Select Page

Australian Cyber Aware

Providing Australian and New Zealand news and services on cybersecurity, information security, privacy, and AI security.
Vendor-neutral, press release-free, and advertisement-free.

Please follow the Source link to the original article to support the content owner. We only provide a summary with metadata to assist in categorisation.

Monthly Australian Cyber News Summaries

Loading

Email Subscription

Australian Info & Cyber Security News

Exclusive: Shellharbour-based Leisure Coast Kitchens listed by Kairos ransomware group

Hackers have published employee driver’s licenses, tax file numbers, and customer correspondence, with more data to come. • Fri, 18 Sep 2026 • Security … [...]

Australian government launches consultation period on the future of AI in the country

Canberra is looking for feedback on its approach to AI and its infrastructure in Australia, from data centre growth to consumer costs. • Fri, 18 Sep … [...]

Optus may ban smart glasses in stores, offices

Key points Optus is discussing cyber security policies that could regulate or even ban smart glasses in its stores and offices. • EGM security and risk … [...]

RentTech companies asking tenants for personal details ‘completely outside’ new Victorian laws

Some rental platforms encourage hopeful tenants to share ‘excessive’ amount of information, Consumer Policy Research Centre review finds [...]

Australia’s outdated technology is vulnerable to AI hacking attacks, signals chief says

Abigail Bradshaw says ‘enormous’ amounts of money required to update systems that people now expect to be constantly available [...]

NDIS data may have ended up in Palantir’s analytics platform as part of efforts to curb fraud

Exclusive: The Australian Criminal Intelligence Commission, which has access to NDIA data, used Palantir as part of a multi-agency fraud taskforce [...]

Quest hotel data breach affects one million guests | 7NEWS

More than one million Quest apartment hotel guests have had their personal data stolen by hackers in a major data breach. The compromised information includes names and contact details from [...]

AI companies would need to report 'rogue' incidents under proposed national standards | ABC NEWS

The Prime Minister is travelling to the United States, where he'll meet with world leaders to discuss online safety and artificial intelligence. After stark warnings from industry heavyweights this week [...]

Cybersecurity spy chief sounds alarm over AI | ABC NEWS

The Director-General of the Australian Signals Directorate says Australia needs an AI 'early warning system' to defend against the dangers of the emergent technology. Abigail Bradshaw also struck a more [...]

AUSCERT Week In Review for 18th of September

September is MFA Month, making it the perfect time to review one of the simplest and most effective cyber security measures available: multi-factor … [...]

Judge orders parties to probe use of AI to prepare evidence – Proctor

Cairns bailiff takes on new role after admission sitting Shayne Vigorelli was one of six lawyers admitted to the Supreme Court of Queensland as a … [...]

Scam alert: Scammers are impersonating ASIC via SMS. Scammers are sending SMS messages impersonating ASIC and urging recipients to call a fake phone number. The messages falsely state there… | ASIC

Scam alert: Scammers are impersonating ASIC via SMS. Scammers are sending SMS messages impersonating ASIC and urging recipients to call a fake phone … [...]

Optus outage attributed to hardware failure at exchange

Key points A hardware failure at an Optus exchange in Victoria caused a voice outage lasting about one hour and 16 minutes on Friday. • The outage … [...]

Digital platforms to be targeted as part of NSW crackdown on organised crime operations

NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • … [...]

Exclusive: Penfold Motors latest car dealer to fall victim to the Storm ransomware group

Victorian car dealership says it is contacting its customers after their contact and vehicle details were compromised by hackers. • Mon, 14 Sep 2026 • … [...]

ATO employee charged over alleged disclosure of information to organised crime groups

A Gold Coast man who worked with the Australian Taxation Office (ATO) has been charged over the alleged disclosure of information to organised crime … [...]

Cyber Wardens program to shut down as government funding ends

The COSBOA CEO says lessons learnt from the program “will help shape what comes next” as she celebrates assisting 23,150 small businesses. • Fri, 11 … [...]

Nick Scali security breach: What it means for customer information

Furniture giant Nick Scali has confirmed New Zealand customers’ personal details were held on systems affected by a security breach last month. In an … [...]

Australian Cyber Incidents and Audits Reports

September 2026 so far

Thorndale FoundationClaim 16-Sep-26 AU NSW
[Unconfirmed] Thorndale Foundation has been listed by the ransomware group Qilin as a victim of their attack.
Thorndale Foundation is a disability support services organisation operating in Western Sydney and has been listed by threat actor Qilin as a victim. The attackers posted sample images of passports, staff and contractor clearances, and other documents as proof of the claim.

Reddrop GroupClaim 16-Sep-26 AU VIC
[Unconfirmed] Threat actor Qilin has posted a breach claim against an Australian independent supermarket chain.
The Reddrop Group, a prominent Victorian independent supermarket, has been listed as a victim of a cyberattack by the Qilin ransomware group. Qilin provided no published evidence to support the claim.

