Select Page

Australian Cyber Aware

Providing Australian and New Zealand news and services on cybersecurity, information security, privacy, and AI security.
Vendor-neutral, press release-free, and advertisement-free.

Please follow the Source link to the original article to support the content owner. We only provide a summary with metadata to assist in categorisation.

Monthly Australian Cyber News Summaries

Australian Cyber Aware – As It Was 2607 – July 2026

Australian Cyber Aware – As It Was 2606 – June 2026. Aggregated listing of Australian and New Zealand cybersecurity, privacy, and AI risks developments identified during June 2026. It includes cybersecurity incidents, regulatory updates, news stories, audit findings, and broader industry developments relevant to business and government audiences.

Australian Cyber Aware – As It Was 2606 – June 2026

Australian Cyber Aware – As It Was 2606 – June 2026. Aggregated listing of Australian and New Zealand cybersecurity, privacy, and AI risks developments identified during June 2026. It includes cybersecurity incidents, regulatory updates, news stories, audit findings, and broader industry developments relevant to business and government audiences.

Loading

Email Subscription

Australian Info & Cyber Security News

Treasury warned Government not to rush new school assessment tool before data breach

Treasury warned the Government not to rush its new school assessment tool – months before a security flaw made the records of 276 students accessible. … [...]

Expired anti-spam domain bites NZ's national stadium, Eden Park

Key points Eden Park's DNS configuration referenced an expired domain, spamcontrol.co.nz, letting consultant Alex Shakhov capture DMARC reports for a … [...]

Facial recognition technology 'scope creep' is upon us, experts warn

A shopper walks into a supermarket and grabs a basket. By that time, a camera has scanned their face. That is what experts warn could be the new … [...]

The Australian Financial Complaints Authority (AFCA) is inviting feedback from stakeholders on proposed changes to its Rules, that will enable it to … [...]

What changes will be made under federal government’s privacy law reform? | ABC NEWS

The federal government has unveiled plans to strengthen privacy laws. The proposed reforms take aim at identity fraud and give people the right to erase their data from online platforms. [...]

Australians to gain greater control over compromised identity documents with new IDLock scheme

The Albanese Government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]

Two WA Men Face Court Over Global Cybercrime Syndicate Allegations | 10 News

Two WA men have faced court, accused of masterminding of a sophisticated cyber-crime syndicate. The pair arrested following raids across three suburbs in a joint investigation between Australian police and [...]

New privacy laws target smart glasses and AI tech | 7NEWS

The Federal Government is developing new privacy laws targeting AI technology, including smart glasses and social media platforms. The proposed measures include expanding the Credential Protection Register through a new [...]

ASX creates deputy CISO role

Key points The ASX has created a new deputy chief information security officer role, with Hanlie Botha appointed as its first holder. • Botha joins ASX … [...]

Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime … [...]

Mopping up AI Slop: Fair Work Commission taking ac... | Clayton Utz

What you need to know On 24 August 2026, Justice Hatcher, President of the Fair Work Commission (FWC), released a Guidance Note on the use of … [...]

Busted! Alleged Aussie hackers linked to TeamPCP arrested in joint AFP-FBI-WAPF operation

Two men in their early 20s are to face a total of 14 charges for their alleged part in a global cybercrime organisation. • Fri, 28 Aug 2026 • … [...]

Financial Crimes Squad detectives have charged a telecommunications employee with allegedly accessing customer information without authorisation and … [...]

Sydney-based telco employee accused of selling customer data

Key points A 30-year-old telco employee has been charged over allegedly accessing customer data and selling it to "criminal groups". • NSW Police made … [...]

The Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC) are urging financial market … [...]

Aussie publisher Hachette restoring systems following ‘detection of unauthorised activity’ on network

Bookstores are facing stocking delays in the wake of a cyber attack, as the publisher says a timeline for return to full operations is impossible to … [...]

Report: Australia’s transport sector underprepared for risk of cyber attack

Less than half of respondents in a recent survey polling the logistics industry said they felt prepared to face a cyber security incident. • Tue, 25 … [...]

Minister to launch smart device security labelling pilot at Connecting Technology Summit

The conversation around securing connected devices in Australia is entering its next phase and smart product vendors and manufacturers are preparing … [...]

Australian Cyber Incidents and Audits Reports

August 2026  So Far

Sharp Motor GroupConfirmed 28-Aug-26 AU NSW
Exclusive: Sharp Motor Group confirms third-party cyber incident in wake of ransomware claims
The Sharp Motor Group is aware of the hacker’s claims and is actively investigating the incident. Threat actor Storm listed the company on 24-Aug-26 on their breach site. As evidence, Storm provided screenshots of driver licences, a customer list with names/contact details/VIN numbers, along with a range of internal documents. 

DigiGround Claim 28-Aug-26 AU NSW
[Unconfirmed] Qilin’s latest victim post puts DigiGround in the extortion spotlight
A ransomware-linked post has named Sydney-based web development company, DigiGround, as a new victim associated with Qilin. No details of evidence of the breach were posted. 

The Frame GroupClaim 29-Aug-26 AU NSW
[Unconfirmed] New South Wales ICT Consulting firm, The Frame Group, has been listed by Qilin as a victim
Qilin ransomware group posted an allegation tied to the ICT consulting firm, The Frame Group. No evidence has been presented to support the claim. 

Confirmed 28-Aug-26 AU NSW
Sydney-based telco employee accused of selling customer data
Financial Crimes Squad detectives have charged a telecommunications employee with allegedly accessing customer information without authorisation and selling it to criminal groups.

Claim 27-Aug-26 AU NSW
[Unconfirmed] A victim entry tied to health.nsw.gov.au describes 103 extracted emails
A new ransomware listing has put a health-related domain into the public record, but the facts remain narrow. Medusalocker is named in connection with a victim entry labeled Health, and 103 emails are said to have been extracted from health.nsw.gov.au. Public information does not establish the intrusion method, the initial access vector, or whether any wider data types were affected.

