026 appears to have been exposed, suggesting the data may have come from a third-party service provider rather than NSW Health itself.

    Government / Health · Ransomware / cyber extortion (leak-site claim) · MedusaLocker · Source: Cyber Daily

  11. 3 Sept

    Agrimac

    Claimed, not confirmed

    The Storm ransomware group claims to have hacked the Warrnambool-based farm machinery dealership Agrimac, publishing documents including payroll and customer contact data as alleged proof; the company has not publicly confirmed the incident.

    Agriculture / Farm Machinery · Ransomware / cyber extortion (leak-site claim) · Storm · Source: Cyber Daily

August 2026

8 incidents disclosed

  1. 31 Aug

    DigiGround

    Under investigation

    The Qilin ransomware group has listed the Sydney-based bespoke app developer DigiGround on its darknet leak site, but the company says it has so far found no evidence that its systems or data were compromised and is treating the claim as unverified while it investigates.

    Technology / App Development · Ransomware (leak-site claim) · Qilin ransomware group · Source: Cyber Daily

  2. 28 Aug

    Sharp Motor Group

    Confirmed

    The Storm ransomware group listed the Tweed Heads-based Sharp Motor Group on its leak site on 23 August, publishing files it claims were stolen; the dealership has confirmed its third-party IT provider was involved in a cyber incident and is actively investigating, but has not verified the attacker's claims about the scope of data stolen.

    Automotive retail · Ransomware / third-party (supply chain) compromise · Storm · Source: Cyber Daily

  3. 27 Aug

    Hachette Australia & New Zealand / Alliance Distribution Services (ADS)

    Confirmed

    Hachette Australia confirmed that its distribution subsidiary, Alliance Distribution Services, detected unauthorised activity on its computer systems believed to have begun on 18 July, severely disrupting national book distribution; the company has notified authorities but has not disclosed whether data was compromised or named an attacker.

    Publishing / logistics · Unauthorised network access (suspected ransomware) · Source: ABC News

  4. 21 Aug

    Oz Hair and Beauty

    Confirmed

    Oz Hair and Beauty confirmed that its online purchase and order platform was briefly accessed by an unauthorised third party, with limited personal information tied to purchases made before August 2026 affected.

    Retail (beauty and personal care e-commerce) · Data breach via unauthorised access to online ordering platform (cyber extortion/leak) · xpl0itrs · Source: Inside Retail

  5. 20 Aug

    Quest Apartment Hotels

    Confirmed

    Quest Apartment Hotels confirmed that unauthorised access to a database system operated by a third-party service provider compromised guests' names, emails and dates of birth, and warned customers to watch for scam attempts.

    Hospitality · Third-party/supply chain breach · Source: Cyber Daily

  6. 20 Aug

    Ramsey Bros

    Claimed, not confirmed

    The newly emerged Storm ransomware group has listed South Australian farm machinery supplier Ramsey Bros as a victim on its leak site, publishing sample documents and threatening full data release on 4 September; the company has not confirmed the intrusion.

    Agriculture / farm machinery distribution · Ransomware / data theft · Storm · Source: Cyber Daily

  7. 19 Aug

    Mighty Kingdom

    Claimed, not confirmed

    The Direwolf ransomware group has claimed on its darknet leak site to have accessed more than 260 code repositories belonging to Adelaide-based game studio Mighty Kingdom; the claim is unverified by the company.

    Video game development · Ransomware / data theft · Direwolf · Source: Cyber Daily

  8. 19 Aug

    Westco Motors Cairns

    Claimed, not confirmed

    The Storm ransomware group publicly claimed responsibility for an attack on Queensland automotive dealership Westco Motors Cairns, posting a notice threatening to leak stolen data unless negotiations occur; the dealership has not publicly confirmed the incident.

    Automotive retail · Ransomware (leak-site claim) · Storm · Source: DeXpose

July 2026

7 incidents disclosed

  1. 24 July

    LR Reed

    Resolved

    The Kairos group listed Melbourne property management firm LR Reed, claiming 335 gigabytes of data.

