Select Page

Australian Cyber Aware

Providing Australian and New Zealand news and services on cybersecurity, information security, privacy, and AI security.
Vendor-neutral, press release-free, and advertisement-free.

Please follow the Source link to the original article to support the content owner. We only provide a summary with metadata to assist in categorisation.

Featured

Latest

Email Subscription

Australian Info & Cyber Security News

Australian privacy law is not standing still. In 2026, businesses face a wave of new compliance obligations: mandatory disclosure requirements for… [...]

Privacy awareness 2026: Trust is built when things go wrong

How cyber and data teams support effective privacy complaint resolution When talking about privacy, the focus is often on protection - strong … [...]

Queensland students unable to submit assignments after cyber attack forces shutdown of QLearn and Canvas

Hackers accessed data linked to 1300 schools, leaving thousands scrambling to submit assignments and access coursework. [...]

Hackers just stole data from 9,000 schools and unis around the world. How can we protect student privacy?

This week, US-based education technology provider Instructure announced a significant cybersecurity incident affecting its Canvas system. This is … [...]

Australia warns finance firms over AI-driven cyber risks

The Australian Securities and Investments Commission (ASIC) told financial firms to strengthen cyber defenses, warning that advanced AI models such … [...]

APRA calls for step-change in AI risk management across financial sector

The Australian Prudential Regulation Authority (APRA) has urged banks, insurers and superannuation trustees to lift how they manage artificial … [...]

Queensland education breach highlights third-party cyber risk concerns

A third-party data breach disclosed by the Queensland Department of Education has renewed scrutiny on cyber risks tied to vendors and online learning … [...]

ASIC calls for financial sector uplift as AI cyber threats take hold

The Australian Securities and Investments Commission (ASIC) has urged financial services firms to bolster their cyber resilience as AI tools expand … [...]

New Zealand announces new sanctions against Russian cyber actors, online support platforms

The New Zealand government has announced a new round of sanctions targeting malicious Russian, North Korean, and Iranian cyber actors as well as … [...]

Police advised to disable bluetooth on Axon body-worn cameras to avoid detection by criminals

Thousands of police officers have been told to disable the bluetooth on their Axon body-worn cameras during raids and undercover jobs to avoid being … [...]

Aussie schools breach: The Instructure hack “transcends an isolated IT incident”

Schools and universities across Australia have been caught up in a global IT breach, with possibly lifelong impacts for students. • Fri, 08 May 2026 • … [...]

Hacked: ALS discloses cyber incident, unauthorised access to IT systems

The global scientific testing company told the ASX that “malicious cyber activity” caused some operational disruptions. • Wed, 06 May 2026 • … [...]

Australian Cyber Incidents and Audits Reports

Australian Cyber Aware News and Breaches

Latest

Australian Cyber Aware – As It Was 2604 – April 2026

Australian Cyber Aware - As It Was 2604 - April 2026. This monthly review provides a curated summary of Australian and New Zealand cyber, privacy, and information security developments identified during April 2026. It includes a cross-section of incidents, regulatory updates, audit findings, and broader industry developments relevant to business and government audiences.

May 2026 So Far

Claim Status: Confirmed = Acknowledged by organisation/public statement/regulator | Published = Published in mainstream or reputable media | Claim = Leak-site claim only, unverified | Withdrawn = The claim has been withdrawn | Denied = The victim has formally denied the claim | Unknown = No corroborating evidence has been found

Claim 08-May-26 AU VIC
[Unconfirmed] Incransom claims to have hacked an Australian-based environmental solutions company, Earth Systems
Earth Systems is an environmental and social science and engineering company that develops and implements innovative and effective environmental, water, and sustainability solutions worldwide. 

Published 07-May-26 AU QLD
Exclusive: Aussie car parts importer Strategic Imports allegedly breached by threat actors
Threat actors have claimed responsibility for a cyberattack on a Queensland automotive parts importer, Strategic Imports, alleging they exfiltrated data from its network.