Agrimac Claim 27-Aug-26 AU VIC
[Unconfirmed] Storm has just published a new victim: Agrimac
Victorian agribusiness Agrimac has been listed on threat actor Storm's breach site. No details of the breach are available at this time.

Hachette AustraliaConfirmed 27-Aug-26 AU, NZ
Aussie publisher Hachette restoring systems following ‘detection of unauthorised activity’ on network
Hachette bookstores are facing stocking delays in the wake of a cyber attack, as the publisher says a timeline for return to full operations is impossible to judge.

New Zealand Sotheby's International RealtyPublished 24-Aug-26 NZ
Exclusive: New Zealand Sotheby’s International Realty investigating cyber security incident
Known only as 2019, the hacker posted details of a hack impacting New Zealand Sotheby’s International Realty on 18 August. The compromised data includes customer details such as names, email addresses, and physical addresses, which is currently being offered for sale.

Tower InsuranceClaim 22-Aug-26 NZ
[Unconfirmed] Coinbasecartel puts Tower Insurance Into Its victim feed
New Zealand-based Tower Insurance has been listed on the threat actor Coinbasecartel's ransomware site. No details or evidence have been presented.

Quest Apartment Hotels

Confirmed 19-Aug-26 AU
Quest Apartment Hotels customers' personal data exposed in security breach
In an email to customers, seen by ABC News, Quest Apartments Hotels said the compromised data related to records from before June 2025 and included full names, email addresses and other contact details.

Brighton East Dental ClinicPublished 18-Aug-26 AU VIC
Exclusive: Patient data potentially compromised in alleged dental clinic data breach
INC Ransom cyber extortion group shares patient X-rays, specialist reports, and correspondence on the dark web after claiming a breach of a Victorian dental clinic, Brighton East Dental Clinic.

SIA Medical Centre Published 18-Aug-26 AU VIC
Exclusive: SIA Medical Centre confirms it is investigating cyber incident involving patient data
Victorian-based SIA Medical Centre is responding to a ransomware incident after the Rhysida cyber extortion group claimed to have thousands of patient records.

Oz Hair and BeautyPublished 18-Aug-26 AU NSW
Exclusive: Oz Hair and Beauty confirms cyber incident
Oz Hair & Beauty was listed on the dark web leak site of a threat actor “xpl0itrs”, which claimed to have stolen 2,100,000 customer records containing names, email addresses, home addresses, phone numbers and the last four digits of active gift cards. The threat actor did not post any corroborating evidence.

Ramsey BrosClaim 18-Aug-26 AU SA
[Unconfirmed] Storm listing puts a farm-equipment dealer in the ransomware crosshairs
Threat actor Storm names South Australian farming equipment dealer Ramsey Bros as a victim. The report provided sample screenshots of files as evidence.

Westco Motors CairnsClaim 18-Aug-26 AU QLD
[Unconfirmed] Storm names motor dealer Westco Motors Cairns as ransomware victim
Westco Motors Cairns has appeared in a new victim listing associated with Storm, putting the Cairns dealership into the public frame of a ransomware and extortion event. Some screenshots of files were presented as evidence.

Might KingdomClaim 17-Aug-26 AU SA
[Unconfirmed] An extortion claim by Direwolf has been made against South Australian games developer Mighty-Kingdom
Threat actor Direwolf has made a claim against South Australian games developer Mighty-Kingdom. No clear evidence was posted in the claim.

Ollies PlaceClaim 14-Aug-26 AU NSW
[Unconfirmed] Ollies Place Kidswear has been listed by thegentlemen ransomware group
New South Wales retailer Ollies Place Kidswear has been listed on TheGentleman's breach site. No details of the breach or sample files could be located.

MidlandPublished 14-Aug-26 AU NSW
Exclusive: Australian truck trailer company Midland among dozens of victims listed by Cl0p cyber extortion group
Midland was listed on 12 August, with Cl0p claiming to have accessed half a gigabyte of data, which the hackers claim includes project information and at least one database.

Nick ScaliConfirmed 14-Aug-26 AU NSW
Aussie furniture company Nick Scali discloses cyber incident
Furniture retailer Nick Scali has said it is investigating a security incident in a disclosure to the Australian Stock Exchange. The company was forced to take “certain systems” offline in the wake of a cyber attack, and customer orders were impacted.

3-point AustraliaClaim 13-Aug-26 AU VIC
[Unconfirmed] Ransomware group Storm publicly claimed responsibility for a cyberattack against 3-point Australia
Victorian project management consultancy 3-point Australia has been reported breached by threat actor Storm. Storm listed various documents, including passports, as evidence of the exfiltration.

Bendigo BankConfirmed 11-Aug-26 AU VIC
Bendigo and Adelaide Bank admits to breaching its BEAR obligations in relation to cyber incident
Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime (BEAR) in relation to a 2023 cyber attack involving its Alliance Bank business. Accepts an $8 million penalty. 

Asset Flooring GroupPublished 03-Aug-26 AU VIC
Exclusive: Qilin claims breach of Victoria-based flooring firm
Asset Flooring Group was listed on the dark web by the infamous Qilin ransomware group overnight, with the threat actor claiming to have stolen 45 gigabytes of data.

 

If you believe any information in this post is inaccurate or incomplete, please contact us so we can review the matter. Parties with additional relevant information relating to the incident are also invited to get in touch.

Australian InfoSec Incidents and Audits Issues

NZ Incident: KillSec claims breach of NZ medical supplier | Cyberdaily.au

NZ Incident – Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries like healthcare.

Loading

Information Security Memes