    Other · Data theft / extortion · Kairos · Source: Cyber Daily

  2. 23 July

    GO2 Health

    Confirmed

    Brisbane clinic GO2 Health confirmed a limited data breach after its main mailbox was accessed in April through a phishing attack, exposing information in the prior year's emails including some patients' Department of Veterans' Affairs ID numbers.

    Healthcare · Email compromise (phishing) · Source: Cyber Daily

  3. 22 July

    Origin Energy

    Confirmed

    Origin told the ASX it was investigating potential unauthorised access to customer data.

    Energy & utilities · Data theft & extortion · Source: Cyber Daily / The Nightly · Our analysis

  4. 15 July

    Partnered Health

    Confirmed

    GP network Partnered Health disclosed on 15 July that a malicious actor had accessed its network around 23 June, potentially compromising patient data across roughly 21 clinics.

    Healthcare · Cyber attack · Source: Cyber Daily

  5. 13 July

    Royal Foods

    Confirmed

    Queensland gourmet food supplier Royal Foods confirmed it was investigating an incident in which an unauthorised third party accessed part of its internal IT environment.

    Food & agriculture · Ransomware · The Gentlemen · Source: Cyber Daily

  6. 12 July

    Lifeline

    Confirmed

    Lifeline confirmed staff and volunteer data was accessed and posted to a forum for free by an actor using the handle 2019.

    Not-for-profit · Data theft (free leak) · 2019 · Source: Cyber Daily · Our analysis

  7. 1 July

    AC Small Maxwell & Co

    Claimed, not confirmed

    Threat actors linked to SafePay claimed a cyber attack on NSW accounting and advisory firm AC Small Maxwell & Co, threatening to leak allegedly stolen data.

    Professional services · Ransomware · SafePay · Source: Cyber Daily

June 2026

10 incidents disclosed

  1. 29 June

    Generation Life

    Confirmed

    Investment firm Generation Life confirmed customer information was affected by a cyber incident first identified in April, involving an attacker reaching its systems through a third-party provider.

    Financial services · Third-party breach · Source: Money Management

  2. 25 June

    NSW Rural Fire Service

    Under investigation

    The NSW Rural Fire Service said historical data was likely compromised in a security incident, while its operational response was unaffected.

    Government · Third-party breach / ransomware · Nova · Source: Information Age (ACS)

  3. 22 June

    Elina Medical Weight Loss Clinic

    Under investigation

    Melbourne clinic Elina Medical Weight Loss said it was investigating after the actor 2019 claimed to have stolen data on more than 28,000 patients.

    Healthcare · Account compromise · 2019 · Source: Cyber Daily

  4. 20 June

    Kennedy McLaughlin

    Confirmed

    Brisbane accounting firm Kennedy McLaughlin confirmed a cyber incident after a Qilin ransomware affiliate listed it and published a dataset including clients' financial details.

    Professional services · Ransomware · Qilin · Source: Cyber Daily

  5. 15 June

    Ochre Health (Tuggeranong)

    Confirmed

    Ochre Health confirmed that patient data from its Tuggeranong clinic was potentially compromised after an actor using the handle 2019 breached a third-party provider.

    Healthcare · Third-party breach / data theft · 2019 · Source: Cyber Daily

  6. 10 June

    Goodstone Group

    Confirmed

    Tasmanian hospitality group Goodstone Group, which runs hotels, bars and bottleshops around Devonport, confirmed a ransomware attack by the newly emerged CMD Organization.

    Other · Ransomware · CMD Organization · Source: Cyber Daily

  7. 10 June

    Mackay Sugar

    Confirmed

    A ransomware attack claimed by The Gentlemen forced two of Mackay Sugar's three Queensland mills offline at the start of the cane crushing season, halting harvesting across around 1,300 family farms.