Confirmed 07-May-26 AU QLD
Qld gov says students, staff caught in Canvas cyber incident
"Education Queensland says that students and staff working or studying at state schools since 2020 may have been caught up in a breach of the global education systems vendor, Instructure. Multiple institutions, including RMIT University, UTS, TasTAFE Tasmania and Western Sydney University, were urgently assessing their potential exposure to the incident."

Claim 06-May-26 NZ
[Unconfirmed] Ransomware group The Gentlemen has claimed to have breached New Zealand sporting distributor Worralls
W.H. Worrall & Co. Limited (Worralls) is New Zealand's leading distributor of world-class cycling and sporting brand

Confirmed 06-May-26 AU QLD
Hacked: ALS discloses cyber incident, unauthorised access to IT systems
Queensland-based scientific testing company ALS recently reported to the ASX that it "identified malicious cyber activity involving unauthorised third-party access to some of our IT systems.” No details are available on the incident.

Published 06-May-06 AU NSW
Exclusive: Australian energy management firm allegedly breached by SafePay
Threat actor SafePay has claimed responsibility for a cyberattack on an NSW energy management and consulting firm, Energy Action, threatening to release allegedly stolen data within a number of days.

Claim 06-May-26 AU NSW
[Unconfirmed] M3rx claimed to have exfiltrated 140 gigabytes of data from Australian toy retail company KB Toys.
KB Toys is a retail company based in Australia that sells toys, games, and children’s entertainment products.
Ransomware notification sites reported that M3rx had successfully infiltrated kbtoys.com.au on May 6. The attackers claim to have exfiltrated 140 gigabytes of data, spanning nearly 37,000 files.

Confirmed 05-May-26 AU NSW
Exclusive: Champion Homes confirms customer data compromised in ‘cyber event’
Australian home builder Champion Homes has confirmed it was recently the victim of a cyber attack that exposed a limited amount of employee and customer data. DragonForce ransomware operation threatened to publish a 44-gigabyte dataset on the dark web.

Confirmed 04-May-26 AU NSW
Exclusive: Major Australian jewellery brand confirms cyber incident
Gregory Jewellers is an Australian-owned retailer that specialises in fine jewellery, watches, and accessories. The company was listed on the Kairos ransomware gang's dark web leak site, which claimed to have stolen 574 gigabytes of data from it.

Confirmed 04-May-26 NZ
Exclusive: Kiwi firm, McKay electrical contractor, confirms cyber attack
McKay, one of New Zealand’s largest privately owned electrical contractors, has confirmed it was the victim of a cyber attack in January, after it was listed as a victim on the darknet leak site of a newly emerged ransomware group.

Claim 01-May-26 AU
[Unconfirmed] Fulcrumsec claims breach of YOUX / DRIVE IQ, formerly known as Drive IQ, is an Australian technology company specialising in connected vehicle data and mobility intelligence.

Published 01-May-26 AU NSW
Exclusive: Prime Properties listed as breach victim by M3rx ransomware
Hackers are alleged to have stolen more than 80,000 documents totalling 100 gigabytes of data from a Sydney-based property investment firm, Prime Properties.

If you believe any information in this post is inaccurate or incomplete, please contact us so the matter can be reviewed. Parties with additional relevant information relating to the incident are also invited to get in touch.

Australian InfoSec Incidents and Audits Issues

NZ Incident: KillSec claims breach of NZ medical supplier | Cyberdaily.au

NZ Incident – Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries like healthcare.

Update AU Incident: The University of Notre Dame Australia confirms cyber incident | Cyberdaily.au

Updated AU Incident – Education Cyber Attack, 04 February 2025: The University of Notre Dame Australia in Western Australia confirms cyber incident. Claims are that 62.3 Gb of data was exfiltrated. Containing employee and student contact data, medical documents, confidential agreements and licenses. Problems with enrolling and accessing class timetables, weeks after a cyber attack

Loading

Information Security Memes