Yearly Breach Reports Summary 2023
This is a listing of all publicly disclosed Australian cyber-attacks and data breaches from 2023.
This is a listing of all publicly disclosed Australian cyber-attacks and data breaches from 2023.
Australian Medical Ransomware Attack, 06 Jun 2025: Victorian based Ascot Vale Health Group targeted by Global ransomware group. Global ransomware group has so far not listed how much data it has allegedly stolen or what kind of data may have been compromised.
Australian Racing Industry Ransomware Attack, 05 Jun 2025: Victorian based RISE Racing confirms Sarcoma ransomware attack. Reports indicate that 1.6GB of sensitive data was stolen, including: Banking details, financial records, participant personal information and operational data related to the racing industry.
Australian Accounting Firm Ransomware Attack, 16 May 2025: Victorian MKA Accountants confirms Qilin ransomware attack. Qilin published 12 documents as part of its leak post, including internal correspondence, financial statements, and insurance information
Australian Cyber Incident – Court Data Breach, 26 March 2025: NSW court website involved in major data breach, 9,000 documents downloaded. Man charged in connection with court document data breach.
Incident – Law Firm Ransomware Attack, 13 March 2025: Prominent Sydney law firm Brydens Lawyers reveals a serious cyber incident in the wake of a February intrusion into its network. More than 600 gigabytes of data – including case, client, and staff data – was stolen in the incident.
NZ Incident – Ransomware Attack, 28 February 2025: DragonForce Ransomware Targets Kiwi Car Dealership Tristram European. The attackers claim to have stolen over 30 gigabytes of sensitive data, including customer information and financial records.
Updated Incident – Medical Data Breach, 19 February 2025: Australian IVF provider Genea in cyber incident. Genea patients frustrated by lack of communication amid data breach.
Incident – University Ransomware Attack, 16 February 2025: Australian National University investigating alleged cyber attack by FSociety ransomware group. No ransom amount was given; however, society is threatening to publish the data within seven days.
NZ Incident – Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries like healthcare.
Updated AU Incident – Education Cyber Attack, 04 February 2025: The University of Notre Dame Australia in Western Australia confirms cyber incident. Claims are that 62.3 Gb of data was exfiltrated. Containing employee and student contact data, medical documents, confidential agreements and licenses. Problems with enrolling and accessing class timetables, weeks after a cyber attack
Employee identity documents and Melbourne crane collapse data were posted to the dark web by SafePay ransomware gang. • Wed, 22 Apr 2026 • … [...]
Australian rental technology platform 2Apply collected excessive personal information from prospective tenants and used harmful "dark patterns" to … [...]
ANZ Banking Group’s chief information security officer of almost three years Dr Maria Milosavljevic has retired, with an interim security chief now … [...]
The NSW government declared a significant data breach over the weekend, which it says involved alleged data transfer by a staff member. An arrest has … [...]
An NSW Treasury staff member stands accused of exfiltrating a “substantial cache” of more than 5600 sensitive documents authored by multiple state … [...]
A NSW Treasury employee has been charged after allegedly accessing and illegally downloading more than 5600 sensitive government documents. Police … [...]
A new online marketplace scam has emerged, using a QR code to funnel unsuspecting victims to a fake Australia Post website. 10 News+ breaks down the warning signs to watch [...]
A major investigation into Kim Jong-Un’s devious plan to send North Korean spies to work at IT firms in Australia, the United States and other Western countries. *Quid Game (2026)* [...]
A cybercriminal could find personal information on more than half of all Australians via their public social media accounts, according to new … [...]
A public health patient has called on South Australia's health minister to apologise after his office released her medical history to journalists … [...]
Travel and reservations giant Booking.com has notified an unknown number of customers about a data breach affecting “anything” they’ve shared with … [...]
A 22-year-old Adelaide man who allegedly went on a "cybercrime spree", targeting several government departments and a courthouse, will remain behind … [...]
Quotes and Memes: "There are two types of companies: those who have been hacked, and those who don’t yet know they have been hacked" - John Chambers