Australian Cyber Aware – As It Was 2608 – August 2026
A monthly review of Australian and New Zealand cyber security incidents, data breaches, privacy reform, AI governance developments, audit findings, scams, and regulatory updates for August 2026.
A monthly review of Australian and New Zealand cyber security incidents, data breaches, privacy reform, AI governance developments, audit findings, scams, and regulatory updates for August 2026.
Get the latest Australian Cyber News July 2026 highlights. Stay updated on key privacy and security developments impacting businesses.
COSBOA CEO says lessons learned from the program “will help shape what comes next” as she celebrates assisting 23,150 small businesses. • Fri, 11 Sep … [...]
Furniture giant Nick Scali has confirmed New Zealand customers’ personal details were held on systems affected by a security breach last month. In an … [...]
Millions of people, including school students, have had their data exposed in a data breach on an education website. | Subscribe and 🔔: http://9Soci.al/KM6e50GjSK9 | Get more breaking news at [...]
There's a new warning tonight: artificial intelligence is about to make cyber criminals far more dangerous. One of Australia's most respected cyber security figures has told 7NEWS, AI has transformed [...]
A ransomware group claims to have hacked a Broadmeadow-based office technology supplier that works with Newcastle Airport and Royal Life Saving … [...]
This monthly review provides a curated summary of cybersecurity, privacy, AI, fraud, governance, risk, and compliance developments in Australia and … [...]
The Albanese government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]
NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • … [...]
Key points Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance … [...]
Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud … [...]
Key points Vocus is grappling with a cable break on its Australia Singapore Cable (ASC) system between Perth and Singapore, following a shunt fault on … [...]
Key points Tabcorp has named Maxine Harrison as its new chief information security officer, following the former leader's departure in July. • Harrison … [...]
Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft's … [...]
in brief Scammers are exploiting the growing use of CAPTCHAs to trick people into running malicious code outside their browser. • An expert has practical … [...]
There's a warning tonight about a rise in fake digital IDs being sold to teenagers. Cyber safety experts say it's putting vulnerable Victorians at risk of having their identities stolen. [...]
The federal government has launched a pilot scheme that will allow Australians to compare the cyber security of smart devices before buying them. • … [...]
Modernised Definitions: Casting a Wider Net The Exposure Draft Bill would amend and clarify some of the foundational definitions in the Privacy Act … [...]
Confirmed 10-Sep-26 AU NSW
Exclusive: Not-for-profit Way Forward suspends payments following external cyber incident
The New South Wales registered charity Way Forward has disclosed that its payment systems have been suspended following a third-party cyber incident.
Confirmed 09-Sep-26 AU VIC
Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation
The ransomware group known as The Gentlemen has targeted Sharp Office, a Hunter Region office technology specialist, as its latest Australian victim.
Confirmed 08-Sep-26 AU NSW
Late patching of Metabase SQLi bug claims Sydney's Mathspace
Unknown attackers exploited a critical vulnerability in the Metabase business intelligence (BI) tool to breach the online mathematics learning platform Mathspace. Stolen data includes user IDs, usernames, first and last names, email addresses and other login-related information for students, staff, parents and guardians.
Published 08-Sep-26 AU VIC
Exclusive: Verve Portraits data allegedly compromised by Settra ransomware attack
Threat actor Settra has listed the Victorian-based photography business Verve Portraits, claiming that 105 GB of data was exfiltrated. Settra provided summaries of the information and files claimed.
Published 08-Sep-26 AU VIC
Exclusive: Machinery management specialist Macquarrie investigating data breach after ransomware claims
The Storm ransomware group continues to target Australian companies, this time adding the Victoria-based Macquarrie Corporation to its leak site last week. Sample images, including a passport, tax file declaration, invoice and other documents, were provided as evidence.
03-Sep-26 AU ACMA Telcommunication
ACMA fines Telstra for SIM swapping prevention misses
Telstra has been fined $277,000 by the Australian Communications and Media Authority (ACMA) for not using required identity authentication processes to prevent SIM swapping fraud. In addition to the penalty, the ACMA has accepted court-enforceable undertakings from Telstra to strengthen its fraud prevention processes and improve training for customer-facing staff.
If you believe any information in this post is inaccurate or incomplete, please contact us so we can review the matter. Parties with additional relevant information relating to the incident are also invited to get in touch.
Australian Insurer Ransomware Attack, 07 January 2026 Queensland-based rental car insurer Prosura...
Australian Medical Ransomware Attack, 06 Jun 2025: Victorian based Ascot Vale Health Group targeted by Global ransomware group. Global ransomware group has so far not listed how much data it has allegedly stolen or what kind of data may have been compromised.
Australian Racing Industry Ransomware Attack, 05 Jun 2025: Victorian based RISE Racing confirms Sarcoma ransomware attack. Reports indicate that 1.6GB of sensitive data was stolen, including: Banking details, financial records, participant personal information and operational data related to the racing industry.
Australian Accounting Firm Ransomware Attack, 16 May 2025: Victorian MKA Accountants confirms Qilin ransomware attack. Qilin published 12 documents as part of its leak post, including internal correspondence, financial statements, and insurance information
Australian Cyber Incident – Court Data Breach, 26 March 2025: NSW court website involved in major data breach, 9,000 documents downloaded. Man charged in connection with court document data breach.
Incident – Law Firm Ransomware Attack, 13 March 2025: Prominent Sydney law firm Brydens Lawyers reveals a serious cyber incident in the wake of a February intrusion into its network. More than 600 gigabytes of data – including case, client, and staff data – was stolen in the incident.
NZ Incident – Ransomware Attack, 28 February 2025: DragonForce Ransomware Targets Kiwi Car Dealership Tristram European. The attackers claim to have stolen over 30 gigabytes of sensitive data, including customer information and financial records.
Updated Incident – Medical Data Breach, 19 February 2025: Australian IVF provider Genea in cyber incident. Genea patients frustrated by lack of communication amid data breach.
Incident – University Ransomware Attack, 16 February 2025: Australian National University investigating alleged cyber attack by FSociety ransomware group. No ransom amount was given; however, society is threatening to publish the data within seven days.
NZ Incident – Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries like healthcare.
Quotes and Memes: "Complexity creates confusion, simplicity focus." - Edward de Bono