
Generation Life – June 2026
Aussie investment firm has confirmed that customer data was impacted in a cyber attack it suffered back in April. | The firm confirmed that services remain operating as normal, and that core systems for investment operations remain unaffected, with client investments and funds not impacted.

NSW Rural Fire Service (RFS) – June 2026
NSW Rural Fire Service warns members of ‘cyber security incident’ | NSW RFS commissioner says there is “no impact to our operational response capability”, but historical data likely compromised.

Elina Medical Weight Loss Clinic – June 2026
An infamous threat actor has claimed a cyber attack on an Australian weight-loss clinic | We can confirm two Elina HotDoc user accounts were logged into by an unknown third party. The incident was quickly contained, with activity limited to these Elina accounts

Ochre Medical Centre – June 2026
Ochre Health confirms patient data from its Tuggeranong clinic potentially compromised | Threat actor 2019 claimed to have breached the data of more than 25,000 patients via a third-party platform – and it’s already been sold on a hacking forum.

Mackay Sugar – June 2026
2 Mackay sugar mills shut down following cyber incident | A cyber incident has led to operations at two sugar mills in the Mackay region of North Queensland being halted.

Melbourne International Film Festival (MIFF) – June 2026
Melbourne International Film Festival responding to cyber incidents | MIFF releases statement after hacker claims to have breached the details of more than 340,000 customers.

Kennedy McLaughlin – May 2026
Accounting firm Kennedy McLaughlin confirms ‘cyber incident’ following Qilin ransomware attack | Queensland-based firm Kennedy McLaughlin says it has notified impacted individuals as hackers publish client financial and banking data online.

Goodstone Group – May 2026
Tassie hospitality group confirms CMD Organization ransomware attack | A new hacking group targets Devonport-based Goodstone Group, compromising employee passports in the attack.

Canvas – May 2026
Australian educational facilities impacted as ‘criminal’ hacks Canvas learning platform | It is used by schools, universities and vocational education facilities across the world, including Australia, to deliver and manage learning for students and staff.

Scope Systems – May 2026
Western Australia-based software deployment specialist and reseller Scope Systems has disclosed a cyber incident but said no data loss occurred. | News of the incident was first reported by WA Business News, but the firm has since disclosed details.

Queensland Department of Education – May 2026
Queensland Department of Education confirms students, staff impacted by ShinyHunters data breach | The state education minister says “names, email addresses, and school locations” were compromised by a hack of a third-party cloud provider, Instructure.

Champion Homes – May 2026
Champion Homes confirms customer data compromised in ‘cyber event’ | A Sydney-based home builder will contact impacted customers following the DragonForce ransomware attack.

Gregory Jewellers – May 2026
Major Australian jewellery brand confirms cyber incident | Threat actors have claimed a cyber attack on an Australian fine jewellery retailer, claiming to have stolen over half a terabyte of data.

Gelatissimo – April 2026
Gelatissimo confirms unauthorised access, investigates DragonForce hack claims | Major Australian ice-cream retailer Gelatissimo has launched an investigation into claims made by hackers that the company was breached in a ransomware incident.

Genealogy SA – April 2026
SA genealogical research firm confirms cyber incident following SafePay ransom claims | We can confirm that the incident is resolved, and we have communicated with our members about the incident.

NSW Government – April 2026
Treasury staffer charged for NSW government data breach | The NSW Government declared a significant data breach over the weekend, which it says involved alleged data transfer by a staff member. An arrest has since been made.

Mastercom – April 2026
Aussie communications company Mastercom ‘aware’ of INC Ransom claims | Hackers have published customer and hardware data belonging to a Sydney-based firm providing communications solutions to hundreds of businesses and local councils

Booking.com – April 2026
Data Breach Exposes Supply Chain Vulnerabilities as Customers Face Targeted Phishing | Booking.com confirms hackers accessed customer names, emails, addresses, and booking details via third-party compromise.

Bendigo & District Aboriginal Co-operative (BDAC) – April 2026
Aboriginal community organisation confirms cyber incident following INC Ransom claims | The issue was identified promptly, contained the same day, and our systems are secure. There has been a limited impact on our services to community.

Smile Team Orthodontics – March 2026
SafePay ransomware claims hack of Smile Team Orthodontics | Hackers publish stolen data, including staff details, addresses, and patient payment plans, to the dark web.

LexisNexis – March 2026
LexisNexis Confirms Major Cloud Breach, Exposing Legal and Government Client Data | The company is a critical information supplier for many Australian law firms, courts, and federal agencies, making this breach a significant supply chain security event.

Hazeldenes – February 2026
Aussie poultry processor confirms cyber attack, chicken shortages hit customers | Victoria-based Hazeldenes is investigating a cyber incident that has led to shortages of chicken products in the surrounding community.

The Aeromedical Society of Australasia (ASA) – February 2026
Aeromedical Society of Australasia confirms cyber incident following LockBit ransomware claims | A resurrected hacking group has targeted an air medicine not-for-profit, threatening to publish stolen data by month’s end.

youX – February 2026
Aussie FinTech platform youX confirms data breach as hacker shares massive dataset online | Hacker claims compromise of 141 gigabytes of data from a MongoDB Atlas cluster, more than 600k loan applications to almost 100 lenders potentially compromised.

Seagrass Boutique Hospitality Group – February 2026
Aussie hospitality group confirms cyber incident, claimed by Kairos ransomware | An Australian hospitality company has confirmed that it suffered a cyber incident, following claims by a notorious hacking group that they launched an attack on the company’s network, exfiltrating data.

Victorian Department of Education – January 2026
The Victorian Department of Education has confirmed a major data breach | Impacting all 1700 of its government schools, with the personal information of current and former students accessed by an unauthorised third party.

Prosura – January 2026
Prosura Breach Exposes 300,000 Customers | Australian car rental insurer Prosura has suffered a major data breach, exposing the personal and policy information of an estimated 300,000 customers.

Regis Resources – January 2026
Major Australian gold producer confirms cyber attack | ASX-listed gold producer Regis Resources has confirmed a cyber incident targeting its network, after hackers claimed to have breached the company.