Australian Cyber Aware – As It Was 2608 – August 2026
A monthly review of Australian and New Zealand cyber security incidents, data breaches, privacy reform, AI governance developments, audit findings, scams, and regulatory updates for August 2026.
A monthly review of Australian and New Zealand cyber security incidents, data breaches, privacy reform, AI governance developments, audit findings, scams, and regulatory updates for August 2026.
Get the latest Australian Cyber News July 2026 highlights. Stay updated on key privacy and security developments impacting businesses.
A ransomware group claims to have hacked a Broadmeadow-based office technology supplier that works with Newcastle Airport and Royal Life Saving … [...]
This monthly review provides a curated summary of cybersecurity, privacy, AI, fraud, governance, risk, and compliance developments in Australia and … [...]
The Albanese government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]
NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • … [...]
Key points Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance … [...]
Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud … [...]
Key points Vocus is grappling with a cable break on its Australia Singapore Cable (ASC) system between Perth and Singapore, following a shunt fault on … [...]
Key points Tabcorp has named Maxine Harrison as its new chief information security officer, following the former leader's departure in July. • Harrison … [...]
Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft's … [...]
in brief Scammers are exploiting the growing use of CAPTCHAs to trick people into running malicious code outside their browser. • An expert has practical … [...]
There's a warning tonight about a rise in fake digital IDs being sold to teenagers. Cyber safety experts say it's putting vulnerable Victorians at risk of having their identities stolen. [...]
The federal government has launched a pilot scheme that will allow Australians to compare the cyber security of smart devices before buying them. • … [...]
Modernised Definitions: Casting a Wider Net The Exposure Draft Bill would amend and clarify some of the foundational definitions in the Privacy Act … [...]
Shifting the emphasis from individuals upholding privacy standards to harmful and invasive business practices is the right move. But an existing … [...]
Threat detection and reporting Internal policies and procedures What policies or procedures must organisations have in place to protect data or … [...]
When Telstra engineers embarked on a simple server chassis replacement exercise in 2020, they could barely have contemplated the complex chain of … [...]
Ransomware actor claims hack of government department, but evidence suggests no malicious activity has occurred… But patient data from multiple … [...]
Claim 03-Sep-26 AU VIC
[Unconfirmed] Settra ransomware attack on Verve Portraits
Threat actor Settra has listed Victorian-based photographic business Verve Portraits, claiming 105 GB of data exfiltrated. Settra provided summaries of the information and files claimed.Â
Claim 01-Sep-26 AU VIC
[Unconfirmed] Storm ransomware attacks Australian engineering firm Macquarrie
Threat actor Storm has listed Victorian engineering firm Macquarrie on this breach notification site. Sample images, including a passport, tax file declaration, invoice and other documents, were provided as evidence.Â
If you believe any information in this post is inaccurate or incomplete, please contact us so we can review the matter. Parties with additional relevant information relating to the incident are also invited to get in touch.
Australian Insurer Ransomware Attack, 07 January 2026 Queensland-based rental car insurer Prosura...
Australian Medical Ransomware Attack, 06 Jun 2025: Victorian based Ascot Vale Health Group targeted by Global ransomware group. Global ransomware group has so far not listed how much data it has allegedly stolen or what kind of data may have been compromised.
Australian Racing Industry Ransomware Attack, 05 Jun 2025: Victorian based RISE Racing confirms Sarcoma ransomware attack. Reports indicate that 1.6GB of sensitive data was stolen, including: Banking details, financial records, participant personal information and operational data related to the racing industry.
Australian Accounting Firm Ransomware Attack, 16 May 2025: Victorian MKA Accountants confirms Qilin ransomware attack. Qilin published 12 documents as part of its leak post, including internal correspondence, financial statements, and insurance information
Australian Cyber Incident – Court Data Breach, 26 March 2025: NSW court website involved in major data breach, 9,000 documents downloaded. Man charged in connection with court document data breach.
Incident – Law Firm Ransomware Attack, 13 March 2025: Prominent Sydney law firm Brydens Lawyers reveals a serious cyber incident in the wake of a February intrusion into its network. More than 600 gigabytes of data – including case, client, and staff data – was stolen in the incident.
NZ Incident – Ransomware Attack, 28 February 2025: DragonForce Ransomware Targets Kiwi Car Dealership Tristram European. The attackers claim to have stolen over 30 gigabytes of sensitive data, including customer information and financial records.
Updated Incident – Medical Data Breach, 19 February 2025: Australian IVF provider Genea in cyber incident. Genea patients frustrated by lack of communication amid data breach.
Incident – University Ransomware Attack, 16 February 2025: Australian National University investigating alleged cyber attack by FSociety ransomware group. No ransom amount was given; however, society is threatening to publish the data within seven days.
NZ Incident – Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries like healthcare.
Quotes and Memes: "Complexity creates confusion, simplicity focus." - Edward de Bono