August 2026 So Far
Published 18-Aug-26 AU VIC
Exclusive: Patient data potentially compromised in alleged dental clinic data breach
INC Ransom cyber extortion group shares patient X-rays, specialist reports, and correspondence on the dark web after claiming a breach of a Victorian dental clinic, Brighton East Dental Clinic.
Published 18-Aug-26 AU VIC
Exclusive: SIA Medical Centre confirms it is investigating cyber incident involving patient data
Victorian-based SIA Medical Centre is responding to a ransomware incident after the Rhysida cyber extortion group claimed to have thousands of patient records.
Published 18-Aug-26 AU NSW
Exclusive: Oz Hair and Beauty confirms cyber incident
Oz Hair & Beauty was listed on the dark web leak site of a threat actor “xpl0itrs”, which claimed to have stolen 2,100,000 customer records containing names, email addresses, home addresses, phone numbers and the last four digits of active gift cards. The threat actor did not post any corroborating evidence.
Claim 18-Aug-26 AU SA
[Unconfirmed] Storm listing puts a farm-equipment dealer in the ransomware crosshairs
Threat actor Storm names South Australian farming equipment dealer Ramsey Bros as a victim. The report provided sample screenshots of files as evidence.
Claim 18-Aug-26 AU QLD
[Unconfirmed] Storm names motor dealer Westco Motors Cairns as ransomware victim
Westco Motors Cairns has appeared in a new victim listing associated with Storm, putting the Cairns dealership into the public frame of a ransomware and extortion event. Some screenshots of files were presented as evidence.
Claim 17-Aug-26 AU SA
[Unconfirmed] An extortion claim by Direwolf has been made against South Australian games developer Mighty-Kingdom
Threat actor Direwolf has made a claim against South Australian games developer Mighty-Kingdom. No clear evidence was posted in the claim.
Claim 14-Aug-26 AU NSW
[Unconfirmed] Ollies Place Kidswear has been listed by thegentlemen ransomware group
New South Wales retailer Ollies Place Kidswear has been listed on TheGentleman's breach site. No details of the breach or sample files could be located.
Published 14-Aug-26 AU NSW
Exclusive: Australian truck trailer company Midland among dozens of victims listed by Cl0p cyber extortion group
Midland was listed on 12 August, with Cl0p claiming to have accessed half a gigabyte of data, which the hackers claim includes project information and at least one database.
Confirmed 14-Aug-26 AU NSW
Aussie furniture company Nick Scali discloses cyber incident
Furniture retailer Nick Scali has said it is investigating a security incident in a disclosure to the Australian Stock Exchange. The company was forced to take “certain systems” offline in the wake of a cyber attack, and customer orders were impacted.
Claim 13-Aug-26 AU VIC
[Unconfirmed] Ransomware group Storm publicly claimed responsibility for a cyberattack against 3-point Australia
Victorian project management consultancy 3-point Australia has been reported breached by threat actor Storm. Storm listed various documents, including passports, as evidence of the exfiltration.
12-Aug-26 AU NSW
AONSW Multiple Agencies
AUDIT: Internal controls and governance 2026: grants, consultants, purchasing cards and technology
Less than half of agencies reported compliance with requirements to protect and govern their risk exposure. Some agencies did not assess risks from legacy systems that cannot be patched, increasing their exposure to cyber-attack.
12-Aug-26 AU TAS
AuditTas Finance Multiple Agencies
AUDIT: Auditor-General’s Report on the Financial Statements of State Entities 2025-26, Volume 1
Our audits continue to identify recurring weaknesses in core control disciplines. These issues have been reported repeatedly over several years and should no longer be regarded as emerging challenges. They are known risks requiring sustained management attention. This includes matters on cyber security and information technology. However, due to the sensitive nature of these matters, only limited detail has been included in the report to avoid identifying potential security vulnerabilities.
Published 03-Aug-26 AU VIC
Exclusive: Qilin claims breach of Victoria-based flooring firm
Asset Flooring Group was listed on the dark web by the infamous Qilin ransomware group overnight, with the threat actor claiming to have stolen 45 gigabytes of data.
If you believe any information in this post is inaccurate or incomplete, please contact us so we can review the matter. Parties with additional relevant information relating to the incident are also invited to get in touch.