    Food & agriculture · Ransomware · The Gentlemen · Source: Cyber Daily / SecurityWeek · Our analysis

  8. 2 June

    Melbourne International Film Festival

    Confirmed

    About 26,782 Melbourne International Film Festival customer records were exposed after its third-party ticketing platform Ferve was breached.

    Not-for-profit · Third-party breach (Ferve ticketing) · Source: Cyber Daily

  9. 1 June

    Australian Computer Society

    Under investigation

    The Australian Computer Society said it was investigating a possible breach after ShinyHunters claimed to have accessed its data.

    Not-for-profit · Data breach (claimed) · ShinyHunters · Source: Cyber Daily

  10. 1 June

    Tripod Farmers Group

    Confirmed

    The Qilin ransomware group listed the fresh-produce supplier Tripod Farmers after unauthorised access detected around February.

    Food & agriculture · Ransomware / data theft · Qilin · Source: Cyber Daily · Our analysis

May 2026

7 incidents disclosed

  1. 7 May

    Queensland Department of Education

    Confirmed

    The Queensland Department of Education confirmed students and staff were affected by a breach of Instructure, the third-party provider behind its QLearn platform.

    Government · Third-party breach (Instructure / QLearn) · ShinyHunters · Source: Cyber Daily

  2. 6 May

    Champion Homes

    Confirmed

    Sydney home builder Champion Homes confirmed a cyber attack that exposed a limited amount of employee and customer data.

    Other · Ransomware · DragonForce · Source: Cyber Daily

  3. 5 May

    Gregory Jewellers

    Under investigation

    Fine jewellery retailer Gregory Jewellers said it was investigating after the Kairos group claimed on 22 April to have stolen about 574 gigabytes of data.

    Retail & consumer · Ransomware / data theft · Kairos · Source: Cyber Daily

  4. 5 May

    Scope Systems

    Resolved

    Perth-based Scope Systems, an IT provider to the mining sector, confirmed a malicious actor accessed its network for under 24 hours, disrupting hosted services including Pronto Xi.

    Technology · Cyber incident (service disruption) · Source: Cyber Daily

  5. 1 May

    ALS Global

    Confirmed

    Testing and inspection firm ALS Global disclosed a cyber incident in May.

    Professional services · Ransomware / data theft · Aur0ra · Source: Cyber Daily

  6. 1 May

    Earth Systems

    Claimed, not confirmed

    The INC Ransom group listed environmental and engineering consultancy Earth Systems, claiming around 600 gigabytes of stolen data.

    Professional services · Ransomware / data theft · INC Ransom · Source: Cyber Daily

  7. 1 May

    Energy Action

    Claimed, not confirmed

    The SafePay ransomware group listed the energy-management consultancy Energy Action on its leak site, claiming roughly 470 GB of stolen data.

    Energy & utilities · Ransomware / data theft · SafePay · Source: Cyber Daily · Our analysis

April 2026

3 incidents disclosed

  1. 21 Apr

    NSW Government (Treasury)

    Confirmed

    A NSW Treasury staff member was charged after internal monitoring detected the alleged transfer of more than 5,600 restricted government documents to an external server.

    Government · Insider data breach · Source: Cyber Daily

  2. 14 Apr

    Bendigo & District Aboriginal Co-operative

    Confirmed

    The Bendigo & District Aboriginal Co-operative, which delivers health, education and community services to the Dja Dja Wurrung community, confirmed a cyber incident after being listed by INC Ransom.

    Not-for-profit · Ransomware · INC Ransom · Source: Cyber Daily

  3. 11 Apr

    Mastercom

    Under investigation

    The INC Ransom group listed Granville, NSW communications firm Mastercom, which operates Australia's largest commercial two-way radio network, and published customer, HR and financial data.

    Telecommunications · Ransomware · INC Ransom · Source: Cyber Daily

March 2026

1 incident disclosed

  1. 11 Mar

    Smile Team Orthodontics

    Confirmed

    The SafePay ransomware group listed NSW dental practice Smile Team Orthodontics and published stolen data, including staff details, personal emails, medical certificates and hundreds of DentiCare patient payment plans.