Leisure Coast KitchensClaim 16-Sep-26 AU NSW
[Unconfirmed] Leisure Coast Kitchens listed as a victim of Kairos ransomware group.
New South Wales' Leisure Coast Kitchens has been named by the Kairos ransomware group on a leak site. As of 17 September 2026, no public confirmation from the company, regulators, or mainstream media has been identified, so the claim remains unverified.

Alchin Long GroupClaim 15-Sep-26 AU NSW
[Unconfirmed] TheGentlemen Ransomware Attack on Alchin Long Group
On September 15, 2026, the ransomware group The Gentlemen publicly claimed responsibility for a cyberattack against Alchin Long Group, a prominent Australian hardware conglomerate. The group posted an extortion notice threatening to leak sensitive data unless negotiations were initiated.

Auto-ITConfirmed 15-Sep-26 AU VIC
Exclusive: Aussie software firm Auto-IT confirms customers compromised by Storm ransomware attack
Maker of dealer management software responds to dark web hacking claims, saying a “small number of Auto-IT customer environments” were impacted by an unauthorised external party. On 18 August, the threat actor Storm, started listing Australian car dealerships and auto and machinery suppliers. Among the first were Westco Motors Cairns, alongside Ramsey Bros and Penfold Motors. The Sharp Motor Group, Agrimac, and Macquarrie followed. 

St James Anglican SchoolConfirmed 15-Sep-26 AU WA
Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack
St James Anglican School, in Perth’s north, identified a cyber breach involving unauthorised access into its computer systems. Hackers copied names, addresses, emails, phone numbers, bank account details, student medical records and photographs of current and former students enrolled at the school since 2015, according to The West Australian. 

Dome Gold MinesClaim 14-Sep-26 AU NSW
[Unconfirmed] Dome Gold Mines listed by The Gentlemen Ransomware Group
Dome Gold Mines was listed on The Gentlemen's leak site. The Gentlemen claims it stole internal data. This is the group's claim, not a confirmed finding.

Penfold MotorsConfirmed 14-Sep-26 AU VIC
Exclusive: Penfold Motors latest car dealer to fall victim to the Storm ransomware group
Victorian car dealership Penfold Motors says it is contacting customers after hackers compromised their contact and vehicle details. Data published so far includes staff efficiency reports, customer details, vehicle identification numbers, and tax invoices. 

Way ForwardConfirmed 10-Sep-26 AU NSW
Exclusive: Not-for-profit Way Forward suspends payments following external cyber incident
The New South Wales registered charity Way Forward has disclosed that its payment systems have been suspended following a third-party cyber incident.

Sharp OfficeConfirmed 09-Sep-26 AU VIC
Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation
The ransomware group known as The Gentlemen has targeted Sharp Office, a Hunter Region office technology specialist, as its latest Australian victim.

MathspaceConfirmed 08-Sep-26 AU NSW
Late patching of Metabase SQLi bug claims Sydney's Mathspace
Unknown attackers exploited a critical vulnerability in the Metabase business intelligence (BI) tool to breach the online mathematics learning platform Mathspace. Stolen data includes user IDs, usernames, first and last names, email addresses and other login-related information for students, staff, parents and guardians.

Verve PortraitsPublished 08-Sep-26 AU VIC
Exclusive: Verve Portraits data allegedly compromised by Settra ransomware attack
Threat actor Settra has listed the Victorian-based photography business Verve Portraits, claiming that 105 GB of data was exfiltrated. Settra provided summaries of the information and files claimed. 

MacquarriePublished 08-Sep-26 AU VIC
Exclusive: Machinery management specialist Macquarrie investigating data breach after ransomware claims
The Storm ransomware group continues to target Australian companies, this time adding the Victoria-based Macquarrie Corporation to its leak site last week. Sample images, including a passport, tax file declaration, invoice and other documents, were provided as evidence.

Telstra03-Sep-26 AU ACMA Telcommunication 
ACMA fines Telstra for SIM swapping prevention misses
Telstra has been fined $277,000 by the Australian Communications and Media Authority (ACMA) for not using required identity authentication processes to prevent SIM swapping fraud. In addition to the penalty, the ACMA has accepted court-enforceable undertakings from Telstra to strengthen its fraud prevention processes and improve training for customer-facing staff. 

The Art Scene01-Sep-26 AU NSW
NSW District Court, Privacy Act
A Canva account at centre of legal fight over employee privacy
Australia’s new privacy laws have been used to prevent a business, The Art Scene, from destroying a former employee’s personal information, including family medical records, that were stored on a Canva account, in an unusual early application of the new rules. 

 

If you believe any information in this post is inaccurate or incomplete, please contact us so we can review the matter. Parties with additional relevant information relating to the incident are also invited to get in touch.

Australian InfoSec Incidents and Audits Issues

NZ Incident: KillSec claims breach of NZ medical supplier | Cyberdaily.au

NZ Incident – Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries like healthcare.

Loading

Information Security Memes