    Healthcare · Ransomware · SafePay · Source: Cyber Daily

February 2026

7 incidents disclosed

  1. 25 Feb

    Hazeldenes

    Confirmed

    A February cyber attack on major Victorian poultry processor Hazeldenes caused production disruption and regional chicken shortages.

    Food & agriculture · Ransomware · DragonForce · Source: Cyber Daily

  2. 22 Feb

    Australian federal and state courts (via VIQ Solutions)

    Confirmed

    Canadian transcription provider VIQ Solutions confirmed a security incident that exposed sensitive Australian court files after it subcontracted work to an Indian firm, e24 Technologies, allegedly in breach of its Commonwealth contracts.

    Government / justice (third-party transcription services) · Third-party / supply-chain data exposure · Source: Cyber News Centre

  3. 19 Feb

    youX

    Confirmed

    Sydney-based finance-broking platform youX confirmed unauthorised access to its systems after a threat actor released data it claims to have taken from an unsecured database.

    Financial services (fintech / asset finance) · Data breach and extortion (unsecured MongoDB Atlas cluster) · Source: Cyber News Centre

  4. 19 Feb

    youX

    Confirmed

    Sydney fintech platform youX confirmed a data breach exposing the personal and financial records of 444,538 Australians.

    Financial services · Data breach · FulcrumSec · Source: Cyber Daily

  5. 12 Feb

    Seagrass Boutique Hospitality Group

    Confirmed

    Seagrass Boutique Hospitality Group, the operator behind restaurant brands including The Meat & Wine Co and Hunter Barrel, confirmed a cyber incident involving unauthorised access to part of its network.

    Other · Ransomware · Kairos · Source: Cyber Daily

  6. 11 Feb

    Aeromedical Society of Australasia

    Confirmed

    The LockBit ransomware operation listed the Aeromedical Society of Australasia, an air-medical transport body for Australia and New Zealand, in an 11 February leak post and threatened to publish data.

    Not-for-profit · Ransomware · LockBit · Source: Cyber Daily

  7. 4 Feb

    Ansell Limited

    Claimed, not confirmed

    The 0apt group claimed a cyber attack on protective-equipment manufacturer Ansell Limited, threatening to release material it said included product formulas and supply-chain contracts.

    Manufacturing · Ransomware / data theft · 0apt · Source: DeXpose

January 2026

3 incidents disclosed

  1. 15 Jan

    Victorian Department of Education

    Confirmed

    Attackers reached a Victorian Department of Education database through a school's network, accessing names, email addresses, encrypted passwords and school details of current and former students across all 1,700 government schools.

    Government · Unauthorised access via a school network · Source: iTnews

  2. 14 Jan

    Prosura

    Confirmed

    Rental car insurer Prosura, which also trades as Hiccup, confirmed a cyber incident after attackers accessed its systems around 1 January and began contacting customers.

    Financial services · Data breach · Source: Cyber Daily

  3. 5 Jan

    Regis Resources

    Resolved

    ASX-listed gold producer Regis Resources confirmed a cyber incident first detected in mid-November 2025, after the Lynx ransomware group listed its McPhillamys Gold subsidiary on 5 January 2026.

    Other · Attempted ransomware (contained) · Lynx · Source: Cyber Daily

About this list

Entries are compiled from public reporting and official disclosures, reviewed by a person before they appear, and dated by when the incident became public rather than when it happened. The list is provided on a best-effort basis for general information only. Details often change as incidents are investigated, so each entry links to its source.

Where an incident is only an attacker's claim and the organisation has not confirmed it, it is labelled claimed, not confirmed. IronSights is not affiliated with, and makes no allegation against, the organisations listed. If you represent one and would like a correction or removal, contact us and we will review it promptly.

If your organisation is next

A breach is a bad week, not the end of one.

If you are dealing with an incident now, our Australian incident response team is available around the clock. If you are not, the cyber obligations hub explains what you would have to report, and by when.